All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Legion Security sells a security operations tool that installs as a browser extension, watches analysts work inside whatever tools they open, and learns to replay it with no integrations. The payoff is fast deployment and reach into homegrown systems no API exposes. Two founders held senior roles on the Microsoft Sentinel team Legion now sells against, and Coatue led a $30 million Series A after an $8 million seed from Accel and Picture Capital, both announced in July 2025, with angels who work at Google, CrowdStrike, and Wiz. The proof comes from Legion and the press: its Fortune 500 adoption across finance, healthcare, and energy is vendor-reported, and public sources document no independent benchmark of the extension in a SOC it has not learned.
| Description | Legion Security builds a browser-native AI SOC analyst that learns how a security team investigates alerts and turns that knowledge into agentic workflows it can run with human oversight or autonomously. | [f1] |
|---|---|---|
| Founded | 2024 | [f2] |
| HQ | New York City, NY, US | [f3] |
| Funding | $38M total | [f4] |
| Latest funding | Series A, $30M, led by Coatue (July 2025), joining Accel and Picture Capital | [f5] |
| Product | What it does |
|---|---|
| Legion | A browser extension that observes analyst investigations across browser-accessible security tools, learns the team's workflows, and executes investigations in learning, guided, or autonomous modes. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Legion's browser extension learns how analysts investigate alerts across SIEM, threat intel, and email tools, then investigates and responds to threats through those tools. Legion applies AI to defend conventional assets and is mapped to the Cyber Defense Matrix. [f3]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The SOC analyst buyer drowning in alerts is clear and SecurityWeek and Calcalist corroborate the alert-fatigue and staffing pain, but the quantified pain still arrives through the company's own framing rather than independent measurement, leaving it real but not independently quantified. [s2, s4, s5] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The three-mode model, browser-extension mechanism, and vision-model capture are described across press and the company's pages, but the public record is vendor-described capability relayed through company pages, vendor-controlled product videos, and launch coverage, without an independent technical evaluation, so depth rests on company-sourced description. [s1, s3, s9] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | Legion founded in 2024 and exited stealth in July 2025 into an active AI SOC market that SecurityWeek, Fortune, and Crowdfund Insider all cover, but the Fortune 500 adoption that coverage relays is company-reported rather than independent, and the cited record shows no analyst category placement, independent study, or buyer speaking outside the vendor's materials, so the demand evidence is indirect. [s2, s4, s7] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Two founders held senior roles on the Microsoft Sentinel team and the third brings a Cambridge AI research background, documented by Fortune and Calcalist, but this is in-domain senior pedigree rather than a founder-level prior build or exit or a publication record, which the raised bar places at present but unproven. [s4, s2, s5] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Named customers (Virgin Money, WELL Health, University of Tulsa) carry quotes only on the company's own pages and the Fortune 500 adoption is press-relayed from the vendor, with the Google Cloud Marketplace a listing rather than corroborated scale, lifted slightly by the Coatue-led backing with individual angels who work at Google, CrowdStrike, and Wiz, but held at present but unproven. [s1, s2, s8, s6, s9] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The $38M raise is sized to an enterprise go-to-market split across New York and Israel, with a team of around 25 reported at the July 2025 funding announcement, stage-appropriate output per dollar without evidence of over- or under-capitalization. [s3, s5, s9] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Press places Legion in the AI SOC analyst space and compares it against incumbent SOC platforms, but that budget slot is still forming and placement leans on the browser-native framing rather than slotting cleanly into an established line item. [s2, s7, s4] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Browser-native capture and per-customer learning are differentiated, but the core function is a plausible feature for Microsoft, CrowdStrike, or Palo Alto, who own the consoles a SOC works in. Legion claims a per-customer memory that compounds, though its durability and switching-cost impact are not independently validated. [s4, s7, s1, s6] |
Legion Security sells to security operations teams that receive more alerts than their analysts can investigate. The company frames the modern SOC as stretched to the brink, where heavy integrations slow time to value and externally trained AI ignores how a given team actually works. The buyer is concrete, a SOC analyst at a large enterprise, and the pain is the triage queue that grows faster than the team can clear it.
Voices outside the vendor corroborate the pressure. SecurityWeek and Calcalist describe SOC teams burdened by alert fatigue and persistent staffing shortages, the conditions Legion built its product to address. CEO Ely Abramovitch, who ran Microsoft Sentinel for nearly five years, told Fortune that customers had little automation in place and that the problem worsened as attackers adopted AI.
Legion's framing of the problem also explains its design choice. Rather than ship another externally trained model, the company argues that an organization's own analysts hold knowledge no off-the-shelf playbook captures, so the product is built to learn from inside the team rather than impose a generic workflow. [s1, s2, s4, s5]
The Legion product is a browser extension that learns how analysts investigate and then runs those investigations itself. It observes a team working across the security tools they already open in the browser, captures their decision-making with vision models, and turns each investigation into an editable workflow that can be automated when the team is ready. Legion describes three modes that escalate from observation to action: a learning mode that shadows analysts, a guided mode that executes under human supervision, and an autonomous mode that runs investigations on its own.
The product's stated advantage is that it needs no integrations. Because Legion operates inside the browser, it works across whatever a team can open there, from SIEMs and threat intel platforms to internal homegrown tools no API exposes, which the company says lets it deploy in minutes with no connector work. Legion's Google Cloud Marketplace offering documents workflows executed by AI agents powered by Gemini models, and the cited record does not establish which models power the platform elsewhere.
External validation is real but vendor-relayed. SecurityWeek reports adoption among Fortune 500 organizations in energy, finance, and healthcare, while named results from Virgin Money, WELL Health Technologies, and the University of Tulsa appear in the company's own customer accounts rather than independent benchmarks. [s1, s3, s6, s9, s2]
Legion competes on two fronts, other AI SOC startups and the platform incumbents whose tools generate the alerts. Other venture-backed entrants market agentic AI SOC analysts that investigate alerts across a customer's existing tools, the same buyer and outcome Legion targets, and Legion positions its browser-native design as the difference from products it describes as needing API integrations.
Legion's stated edge is the browser-native approach itself. By learning from what analysts do in the browser instead of wiring into back-end tools, Legion claims faster deployment and reach into systems no integration touches, and it leans on per-customer learning as the source of workflows a generic model cannot reproduce. Legion builds that edge from captured analyst technique, and no named proprietary cross-customer dataset appears in the cited record, while the models behind the reasoning are only partly documented. Legion says its Google Cloud Marketplace offering executes each workflow with Google's Gemini models, and the cited record does not establish the model architecture of its other deployments.
The incumbents are the structural threat. Fortune frames Legion against Microsoft Sentinel, CrowdStrike, and Palo Alto Networks, the established SOC platforms that detect at the network, server, and endpoint layers and that two Legion founders came from. Those vendors own the consoles and telemetry a SOC works in, so Legion's differentiation depends on the browser layer staying valuable if they extend into the same automated investigation. [s1, s4, s6, s7, s11, s12, s13]
Named customers anchor Legion's traction story. Virgin Money, WELL Health Technologies, the University of Tulsa, and IQ-EQ carry attributed quotes on the company's pages, and Legion's May 2026 Google Cloud Marketplace announcement describes a large insurance organization that automated 24,000 investigations and cut mean time to respond from twenty minutes to two. These figures appear in Legion's own voice rather than independent reporting.
Press carries the shape of the adoption if not independent proof of it. SecurityWeek and Crowdfund Insider report that Fortune 500 enterprises across energy, finance, and healthcare use Legion, and Fortune attributes a Fortune 20 customer to the CEO, claims the coverage relays from the company rather than verifies, so the buyer segment is asserted by Legion and repeated in press.
Channel motion is starting to show. Legion listed its product on the Google Cloud Marketplace in May 2026, a procurement path that can shorten enterprise purchasing, though fetched sources do not document revenue, a reseller program, or an analyst placement. [s1, s2, s7, s4, s6]
The founders' backgrounds map directly onto the product. CEO Ely Abramovitch and VP of R&D Michael Gladishev previously held senior roles on the Microsoft Sentinel team, the SIEM product Legion now aims to displace, and CTO Eyal Fisher brings an artificial intelligence research background from the University of Cambridge. Fortune, SecurityWeek, and Calcalist document the pairing independently of the company.
The investor base reinforces the team signal. Coatue led the Series A, Accel and Picture Capital co-led the earlier seed, and individual angels who work at Google, CrowdStrike, and Wiz joined, a roster of security and venture names that Calcalist and Fortune report. Picture Capital is run by Island co-founders Michael Fey and Dan Amiga and Transmit Security CEO Mickey Boodaei, and Fey publicly praised Legion's technology.
Fetched sources name the three founders and the lead investors but little of the wider executive bench, so engineering and go-to-market leadership depth beyond the founders is the unanswered question. [s4, s5, s8, s9]
Any enterprise buyer weighing Legion starts with trust, because of how much the product reaches. The extension can observe and act within the browser-accessible tools a team permits, so buyers probe its data handling and oversight first. SiliconANGLE reports that analysts can restrict where the agent operates, mask sensitive data during sessions, and keep every action auditable.
The published assurance is broad for a company this young. Legion's SafeBase trust center lists SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 42001:2023, HIPAA, and CSA STAR Level 1. Its featured documents, the SOC 2 Type 2 and HIPAA reports and a pentest report, sit behind an access request. ISO 42001 is the notable entry, since it certifies an AI management system, the risk surface Legion's own product creates.
Human oversight is the trust argument Legion leads with. The company stresses that teams grant autonomy in phases and that Legion shows what it plans to do, does it, and logs every step, positioning staged human control against black-box automation that acts without context or consent. [s1, s3, s10]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Prophet Security | competes with | Prophet Security's own site markets an agentic AI SOC platform whose agents run alert investigation and response and connect to a customer's existing security stack, the same buyer and outcome Legion targets. | |
| Dropzone AI | competes with | Dropzone AI's own site markets an AI SOC analyst that investigates alerts end to end across a customer's existing tool stack, competing for the same SOC budget Legion pursues. | |
| Radiant Security | competes with | Radiant Security's own site markets an agentic AI SOC platform that automates alert triage, investigation, and response to cut analyst workload, the same problem Legion addresses from the browser. | |
| Microsoft | competes with | Owns the Sentinel SIEM that two Legion founders came from and the consoles many Legion prospects already license, the incumbent platform Fortune contrasts Legion against. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
| CrowdStrike | competes with | Owns endpoint telemetry a SOC works in and is named by Fortune among the established SOC platforms Legion positions against, while individual angels who work at CrowdStrike invested in Legion. |
Add analyzed competitors to compare them side by side with Legion Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
What Legion has built is reproducible. Its autonomous investigation runs on third-party frontier models, and the accumulated asset is captured analyst technique and per-customer workflows a rival could rebuild, with no pooled cross-customer data in the record. The browser-native design that deploys without integrations builds little of the connector lock-in that raises switching costs, so what slows a switch is process reliance: once a SOC offloads triage to Legion's learned automation, reabsorbing that work is costly even though the extension leaves no integration behind. The broad trust posture and founders who built Microsoft Sentinel are real advantages, but they are a head start on execution, not an asset a competitor cannot obtain.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy software they install and run, with staged autonomy that moves from passive observation to full automation while analysts keep accountability for verdicts. The cited record describes customer-operated software and does not document a managed-service or human-judgment layer that assumes that accountability, so the delivered artifact reads as a product the customer operates. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The product embeds in analysts' daily investigation work and accumulates learned, editable workflows whose replacement would likely cost a departing customer real effort, though public sources do not document whether those workflows are exportable. That revert cost holds even though the browser extension itself leaves no back-end integration to unwind. Because Legion needs no back-end integrations by design, it builds little connector lock-in, and its per-customer learning is vendor-asserted rather than independently validated. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Legion's trust center publishes SOC 2 Type 2, ISO 27001, ISO 42001, HIPAA, and CSA STAR Level 1, an unusually broad set for its stage that eases procurement without blocking a substitute. The cited record identifies no mandate specific to this product class, and a funded rival can obtain the same certifications. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | End-to-end autonomous investigation across heterogeneous, browser-accessible security tools under adversarial pressure is hard applied engineering, and Legion's published work on indexing indicators of compromise to keep agent output reliable across long investigations shows the depth is real. Capturing analyst technique with vision models adds to the build difficulty. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The buyer is an identifiable security budget holder, the enterprise SOC, and Legion names Fortune 500 references across finance, healthcare, and energy plus a major financial institution and other Fortune 20 companies, with regulated-sector handling backed by HIPAA and ISO documentation. The traction is vendor-reported rather than independently audited. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Legion coordinates multi-tool investigations across the customer's security stack, a workflow layer above the tools rather than a feature inside one. It runs as an out-of-path browser overlay other software does not depend on, so removing it costs coverage rather than breaking production. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The accumulated asset is captured analyst technique and per-customer workflows, which are tenant-specific and rebuildable by a rival willing to observe the same team. The reasoning runs on third-party frontier models, and no named cross-customer dataset or model of its own appears in the record. |
Legion Security sells to security operations teams at large enterprises whose alert volume outruns the analysts available to work it. The buyer is the SOC, an analyst or CISO who owns a recognized security-operations budget, and Legion segments by enterprise tier and regulated industry rather than by a single vertical.
The named references cluster in regulated sectors. SecurityWeek reports adoption among Fortune 500 organizations in energy, finance, and healthcare, and Legion's own pages carry attributed results from customers in banking, healthcare, financial services, and higher education, including a measured investigation-time reduction reported by a healthcare-technology customer's security executive. Fortune adds that Legion serves dozens of customers including a major financial institution and other Fortune 20 companies.
The demand signal is real but vendor-shaped. Every customer name and outcome reaches the record through Legion or a press account relaying the company, not an independent buyer survey, so the segment is well chosen and credibly addressed rather than independently measured.
Legion's claimed advantage is to learn from what analysts already do in the browser instead of wiring into back-end tools. The product is a browser extension that captures analyst decision-making with vision models and turns each investigation into an editable workflow, escalating from passive observation to supervised action to full automation.
The engineering behind the claim is published in concrete detail. Legion publishes technical work on its agent internals, including a method for indexing indicators of compromise that it reports took its agents' structured output from roughly four in five valid to fully valid across a hundred evaluation runs, plus internal evaluations that compare frontier models across investigation use-case categories. The fetched record offers architecture and evaluation specifics rather than positioning alone, and no basis for comparing that disclosure against similarly staged rivals.
The reasoning runs on third-party models. Legion's workflows run on frontier models, Gemini among them on Google Cloud, so what it accumulates is captured analyst technique and per-customer workflows rather than a model of its own in the record, and no independent benchmark in the record yet tests the product in a SOC it has not learned.
Legion sells through a founder-led, demo-gated motion aimed at large enterprises. The site routes every visitor to a demo request, the founders front public selling through funding press, and the company appears at industry conferences, and no self-serve trial or price is exposed, the pattern of a vendor pursuing negotiated enterprise deals.
Channel motion is starting through Google Cloud. Legion listed on the Google Cloud Marketplace in May 2026, letting customers apply the spend to an existing Google contract and simplify procurement, and it positions itself for buyers already invested in Google Cloud and Google SecOps.
Traction is asserted through vendor-reported outcomes. Legion says a large insurance customer cut mean time to respond from twenty minutes to two and that it resolves threats far faster than existing players, and a healthcare customer's security executive reports a measured reduction on his most common use case. These figures come from Legion and its customers rather than independent testing.
Legion exposes no pricing on its public pages. No pricing is on the fetched pages and buyers reach a number through a demo request, a sales-assisted enterprise motion in which negotiated terms and a procurement or security review are the likely route to a price rather than a documented one.
The value the price must capture is analyst labor displaced. Legion frames its outcome as faster investigations and lower mean time to respond, so the natural anchor is headcount economics rather than a per-tool line item, though fetched pages do not state whether Legion charges by seat, by analyst, or by investigation volume.
Consumption cost is a live design question for this product. Because each investigation runs through third-party frontier models, token cost scales with investigation volume, and Legion's own published work on trimming indicator noise to control token use shows the unit economics are something the company is actively engineering around.
Legion's delivery model is its sharpest operational claim. Because it works inside the browser, it says it reaches any tool an analyst can open there, from threat-intel platforms to legacy internal tools, without API configuration. Legion markets zero-integration deployment and says rival automation platforms leave enterprises facing months of API work and custom connectors first.
Oversight controls are built into the operating model. Analysts can restrict where the agent operates, mask sensitive data during a session, and keep every action logged and reviewable, and autonomy is granted in stages rather than switched on at once.
The platform runs on Google Cloud infrastructure and third-party frontier models, and Legion says its Google Cloud integration reaches beyond the Marketplace listing. Fetched pages do not document data-residency options or a support responsibility model, the operational detail an enterprise review would probe.
Legion's access model puts trust at the center of any enterprise review. The extension reads and acts inside every security tool an analyst opens in the browser, a privileged position that makes data handling and oversight the opening question a buyer asks.
The published assurance is broad for the company's stage. Legion's trust center, run on SafeBase, lists SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 42001:2023, HIPAA, and CSA STAR Level 1, and offers a penetration-test report and the underlying audit reports on request. The ISO 42001 certificate is notable because it covers an AI management system, matching the product's own risk surface.
Human oversight is the trust argument Legion leads with. The company stresses staged autonomy and a full log of what the agent plans, does, and concludes, positioning analyst control against automation that acts without a visible trail.
Legion is building a platform position from the browser and workflow layer, not the data layer. It is not positioned as a telemetry store. It coordinates investigations across the customer's existing browser-accessible tools, so its platform claim is the orchestration of work the analyst already does rather than a system of record other tools feed.
Its main ecosystem anchor is Google Cloud. The Marketplace listing, the Gemini-powered Google Cloud offering, and the positioning toward Google SecOps customers lean Legion's distribution toward Google Cloud, which speeds procurement for Google buyers, though the platform routes to the latest frontier models rather than one model provider.
The investor base adds reach rather than a proprietary asset. Coatue led a $30 million Series A, Accel and Picture Capital co-led the seed, and angels from Google, CrowdStrike, and Wiz joined, names that lend credibility but that do not themselves lock in customers.
Legion's founders map directly onto the product they sell. CEO Ely Abramovitch and VP of R&D Michael Gladishev built Microsoft Sentinel, the security product Legion now positions against, and CTO Eyal Fisher brings an artificial-intelligence research background from Cambridge, a pairing of operator and researcher pedigree that fits a product built to learn analyst technique.
The company is small and split between Israel and New York, and the public record names the three founders and the lead investors but little of the wider executive bench, so leadership depth beyond the founders is the open question.
The backing lends the founding team credibility with security buyers. Angels who work at Google, CrowdStrike, and Wiz joined the round, and named enterprise security leaders endorse Legion on its site, the kind of vouching that weighs heavily when a buyer evaluates a young vendor with deep access.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | https://www.legionsecurity.ai | official | 2026-06-24 |
| f2 | SecurityWeek: Legion Emerges From Stealth With $38 Million in Funding | press | 2026-06-24 |
| f3 | FinSMEs: Legion Raises $38M in Seed and Series A Funding | press | 2026-06-24 |
| f4 | SiliconANGLE: Legion raises $38M to automate SOC workflows through browser-native AI | press | 2026-06-24 |
| f5 | Calcalist: Legion raises $30M Series A to train AI on how security teams work | press | 2026-06-24 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Legion Security homepage “Grow your own AI SOC. Legion learns how your team works and scales that knowledge into agentic workflows that elevate your SOC. Born and raised in-org. A browser extension that grows your AI companion.” | official | 2026-06-24 |
| s2 | SecurityWeek: Legion Emerges From Stealth With $38 Million in Funding “Founded in 2024 by Microsoft Sentinel and Cambridge AI research alumni, New York City-based Legion has built a browser-native AI Security Operations Center (SOC) companion. The company has already seen adoption among Fortune 500 organizations in the energy, finance, and healthcare industries.” | press | 2026-06-24 |
| s3 | SiliconANGLE: Legion raises $38 million to automate SOC workflows through browser-native AI “Legion uses a three-phase operational model: a Learning Mode that shadows senior analysts, a Guided Mode that performs tasks under human supervision, and an Autonomous Mode. Analysts can restrict its access to certain tools and mask sensitive data during sessions.” | press | 2026-06-24 |
| s4 | Fortune via Yahoo: Cybersecurity upstart Legion emerges from stealth with $38 million “Legion is a security operations center (SOC) that uses AI to detect threats within users' computer browsers, different from SOC technologies like Palo Alto Networks, Microsoft Sentinel, and CrowdStrike. Legion already has dozens of customers including Fortune 20 companies.” | press | 2026-06-24 |
| s5 | Calcalist: Legion raises $30M Series A to train AI on how security teams work “Legion was founded in 2024 by security veterans Ely Abramovitch (CEO), Michael Gladishev (VP R&D), and Eyal Fisher (CTO). ... Legion currently employs 25 people split between Israel and New York.” | press | 2026-06-24 |
| s6 | Legion Security: Now Available on Google Cloud Marketplace “Legion Security Is Now Available on Google Cloud Marketplace, May 31, 2026. Powered by Google Cloud's Gemini models, each workflow is executed by AI agents. A large insurance organization automated 24,000 investigations and cut mean time to respond from 20 minutes to 2 minutes.” | official | 2026-06-24 |
| s7 | Crowdfund Insider: Legion Raises $38 Million, Emerges From Stealth “Legion claims to be the first of its kind to offer AI SOC as a browser extension. ... funding was led by Coatue, with participation from Accel and Picture Capital, along with investors from tech companies, like Google, Crowdstrike, and Wiz.” | press | 2026-06-24 |
| s8 | About Legion Security “Ely Abramovitch, Founder & CEO. Michael Gladishev, Founder & VP R&D. Eyal Fisher, Founder & CTO. Built Microsoft Sentinel. Ex-Cambridge, Pioneer in Gen AI. We knew real analyst behavior holds more value than any off-the-shelf playbook or pre-trained model.” | official | 2026-06-24 |
| s9 | FinSMEs: Legion Raises $38M in Seed and Series A Funding “Legion emerged from stealth with $38 million in Seed and Series A funding. The round was led by Coatue, with Accel and Picture Capital, plus angel investors from Google, Crowdstrike, and Wiz. The platform uses vision models and a lightweight browser extension to record analyst workflows.” | press | 2026-06-24 |
| s10 | Legion Security Trust Center (SafeBase) “Compliance: HIPAA, ISO/IEC 27001:2022, ISO/IEC 42001:2023, SOC 2 Type 2, CSA STAR Level 1. Featured Documents: SOC 2 Type 2, HIPAA, Pentest Report, ISO/IEC 42001:2023, ISO/IEC 27001:2022. HIPAA Report.” | official | 2026-07-08 |
| s11 | Prophet Security homepage (competitor-controlled page) “The Agentic AI Platform for the Modern SOC ... Built by security operators, Prophet AI spans autonomous alert investigation and response, continuous threat hunting, and closed-loop detection engineering ... Connect your existing security stack with 200+ out-of-the-box integrations.” | official | 2026-08-05 |
| s12 | Dropzone AI homepage (competitor-controlled page) “The agentic SOC. Your team, reinforced. ... Investigates alerts end to end across your full tool stack, 24/7, cutting investigation time by 85% while showing the evidence behind each verdict. ... Works with your existing stack. Out of the box.” | official | 2026-08-05 |
| s13 | Radiant Security homepage (competitor-controlled page) “AI SOC defense built for AI-led attacks ... agentic AI SOC platform automates alert triage, investigation, and response to scale SOC operations and reduce analyst workload.” | official | 2026-08-05 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Legion Security homepage “Legion has been transformative in our SOC, producing real-world, measured reduction in MTTI/R by 81% on our most common use case.” | official | 2026-07-08 |
| s2 | SecurityWeek: Legion Emerges From Stealth With $38 Million in Funding “The company has already seen adoption among Fortune 500 organizations in the energy, finance, and healthcare industries.” | press | 2026-07-08 |
| s3 | SiliconANGLE: Legion raises $38M to automate SOC workflows through browser-native AI “Legion uses a three-phase operational model that moves from passive observation to full automation.” | press | 2026-07-08 |
| s4 | Fortune via Yahoo: Cybersecurity upstart Legion emerges from stealth with $38 million “Legion already has dozens of customers that include a major financial institution and other "Fortune 20" companies, for whom Legion responds to threats 90% faster than existing players, according to Abramovitch.” | press | 2026-07-08 |
| s5 | Calcalist: Legion raises $30M Series A to train AI on how security teams work “Cybersecurity startup Legion Security has raised $30 million in a Series A funding round led by Coatue, with participation from Accel and Picture Capital, as well as senior angel investors from Wiz, Google, and CrowdStrike.” | press | 2026-07-08 |
| s6 | Legion Security: Now Available on Google Cloud Marketplace “Powered by Google Cloud's Gemini models, each workflow is executed by AI agents that reason through the evidence and provide a verdict and even remediate.” | official | 2026-07-08 |
| s7 | Crowdfund Insider: Legion Raises $38 Million, Emerges From Stealth “Legion claims to be the first of its kind to offer AI SOC as a browser extension.” | press | 2026-07-08 |
| s8 | About Legion Security “Ely Abramovitch, Founder & CEO. Michael Gladishev, Founder & VP R&D. Eyal Fisher, Founder & CTO. Built Microsoft Sentinel. Ex-Cambridge, Pioneer in Gen AI.” | official | 2026-07-08 |
| s9 | Legion Security Trust Center (SafeBase) “Compliance: HIPAA, ISO/IEC 27001:2022, ISO/IEC 42001:2023, SOC 2 Type 2, CSA STAR Level 1.” | official | 2026-07-08 |
| s10 | Legion Security engineering blog: IOC Chaos “Across 100 evaluation runs, it took JSON validity from ~80% to 100% and IOC reference compliance to 100%.” | official | 2026-07-08 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.