Security teams are being asked to trust AI with work that used to belong to experienced analysts. So how can they decide if it’s earned its place there? It all starts with trust.
Trust that the data doesn’t leave the platform. Trust that customer data isn’t used to train generative foundation models. Trust that the agent can show its work. And most of all, trust that an analyst can review, correct, or replace the result.
At Sekoia, those commitments sit inside the architecture behind our agentic cybersecurity operations. AI works within the Sekoia SOC platform, with controlled access to customer data and a clear record of the investigation it conducts. All while leaving analysts with the final say.
Trust is an architecture question
AI in cybersecurity operates close to some of an organization’s most sensitive information. Security logs can reveal:
- User activity
- Infrastructure details
- Access patterns
- Endpoint behavior
- Evidence of an active intrusion
An AI feature processing that data needs clear boundaries.
Trust also depends on what happens after the model produces an answer. A security team may need to understand which data informed a result, whether the available evidence was complete, and who approved the resulting action.
That makes trust a property of the whole system. It includes the platform around the model, the permissions assigned to users, the way data is queried, the records created during an investigation, and the controls available when the system is unavailable or produces an inadequate result.
Sekoia’s agentic cybersecurity operations are designed around that wider view. The platform uses several complementary technologies, each with a defined role in security operations.

AI at Sekoia has defined jobs
Sekoia combines generative models, statistical methods, detection rules, runbooks, CTI, platform search, and agentic orchestration.
These components serve different purposes.
For example:
- A behavioral model identifies deviations from an environment-specific baseline.
- A detection rule identifies a pattern that needs attention.
- A runbook describes the investigation questions associated with that detection.
- A generative model can help summarize findings or interpret results.
Agentic orchestration brings those elements into a structured investigation. It helps the system work through authorized sources and investigation guidance while keeping the process within platform controls.
That separation gives security teams a clearer understanding of what each capability does. It also supports more precise governance. The controls around a behavioral model don’t need to be identical to the controls around an agent that queries security data and proposes a verdict.
The data boundary comes first
To investigate an alert, Sekoia’s AI can use the security context already available in the platform. Depending on the feature and customer configuration, that may include:
- Security alerts and events
- Logs and query results
- Information about users, machines and assets
- IoCs
- Cyber threat intelligence (CTI)
- Detection rules
- Runbooks
- Queries or instructions entered by users
An alert rarely tells the whole story. An unusual sign-in may look harmless until it connects to activity elsewhere in the environment. The AI needs enough authorized context to investigate those relationships, while the platform keeps its access within the customer’s permitted environment.
That is the role of the data boundary. It gives the AI useful information to work with and gives the security team a clear limit around what it can see.

Your data stays out of generative model training
For the AI features covered by Sekoia’s AI transparency datasheet, here’s exactly how your customer data is handled:
Sekoia’s approach is one point of comparison as more SOC platforms add AI capabilities. Public vendor documentation shows that external AI processing varies across the market.

Sekoia queries the platform directly
How an AI system retrieves context matters. Sekoia queries data directly from the Sekoia platform and authorized CTI sources, using the information available through the platform’s rules, runbooks, and relationships between events and entities. It doesn’t store customer data.
That keeps the investigation tied to its source. Analysts can trace a proposed verdict back to the queries run and the evidence returned, rather than trying to interpret a separate copy of their environment.
Customer environments remain separated
AI features follow the Sekoia SOC platform’s multi-tenant isolation model.
Thanks to these controls, AI should operate within an environment that security teams can configure, monitor, and restrict.
The platform records the investigation
An AI verdict needs a trail behind it. Sekoia records how an investigation moved from its starting signal to its conclusion, so analysts can see what the agent examined, where the evidence came from, and where uncertainty remains.
If the result doesn’t hold up, an analyst can challenge it, correct it, and record that change. Someone reviewing the case later can follow the investigation without having to rebuild it from scratch. That gives the team a clearer basis for operational review, incident analysis, and audit.

Human oversight remains part of the design
AI takes on different responsibilities across the Sekoia AI SOC platform.
- Roy helps analysts search for and understand information.
- AI Cases connects alerts and summarizes incidents, while behavioral detection identifies unusual activity for review.
- Elevate can take the investigation further by gathering evidence and proposing a verdict.
Whatever role AI plays, the analyst controls the outcome. They can review the evidence behind a result, inspect what the system did, and correct or replace its conclusion. High-impact actions require human validation according to the platform configuration.
Administrators can also restrict access to AI features by changing the relevant permissions across a workspace or community. Core SOC functions, including alert and case management, event search, detections, playbooks, and workflows that don’t depend on AI, remain available.
Sekoia puts the architecture into practice
Sekoia makes all these principles become visible in the SOC.
- When a detection triggers an investigation, it follows the relevant runbook and queries authorized platform data to build an evidence-based view of what happened before proposing a verdict.
- An analyst can then inspect the investigation, including the queries and evidence behind the result, and see where confidence is limited. If the verdict doesn’t fit the evidence, they can correct or replace it.
It carries structured investigation work forward, while the platform governs access and the analyst remains responsible for the decision. That is Sekoia’s approach to agentic cybersecurity operations in practice.

Read the full AI transparency datasheet
This article summarizes Sekoia’s current approach to AI across the SOC platform. The full AI Transparency Datasheet provides more detail.
Read the full AI Transparency Datasheet
Transparency lives in the platform
Trust in an AI SOC comes from what the platform makes visible. Sekoia’s agentic cybersecurity operations give AI a defined place inside the SOC, with controlled access to customer data and investigations that analysts can inspect and challenge. Elevate applies those principles to alert investigations.
That is transparency in practice. The security team can understand how a result was produced, decide whether it holds up, and change it when the evidence points elsewhere. AI helps carry the work forward while the platform and its users remain in control.

