In conjunction with

AI for Enterprise Security: Investigate Every Alert. Hunt Every Advisory. Document Every Action.

COMPANY OVERVIEW

Crogl, founded in 2023, is an AI security operations platform for the enterprise SOC. Founded by CEO Monzy Merza, former VP of Security GTM at Databricks and senior security leader at Splunk, and Chief Engineer Bradford Lovering, formerly Chief Architect at RelationalAI and Splunk. The company raised $30M: a $25M Series A led by Menlo Ventures and a $5M seed led by Tola Capital, both announced in March 2025.

The average enterprise receives 4,330 alerts per day. Teams investigate 37% of them. The other 63% close without a documented finding. Not because analysts are slow. Because the problem is structural. Crogl autonomously investigates every alert and threat intelligence advisory, documenting each action, finding, and decision. Your data never leaves the environment.

Air-gapped. High consequence environment. Extreme security requirements. A U.S. Defense Agency runs Crogl in production today: 1,000+ alerts investigated daily; previously, hundreds went uninvestigated. At a major U.S. electric utility, CRISP report analysis dropped from 24+ hours to under one hour. At a Fortune 500 financial institution, cross-data-lake investigations that took an hour now take minutes.

CORE FOCUS

Crogl conducts end-to-end investigations autonomously: an alert arrives, the knowledge graph enriches context, Crogl queries your SIEM, EDR, data lakes, and threat intelligence feeds in their native format, and a documented verdict lands in your ticketing system. No schema normalization. No playbook authoring. No hardcoded queries. Analysts receive finished investigations and make the calls.

Its differentiator is a neurosymbolic AI system. A knowledge graph maps users, assets, behaviors, and relationships continuously. An AI harness plans and executes the investigation. LLMs reason over evidence. A tool integration layer queries your stack in native format. No single component is responsible for the investigation. The system is.

Crogl deploys entirely within your environment: on-premises, private cloud, or fully air-gapped. This is the architecture, not a configuration option. It is model-agnostic: bring your own frontier model API credentials, run self-hosted open-weight inference, or route through your organization's existing LLM infrastructure.

PRODUCTS & TOOLS

Autonomous Alert and Advisory Investigation

End-to-end investigation of every alert and threat intelligence advisory, fully documented.

  • Crogl detected credential dumping via LSASS, traced lateral movement to DC01, and identified two additional compromised hosts autonomously. That is what an investigation looks like.
  • Handles CRISP reports, ISAC advisories, and vendor bulletins as first-class inputs alongside SIEM and EDR alerts
  • Queries each tool in native format; no schema normalization, no recoding when a source changes
  • Every query, finding, and decision written to your ticketing system; complete audit trail

Neurosymbolic AI Architecture

Knowledge graph + AI orchestration + LLMs + tool integration working as one system.

  • Knowledge graph maps your environment continuously: users, assets, behaviors, relationships, access patterns, and history
  • Investigates novel threats without a playbook; reasons from environmental context, not rules
  • MITRE ATT&CK-informed reasoning across all investigation workflows
  • No single component is responsible for the investigation; the system is

Skills Framework

Production-ready on day one. Extensible from day two.

  • Ships with built-in skills: threat hunting, alert investigation, report creation
  • Skill builder lets detection engineers write new skills using the same AI system that runs the platform
  • No vendor dependency; your team builds what they need without waiting on a roadmap
  • Custom skills integrate your specific data sources, workflows, and escalation paths

Deployment and Data Sovereignty

On-premises, private cloud, or fully air-gapped. Your data never leaves.

  • Runs in your data center, AWS/Azure/GCP, or completely disconnected environments
  • Model-agnostic (BYOM): frontier model APIs, self-hosted open-weight inference, or enterprise LLM services
  • Connect your tools; investigate immediately. No schema normalization phase, no playbook authoring sprint.
  • Same full capability across all three deployment modes; no reduced-feature on-prem edition

Market Segment:

SOC Automation

Categories:

SOC Automation