
Security Operations
Arcanna.ai
Encodes analyst judgment into explainable AI models that triage and close SOC alerts.
Arcanna.ai Overview
What it does
Arcanna.ai is an AI decision-intelligence platform for the security operations center (SOC) that encodes the judgment of experienced analysts into governed models rather than relying on generic large language models or static playbooks. Its core mechanism is the Decision Model: a supervised, analyst-taught neural network that runs without requiring a GPU, classifies each alert with an explainability rationale and a confidence score, and gates automation by that confidence so certain verdicts execute on their own while ambiguous ones route to a human.
How it works
The platform is organized into two layers. The Decision Layer runs structured pipelines that move an alert from ingestion to a versioned, auditable decision, applying confidence thresholds so high-confidence verdicts execute automatically, mid-confidence cases require analyst validation, and low-confidence cases become recommendations only. A living Decision Graph records what was decided, why, and who validated it. The Investigation Layer adds agentic workflows built on Google ADK, natural-language AI assistants, and retrieval-augmented generation (RAG) over organizational knowledge, connecting to SIEM, SOAR, EDR, and threat-intelligence tools through API integrations and the Model Context Protocol (MCP).
Credentials and traction
Arcanna.ai was named a Gartner Cool Vendor for the Modern Security Operations Center in 2024 and is listed as a Sample Vendor in the 2025 Gartner Hype Cycle for Security Operations. Named customers include the telecommunications operator Orange and Core42, alongside European managed security service provider (MSSP), energy, healthcare, and government SOC teams. The platform targets enterprise SOCs and MSSPs running mission-critical, multi-tenant security operations.
Key Capabilities
mapped to solution categoriesPerforms initial triage of incoming alerts automatically, classifying and prioritizing them to cut tier-1 workload before a human touches the queue.
Investigates alerts end-to-end from trigger to verdict and closes them out autonomously, so the full volume of raw alerts gets analyzed without resource-constraint concessions.
Automatically gathers and attaches context — threat intelligence, asset and identity data — to alerts during triage and investigation.
Identifies and dismisses false-positive alerts with documented rationale, reducing noise reaching human analysts.
Generates investigation summaries and incident reports for analysts and leadership from completed investigation activity.
Lets analysts drive investigations and threat hunts through natural-language questions instead of query languages.
Recommends the next response actions to take based on investigation findings.
Applies ML classification to incoming alerts to filter false positives, group related events, and route high-confidence detections to analysts, reducing L1 analyst workload.
Suggests the next investigative or containment steps for an alert or incident, with the supporting reasoning, so analysts can confirm and act rather than deciding from raw telemetry alone.
Accepts natural language queries over security telemetry and translates them to structured queries, enabling investigation without requiring analyst proficiency in SPL, KQL, or SQL.
Inserts AI-generated analysis, triage decisions, and enrichment into existing SIEM and SOAR case management workflows rather than requiring analysts to use a separate interface.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on August 4, 2026
Buyers
See how Arcanna.ai fits your stack
Add Arcanna.ai to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.