Listing Thumbnail

    Torq AI SOC Platform

     Info
    Sold by: Torq 
    Deployed on AWS
    Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution. The platform analyzes your risk context to identify your biggest threats. Working alongside your SecOps staff, the Torq platform integrates with your security stack to facilitate containment and remediation workflows.
    4.8

    Overview

    Play video

    Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution, expanding capacity and throughput. First, Torq ingests and normalizes telemetry from across your security stack, preparing the data for agentic reasoning at scale. Auto Triage filters out noise and prioritizes actual threats. Next, cases are automatically opened and assigned to highly specialized AI agents designed for investigation and response. Using tools and actions you specify, they gather evidence, assemble timelines, and transparently record decisions and authorized actions. Your team is in complete control. With Torq, your SOC delivers more results, more efficiently, from triage through remediation.

    Highlights

    • Eliminates alert fatigue - Torq's AI SOC platform integrates with AWS security tools to provide a unified view of security cases that prioritizes urgent threats to help decrease mean-time-to-response (MTTR).
    • Ends tech sprawl - Torq's AI SOC platform addresses tech sprawl with integrations across the entire security stack. Now security teams can overcome the challenges posed by complex multi-cloud environments and evolving security threats.
    • Addresses talent shortage- Torq's AI SOC platform capabilities enable security teams to achieve more with fewer resources, reducing the need for manual tasks. Pre-built integrations with AWS services automate complex processes, empowering less experienced analysts, and improving overall productivity.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Torq AI SOC Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (3)

     Info
    Dimension
    Description
    Cost/12 months
    Torq Essential
    Essential Plan
    $450,000.00
    Torq Enterprise
    Enterprise Plan
    $450,000.00
    Torq Elite
    Elite Plan
    $450,000.00

    AI Insights

     Info

    Dimensions summary

    You buy the Torq AI SOC Platform through a contract that bills by units. Three plan levels are available: Torq Essential, Torq Enterprise, and Torq Elite. These form a tiered structure, letting you pick the level that matches your security operations needs. Within each plan, you choose the number of units, so the total cost scales with the quantity you commit to. All three plans use the same unit-based billing model and share the same term. The plan you select determines the scope of platform capabilities included.

    Top-of-mind questions for buyers

    All three plans bill by units under the same contract term. The plan you pick sets the scope of platform capabilities you can access. Higher plans expand what is included. To confirm which specific features fall under each plan level, contact the vendor, since the pricing table does not detail per-plan feature splits.
    The plans bill by units, and you choose the quantity you commit to. The available data does not define what a single unit maps to, such as an agent, workspace, case, or seat. Contact the vendor to confirm the exact unit definition before committing to a quantity.
    You select the number of units within your chosen plan, and the total scales with that committed quantity. Cost is driven by two factors together: the plan level you pick and the unit count under it. Adding units raises the total; the plan level sets the capability scope.
    torq.io
    Helpful?

    Vendor refund policy

    Please contact us at sales@torq.io 

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    https://support.torq.io  support@torq.io . By purchasing, deploying, accessing, or using this product, you agree to comply with the AWS Marketplace Standard EULA, and the terms of applicable open source software licenses bundled with the product. In addition, if you elect to use any artificial intelligence (AI) features made available by Torq as part of the product, the Torq AI Terms shall govern your use thereof. Pursuant with the Data Processing Addendum, you authorize the engagement of the sub processors listed at: https://torq.io/legal/subprocessors/ , as may be updated by Torq from time to time.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Alert Triage and Noise Filtering
    Auto Triage filters out noise and prioritizes actual threats based on risk context analysis
    Telemetry Ingestion and Normalization
    Ingests and normalizes telemetry from across security stack to prepare data for agentic reasoning at scale
    Specialized AI Agent Investigation
    Deploys highly specialized AI agents designed for investigation and response that gather evidence, assemble timelines, and record decisions transparently
    Security Stack Integration
    Integrates with AWS security tools and across the entire security stack to provide unified view of security cases
    Automated Containment and Remediation Workflows
    Facilitates automated containment and remediation workflows with tools and actions specified by security teams
    Multi-Source Threat Data Integration
    Correlates and ingests security data from Trellix Security Platform and over 500 third-party tools including 13 AWS integrations to create unified threat visibility across the security stack.
    AI-Driven Detection and Alert Triage
    Applies artificial intelligence-driven analytics and automated alert triage to prioritize threats and provide GenAI-powered insights for threat investigation and remediation guidance.
    No-Code Automation for Investigation and Response
    Provides UI-driven, point-and-click automation capabilities to offload repetitive security operations tasks and accelerate investigation and response workflows.
    Pre-Built Analytics and Correlation Rules
    Utilizes pre-built analytics and correlation rules to rapidly correlate multi-vector threat detections and reconstruct complete attack narratives from ingested security events.
    Hybrid and Air-Gapped Deployment Support
    Supports deployment across cloud, hybrid, and air-gapped environments with flexible integration architecture for diverse infrastructure configurations.
    Alert Prioritization Engine
    Patented Dynamic Risk Scoring alert engine for precise threat identification and response prioritization
    Security Monitoring Coverage
    24x7x365 monitoring and managed detection & response across multiple security domains including endpoint detection, vulnerability management, and firewall management
    SOC Technology Integration
    Curated integration with industry-leading SOC technologies including AWS and Splunk tools through the Deepwatch Security Center
    Security Posture Assessment
    Proprietary Security Index providing quantitative analysis and industry benchmarking for security program maturity evaluation
    Threat Hunting Capability
    Proactive threat hunting services to identify and remediate security threats across the attack surface

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    172 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    88%
    12%
    0%
    0%
    0%
    6 AWS reviews
    |
    166 external reviews
    External reviews are from G2  and PeerSpot .
    Scott H

    Automation has transformed phishing triage and freed analysts for deeper security work

    Reviewed on Oct 02, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We are primarily using Torq for phishing alert handling, which means we are getting the alert data from Splunk and then using that data to pull back the phishing emails and their attachments, detonate those in various sandboxes, and then collate all that data up into an incident for the security team. We have a couple of workflows in that vein. We handle phishing, malware detections, and AI use cases in a similar manner, and we are also doing a lot of data syncs between our various vulnerability platforms. We are using Torq for that, and eventually we will be using it for case management, but that is currently in the works.

    Regarding Torq's Identity AI, we have not really gotten to use it a whole lot because of the nature of the transition project that we are currently working on, so I do not have a lot to say about it.

    We are actually using Torq to automate triage, investigation, and remediation actions across multiple attack surfaces like endpoint, identity, cloud, and IT right now. Outside of the piecemeal automations we have, which encompass all three of those different security domains, the new case management workflow ecosystem we are building out is exactly that.

    How has it helped my organization?

    Torq has changed the day-to-day experience for my security analysts and me by saving literally thousands of man-hours per month since we have implemented some of these use cases. The analysts now have a lot more free time to do their work.

    What is most valuable?

    My favorite thing about Torq thus far is the ease of use. Once you get over the initial learning curve, which for me was not that bad, it is a very simple platform with a lot of drag and drop tools. It is flexible enough that I could use Python if I needed to, and logically, it is a clean editor that makes a lot of sense for me and is just simple and intuitive.

    What needs improvement?

    What I dislike about it is that because my background is primarily in Python, the platform itself can run on Python scripts, and when those fail, it is really easy for me to figure out what is going on. The underlying code being run by the platform for all of the built-in parts of the built-in automations that you can create uses Go, which is a different programming language, and the way it displays errors within the platform when something goes wrong is not as intuitive for me to debug or do a traceback on. That would be the biggest issue I have with it. Sometimes when it spits out an error, it is either because I am not familiar with Go or the platform itself just is not giving me enough to usually go off of.

    The comparison of Torq's unified platform approach to SOC automation and case management to any other experiences managing multiple point solutions across the stack is a loaded one. The automation side is really great. However, the case management piece, due to the platform being an automation-first tool, lacks real robust out-of-the-box case templates or good solutions for creating those without spending a lot of time doing development work, which makes the overall experience poor, honestly. In a previous life, I managed Phantom, Phantom SOAR, Splunk SOAR, whatever you want to call it, and another tool called IBM Resilient, which was our external ticketing system. That tool itself had pre-made case templates you could use. Out-of-the-box, you could get the integration going between the two platforms, and it was relatively simple. With Torq, you have to build everything from scratch, and I wish it had a little bit more of a case management feature that was a bit more developed.

    For how long have I used the solution?

    I have been working with it for just over a year now, since we did our demo with them and got access.

    What do I think about the stability of the solution?

    I have not really noticed any issues with stability. The UI can be a little laggy at times, but I do not think that is really the platform. I think it might just be the implementation at Marriott. We have never had an outage, so I can at least say we have not had that happen. Any lag I think is usually client-side, not server-side.

    What do I think about the scalability of the solution?

    Torq seems to be very scalable. There are some limitations with the platform in terms of how many workflows you can run. There is only so many that you are allowed to run in the system before pricing starts becoming an issue, and that can be a little frustrating, but the actual platform itself seems to scale very well.

    How are customer service and support?

    I have contacted their technical support, and that is usually what I am doing when I am reporting bugs.

    If I were to put them on a scale from one to ten, I would give them a ten. They are fantastic.

    The quality and speed of the support from Torq are very much on top of their game. You put in a ticket, and you usually hear something back within an hour. If it is a big bug, we have got dedicated resources from Torq that we can reach out to directly. Even if it is something as simple as asking how to do something in an automation and it is just not working, they will usually get back to me about that. They are very attentive and very much on top of making sure we have all the resources that we need to do what we need to do.

    Which solution did I use previously and why did I switch?

    I have used Splunk SOAR as an alternative that I can compare Torq to.

    Comparing Torq and Splunk SOAR is tough because it is not exactly an apples-to-apples comparison. Overall, I would still say I probably prefer Torq. There are things I like more about Splunk SOAR, like that it is entirely Python-based, so I feel a lot more comfortable writing custom code in there. However, the way that it handles certain data objects requires designing from a different angle in both tools, and I feel like Torq's angle is a little more intuitive.

    Addressing the specific challenges to our SOC that led us to consider changes before implementing Torq is an odd situation because I was not very involved in that decision. I am just dedicated to development work on this platform, but I do not work for the SOC. They are more or less my customer in a way. I think the primary driver was budgetary concerns, as well as issues with ServiceNow. We have a ServiceNow team managing a lot of this, and our SOC wanted more flexibility and a little bit more control over when they could make changes to their case management or their automations. I am pretty sure that was the main driver—putting some of that ownership back into our security teams, with me being their primary technical resource for it.

    How was the initial setup?

    The initial deployment was super easy. Because Torq is a SaaS solution, there is not a lot that goes into it. They basically spin it up for you and then hand you the keys, essentially. That portion of it was like maybe a day, and there were some internal activities that had to happen for setting up things like SSO on our side. That was not difficult. It is just a big corporation, so it takes time to get all the different teams to do what they need to do.

    What was our ROI?

    I saw the benefits of Torq almost immediately after we deployed it because we transitioned our already existing SOAR workflows from Phantom. Pretty much anything that was running in Phantom is now running in Torq as of day one, so it was immediate savings.

    What's my experience with pricing, setup cost, and licensing?

    I would not be the right person to ask about my opinion on the pricing. That would be my manager.

    Which other solutions did I evaluate?

    Torq's abilities compared to other tools I have looked at are similar in that they all do a lot of the same things. I would say all SOAR platforms are kind of the same, at least in essence, in what they are trying to achieve. What differentiates them really is ease of use, and I would say Torq is probably the easiest one that I have gotten to use so far.

    What other advice do I have?

    In my current field overall, I have been working in SOAR automation and software development specifically for roughly six years.

    I have never really done any maintenance myself. That is all being taken care of by the Torq developers. The only thing I have really helped out with in that regard is bug fix type things where I catch an actual platform bug and then report it.

    I do not know what measurable security outcomes matter most to our leadership team. I do not really talk to management all that much. I code for them and let them worry about the KPIs and other matters.

    Overall, I would give Torq a score of nine out of ten. I think it is fantastic. There are some headaches that come with the platform, and the case management part does have issues, but as a SOAR platform, I think it is fantastic. I give Torq a rating of nine out of ten.

    MANOJCHOUDHARY

    Automation has reduced response times and now improves service management for happy clients

    Reviewed on Sep 27, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Torq is for managing IT services and providing faster response.

    How has it helped my organization?

    One of the workflows I manage with Torq looks good and provides faster response, saving time and resulting in happy clients.

    Torq has not changed the day-to-day experience for my security analysts; they are doing their job quickly and effectively, saving time for other organizations.

    The measurable security outcomes that matter most to my leadership team include Torq helping to show real SOC impact through effective team management.

    It delivered immediate value after I started using it.

    What is most valuable?

    In my experience, the best features Torq offers include IT enterprises data management and data transformation; everything is excellent.

    Regarding Torq's AI capabilities, I find its governance and security are secure, and the AI data governance security is very good.

    In terms of accuracy and reliability of output, I find that Torq has very good accuracy and reliability.

    Torq's unified platform approach to AI SOC automation and case management is good; security points are secure, and data is safe with my organization.

    I have used Torq to automate triage, investigation, and remediation actions across multiple attack surfaces, finding that it performs very well and provides faster response with good latency, saving time compared to other tools.

    My experience with Torq's generative AI in terms of increasing alert handling capacity for my SecOps staff is good.

    What needs improvement?

    What has not worked as well as I hoped with Torq is related to product data management and storing data, although it still provides faster response and saves time.

    I think Torq is a good product as it is.

    For how long have I used the solution?

    I have been using Torq for the past year.

    What do I think about the stability of the solution?

    I find Torq to be stable.

    What do I think about the scalability of the solution?

    The scalability of Torq is very good.

    How are customer service and support?

    Currently, we do not have any challenges in our SOC; if we face any, we contact customer support, and they help very effectively.

    Customer support is also excellent.

    I would rate customer support a 10.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    What was our ROI?

    I have seen a return on investment, including money saved, time saved, and fewer employees needed.

    What's my experience with pricing, setup cost, and licensing?

    I purchased Torq through AWS Marketplace.

    My experience with pricing, setup cost, and licensing is also good.

    Which other solutions did I evaluate?

    We have not evaluated any other option before choosing Torq.

    What other advice do I have?

    I would rate Torq a 10 on a scale of 1 to 10.

    I chose this rating because customer service is excellent.

    I suggest to others looking into using Torq that it provides a positive response, and I recommend they use it as it is a good product that saves time and leads to happy clients.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Consulting

    Agentic Hyperautomation That Slashes Alert Fatigue—No Fragile Code Needed

    Reviewed on Sep 02, 2026
    Review provided by G2
    What do you like best about the product?
    Its agentic hyperautomation actually slashes alert fatigue by handling repetitive triaging instantly, without forcing security teams to write endless, fragile code.
    What do you dislike about the product?
    Despite its hyperautomation, Torq requires a steep initial learning curve, complex pricing with high enterprise entry costs, and debugging nested workflow errors can quickly turn into a headache.
    What problems is the product solving and how is that benefiting you?
    It cuts through endless alert noise and tool sprawl by auto-triaging routine threats, giving analysts their time back to focus on real threat hunting.
    Arnab S.

    Enables IT to Handle Triggers and Alerts with Ease

    Reviewed on Aug 27, 2026
    Review provided by G2
    What do you like best about the product?
    How it can enable IT to deal with lot of triggers and alerts
    What do you dislike about the product?
    Complex license process navigation takes learning curve
    What problems is the product solving and how is that benefiting you?
    To deal with big Enterprise which is tech enables leading to IT disruptions
    Alexandre Becquart

    Automation has transformed incident triage and investigation while freeing analysts for deeper work

    Reviewed on Aug 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Torq is the automation of cyber security processes through a SOAR platform and APIs.

    A main example of how I use Torq for automation would be a classic one: opening of a security incident in an ITSM, bidirectional synchronization, enrichment, and auto-remediation based on closure of the incident. Everything is automated.

    I use Torq for automation of triage, investigation, and remediation actions across multiple attack surfaces such as endpoint, identity, cloud, or IT. It automates the investigation with enrichment such as logs. I do not dive deeper into remediation actions, but they are present, and it automates triage, for example, for phishing incidents. It helps tremendously to have those kinds of data. Its abilities compared to other tools were evaluated through an RFP where we compared multiple tools, and Torq was literally the one, the outsider that stood out, and we chose it. As a technical team, we chose Torq compared to the one that we were using before. We did not start from scratch, as we already had a baseline, and we were searching for a tool that would bring something new to the table with the already existing technical tools that we had, but would bring new innovation and new capabilities. That was the objective, and Torq answered that.

    What is most valuable?

    One of the best features of Torq, I would highlight two main ones. The first one is the capability of transforming an action that you develop yourself, such as an HTTP request that you develop yourself, and make it available as a custom action to all of the other members of the team that you have, which in a sense increases the scalability of the tool and lets the tool be available for people that don't really know the specifics of APIs, HTTP requests, and just know how to click and drop some actions and want to do their small playbooks. Torq is, in a sense, a tool that is ever-evolving based on the usage that you do with it.

    The second one is the look and feel is quite good, and it would be all the AI initiatives that are inside the tool. I can feel that Torq and the company that is behind it are pushing forward what SOAR is, not letting it stale in its current state, and they're pushing it further to make SOAR a new tool in itself by leveraging AI, making it the center of what a SOC is and what incident response is.

    The custom action feature in Torq has helped my team tremendously. For example, SharePoint HTTP requests were quite difficult in one of our scenarios. You only have to do the job once of scraping the documentation, understanding how it works, developing the HTTP request by yourself, and then you can save them, put a meaningful description, and add some dynamic fields that the next person that will use that will find much easier than understanding how the logic is and how the documentation is. For the SharePoint example, it has helped tremendously to deliver automation quickly around SharePoint, CSV file upload, and other related tasks.

    Torq has impacted my organization positively by allowing us to earn time and invest resources in other projects that are more meaningful and more interesting, pushing deeper into what a SOC is, and building our processes. Torq is a good way to reinvest time in something more interesting, whether for the humans, for the analysts, or for the company in a more secure way. This is what automation brings: interesting subject matter, new capabilities, and more time, fundamentally.

    It is quite difficult to quantify, but a good example would be a playbook that is automatically analyzing a phishing incident developed with Torq. It frees up approximately 200 or 250 incidents per week or per month. You take one incident, which took about five minutes to ten minutes, and multiply that across all incidents. The human cost is also significant, such as the fatigue of doing always the same incident, always the same things. This is not easily measurable, but I think it is important to highlight that as it may sometimes be the best resource, the best gain that Torq can bring to the table.

    What needs improvement?

    There are some bugs in Torq, of course. They can be present in data transformation, some UI debugging, and other areas that can be improved. There are some ideas, and Torq always takes them into consideration. Unfortunately, they are currently focused too much on AI and how the tool is evolving. I can understand because this is how they can keep their head above the water and ahead of all the other tools. This is how they can be this disruptive and interesting for companies. However, it is also important to have some good bases, some solid baselines. There are some issues and bugs that I think need to be fixed, but they are currently not focused on it. The tool is working overall. It is doing what we need. No tool can be perfect, and there is room for improvement, but Torq is already quite far advanced compared to others in the market.

    One of the things that I think would be the most interesting for Torq is the ability, when you are debugging, when you have a crash in a playbook, to rerun the playbook from the step that has crashed. This is not implemented, and it is painful to relaunch a playbook manually and do everything when you have actions inside a playbook that have impact. For example, if you reset the token of a user and then the playbook crashes, and it was supposed to send a notification in Teams or add the user to a specific table, just to have the information, you want to have this information, but you don't want to relaunch the whole playbook because it will reset the token of the user again. This is an example where it is quite important, but the feature is lacking.

    For how long have I used the solution?

    I have been using Torq for approximately one year to a year and a half.

    What do I think about the stability of the solution?

    Torq is stable.

    What do I think about the scalability of the solution?

    The scalability of Torq is quite good. The customer support is quite responsive and helpful. Most cases are handled in less than a week.

    How are customer service and support?

    I would rate the customer support a four. They are present and help a lot.

    Which solution did I use previously and why did I switch?

    I previously used Logic App from Microsoft. The two main pain points were the number of connectors available with built-in actions. We needed to redevelop every HTTP request every time that we started to create a new playbook. Scalability was not present in that case. Additionally, the tool was quite stale. It did not move a lot in the last year. It has started to move a bit now, but when we were doing the RFP and thinking of changing, we wanted a tool that has a roadmap, innovation, and people that were working on it.

    What's my experience with pricing, setup cost, and licensing?

    Pricing is pretty straightforward and adaptable based on what you need and what you want to use. The pricing is based on the number of playbooks that you have, which makes it interesting based on how you design your SOC's architecture and makes you spend more time on how you want to design your automation SOCs.

    What other advice do I have?

    Regarding someone thinking about using Torq, I recommend looking into their provided academy to start working with the tool and understand how JQ works, how the sprig function works, and not diving directly into automation without being sure that your processes and what you want to automate have already been tested out and are a good return on investment for the time that your SOAR team will spend on it. I would rate this review as an 8 out of 10.

    View all reviews