What is SynapCores SOAR?+
SynapCores SOAR is an open-core SOAR (Security Orchestration, Automation and Response) platform that runs the autonomous SOC. The application is a Node.js/TypeScript service; the data tier is SynapCores, our AI-native database. It deploys as a docker-compose stack you self-host, or as managed cloud we operate for you. It includes a property-graph engine for asset and identity correlation, AI agents for autonomous Tier-1 triage and IR playbook execution, vector search for similar-incident retrieval, and an immutable audit log for forensic and regulatory defensibility.
How is SynapCores SOAR different from Tines or Torq?+
Tines and Torq are closed-source SaaS workflow engines with per-action pricing that gets expensive as you automate more. SynapCores SOAR is open-core (the application source is public on GitHub), available as managed cloud or self-hosted, and priced per analyst seat with no per-action tax. It also ships with a graph engine, vector search, and an immutable audit log built into the same database — capabilities you would otherwise stitch together from Neo4j, Pinecone, and a custom audit service.
Does SynapCores SOAR replace my SIEM?+
No. SynapCores SOAR sits beside your existing SIEM (Splunk, Datadog, Microsoft Sentinel, Chronicle) and EDR (CrowdStrike, SentinelOne, Defender). It ingests alerts via webhook, enriches them with graph and vector context, runs autonomous IR playbooks, and writes back to your stack via API. Your SIEM keeps log retention; we add the autonomous-SOC brain on top.
What does "open-core" mean — do I need a devops team to run it?+
No devops team required. The SOAR application source is public on GitHub — every connector, every agent persona, every playbook is reviewable code under a permissive license. To run it: one `docker compose up` brings up the stack (SOAR app + SynapCores) on your infrastructure in about 30 seconds. If you would rather not host anything, Enterprise includes managed cloud — we operate it, you log in. Open-core means the code is honest; how you consume it is your choice.
Can my SOC 2 Type II auditor use SynapCores SOAR directly?+
Yes. SynapCores SOAR exposes a scoped MCP (Model Context Protocol) token that an external auditor can paste into Claude, Cursor, or any MCP-compatible LLM. The auditor queries the immutable audit log, incidents, and evidence packs directly using natural language. Every query the auditor runs is itself logged in your tamper-evident audit trail. This collapses the typical four-to-six-week Type II evidence-collection cycle to a token and a chat session.
What data sources does SynapCores SOAR ingest from?+
SIEMs (Splunk, Datadog, Microsoft Sentinel, Chronicle, Elastic, Sumo Logic), EDR/XDR (CrowdStrike, SentinelOne, Microsoft Defender, Carbon Black, Sophos), identity providers (Okta, Azure AD, AWS IAM, GCP IAM, Google Workspace), cloud audit logs (AWS CloudTrail, GCP Audit, Azure Monitor), email security (Proofpoint, Mimecast, M365 Defender, Abnormal), vulnerability scanners (Qualys, Tenable, Wiz, Snyk), ticketing (ServiceNow, Jira, PagerDuty), and threat intelligence feeds (MISP, OpenCTI, Recorded Future, STIX/TAXII).
What actions can the agents execute?+
Isolate endpoints (CrowdStrike, SentinelOne, Defender), disable users and revoke sessions (Okta, Azure AD), block IPs and domains (Cloudflare, Palo Alto, Zscaler, Cisco Umbrella), snapshot disks and capture memory (AWS, GCP, Azure, Velociraptor), quarantine emails (Proofpoint, Mimecast, M365), create and update tickets (ServiceNow, Jira, PagerDuty), and post to channels (Slack, Teams, PagerDuty). High-blast-radius actions stop and ask for human approval by default.
Where is my SOC data stored?+
Wherever you decide. Self-hosted: everything — alerts, identities, asset graphs, playbook state, audit logs — lives in your infrastructure inside the SynapCores RocksDB-backed engine. No customer data leaves your network. Managed cloud: dedicated single-tenant SynapCores instance in your chosen region, ours to operate, yours to query and export. Embedding generation and LLM inference can run locally on the bundled native model or be routed to your chosen provider — your choice, your contract, your data residency.
What does pricing look like?+
Open-core: no license fee for the self-hosted application. Enterprise is per-analyst-seat with no per-action tax — the wedge against incumbents that charge per workflow execution. Enterprise covers managed cloud hosting, 24/7 support and on-call escalation, a certified playbook library with 50+ pre-built workflows, the SOC 2 Type II auditor portal, compliance certifications (SOC 2, ISO 27001, FedRAMP roadmap), and dedicated solution engineering.
When will SynapCores SOAR be generally available?+
The open-source repository is live at github.com/SynapCores/synapcores-soar. General availability of the full enterprise tier is targeted for Q4 2026. Join the waitlist to lock in design-partner status, get architecture-review access, and shape the playbook library.