Companies

Crogl

crogl.com

Crogl deploys autonomous, auditable AI agents that investigate enterprise security alerts without moving customer data.

HQAlbuquerque, New Mexico, United States
Employees11-50
Funding$30M
6 active roles
Profile 6mo agoJobs checked 21m ago
AI / MLAI ApplicationB2B SaaSSeries A$10M-$50M

About

Crogl builds autonomous AI agents and a knowledge engine for enterprise security operations, investigating alerts, threat advisories, and cross-tool data for SOC teams. It sells to large enterprises, financial institutions, and government organizations, differentiating through customer-managed on-premises or air-gapped deployment, no required schema normalization, and fully auditable investigations.

Market

Crogl competes in the AI-SOC and security-operations-automation market, automating alert investigation, threat hunting, endpoint analysis, cloud-posture work, phishing response, and advisory analysis. It differentiates from conventional SIEM/SOC automation and other AI-SOC platforms through a compound neurosymbolic architecture combining knowledge graphs, multiple models, agentic orchestration, and native integrations, while supporting customer-managed on-premises, private-cloud, and air-gapped deployment so security data remains inside the organization.

Target Customers

Crogl targets enterprise security operations teams, especially federal and classified agencies, critical-infrastructure operators, regulated industries, hybrid/cloud-first organizations, and Fortune 500 financial institutions with strict data-sovereignty requirements. Primary users and buyers are SOC analysts, security leaders, and enterprise security practitioners.

At a Glance

Problem

Crogl addresses the capacity and coverage problem in enterprise security operations centers. SOCs receive thousands of alerts daily, but analysts can investigate only a small fraction; Crogl cites an average of 4,500 alerts per day versus roughly eight to 25 investigations per analyst, leaving many alerts unanalyzed. The work is labor-intensive and repetitive—collecting context from multiple tools, querying data sources, cross-referencing threat intelligence, and documenting decisions—while more experienced analysts spend hours on routine triage and genuinely complex threats wait in the queue.

The clearest or “killer” use case is autonomous alert triage and investigation. Crogl is designed to investigate every alert, determine whether it is benign or threatening, document the result, and escalate high-confidence or complex cases with the relevant context already assembled. A related pain point is proactive threat hunting: reactive triage consumes most SOC capacity, so organizations rarely hunt continuously for emerging threats.

Product / Service

Crogl is an agentic AI security platform that conducts end-to-end investigations across an organization’s existing security stack. Its knowledge graph maps users, assets, behaviors, relationships, access patterns, and history, then enriches an alert before investigation begins; the orchestration layer plans and executes the workflow, while native integrations query SIEMs, EDRs, data lakes, cloud logs, ticketing systems, and threat-intelligence sources without requiring schema normalization. Crogl’s stated benefit is to turn a queue item into an auditable decision: benign alerts can be closed with documentation, while serious threats reach analysts with evidence and impact context already prepared.

The delivery model is customer-managed rather than a conventional hosted-only service. Crogl can run on-premises, in a private cloud, or in an air-gapped environment, with no security data leaving the customer’s infrastructure. As of its May 2026 pricing model, a single-user Free edition is available at $0 with integrations, skills, and an audit trail, while the Enterprise edition uses custom annual pricing and adds autonomous investigations and threat hunting, multi-user SSO/RBAC, enterprise-model support, and dedicated support.

Market

Crogl competes in the AI SOC-agent and broader security-operations-automation market, with adjacency to SIEM and SOAR platforms. G2 categorizes its alternatives across AI SOC Agents, SIEM, and security-orchestration software and names Splunk Enterprise Security, Intezer, and Torq AI SOC Platform among the leading alternatives; PeerSpot specifically compares Crogl with Dropzone AI in the AI-SOC category. The competitive distinction Crogl emphasizes is an end-to-end, knowledge-graph-driven investigation system that works across existing tools rather than a standalone alert filter or a playbook-only automation layer.

Crogl has meaningful early traction but the gathered evidence does not establish revenue or a total customer count, so it should not be confidently labeled pre-revenue. The company announced a $5 million seed round and a $25 million Series A led by Menlo Ventures in March 2025, launched a free downloadable platform in May 2026, and reports production use by a U.S. defense agency investigating 60,000 alerts per month across three SIEMs and two SOARs, with a claimed six-FTE-equivalent productivity gain. Crogl also says it is deployed in air-gapped federal environments, critical infrastructure, and Fortune 500 financial institutions; these are company-reported signals rather than independently verified revenue metrics.

Founders & Leadership

Monzy MerzaFounder
Founder & CEO
David DorseyFounder
Co-Founder & CTO
Ryan BurkeVP Worldwide Sales

Funding History

2025-03
Seed$5M

Tola Capital, Firestreak Ventures

2025-03
Series A$25M

Menlo Ventures

Recent News

2026-07-30product
Crogl Announces Its Sovereign AI SOC Agent Is Available as a Free Download

Crogl announced general availability of its Enterprise AI SOC Agent as a free download. The sovereign platform runs on-premises, in customers’ clouds, or in air-gapped environments and supports autonomous investigations, threat hunting, and reporting; Crogl also announced presentations with AWS, Cribl, Palo Alto Networks, Splunk, Reality Labs, ReversingLabs, and ZeroFox at Black Hat USA 2026.

2026-06-11
Monzy Merza of Crogl on Pushing the Boundaries of AI

Authority Magazine interviewed Crogl CEO Monzy Merza about overcoming competency barriers in cybersecurity AI and moving from promising demonstrations to operationally reliable security systems.

2026-05-19
In Conversation with Monzy Merza on the Rise of the Agentic SOC

Digital Digest interviewed Crogl CEO Monzy Merza about agentic SOC architecture, the limits of traditional automation, Crogl’s knowledge engine, and the importance of data sovereignty.

2026-05-11product
Crogl Launches First Free Enterprise-Grade AI SOC Platform, Giving Security Teams Instant Access During Breaches

Crogl launched a free enterprise-grade agentic system for security operations, allowing teams to download the platform, connect it to their environments, and begin investigations and threat hunts within minutes. The initial free version was described as a fully functional single-user deployment, with enterprise features planned for the broader offering.

2026-04-02
AI-Enabled SOC Operations: From Alert Overload to Autonomous Investigation

ITSPmagazine covered a discussion with Crogl CEO Monzy Merza at RSAC Conference 2026 about practical AI-enabled SOC operations and the transition from AI marketing claims to autonomous investigation.

2026-03-25
Every Cybersecurity Breach Has a Warning — Monzy Merza on Inside the Silicon Mind

Inside the Silicon Mind featured Crogl CEO Monzy Merza discussing his path from national-lab and enterprise security leadership to Crogl, the limitations of alert-driven operations, and the role of AI in reducing analyst overload.

2026-03-18
New Research Reveals Enterprises Investigate Just 37% of Daily Security Alerts as AI Expands in the SOC

Crogl announced research examining alert overload, AI effectiveness, and third-party data concerns in security operations. The findings reported that enterprises investigate only 37% of daily security alerts, highlighting integration and governance challenges for AI adoption.

2026-02-18
Crogl Named “Awardable” on DoD CDAO Tradewinds Solutions Marketplace

Crogl announced that it had been designated “Awardable” on the Department of Defense CDAO Tradewinds Solutions Marketplace, enabling DoD organizations to engage the company through streamlined procurement for AI and data solutions.

2026-01-08
AI SOC Summit Announced — Inaugural Practitioner Event for AI in Security Operations

Crogl announced the AI SOC Summit, a practitioner-focused event intended to address real-world AI capabilities in security operations and distinguish them from marketing claims. The inaugural event was scheduled for March 3, 2026, in Tysons, Virginia.

2025-11-11
Crogl Granted Patent for Analyzing Non-Normalized Data for Security

Crogl announced receipt of U.S. Patent US12277177B1, covering technology that allows its knowledge engine to traverse and interrogate security data across different sources without requiring data normalization.

Active Roles

6
Los Ranchos/Engineering/34d ago
United States/Engineering/59d ago
United States/Engineering/65d ago
United States/Sales/66d ago
United States/Forward-Deployed Engineer/119d ago
United States/Engineering/125d ago

Business Model

Crogl offers a free $0-on-premises or self-hosted version for individual analysts, then monetizes SOC teams through custom-priced annual Enterprise contracts. Enterprise customers can also receive volume pricing, autonomous execution, multi-user access, dedicated support, SLAs, SSO, and RBAC.

Products

Crogl AI platform for security operations / autonomous AI SOCSOC automation workflows for alert triage, endpoint investigation, threat hunting, cloud posture, phishing response, and advisory analysisFree single-user deployment for rapid investigations and threat huntsEnterprise edition with multi-user collaboration, SSO, role-based access control, onboarding services, and advanced model management

Tech Stack

Knowledge graphsLarge language models (LLMs)Multiple/task-specific AI modelsAgentic orchestration and autonomous AI agentsNeurosymbolic AI architectureNative tool integrations with SIEM, EDR, ticketing, and data-lake systemsSelf-hosted inference and enterprise LLM services

Competitors

Splunk Enterprise Security
Intezer
Torq AI SOC Platform
Dropzone AI

Key Investors

Menlo Ventures, Tola Capital