Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
Choosing a platform

Soarcery vs Torq. One agent that investigates, compared to an orchestrator that delegates.

Torq built Hyperautomation into an agentic SOC platform: Socrates orchestrates a system of specialized HyperAgents on top of a no-code workflow engine. Soarcery is a single accountable agent, the Familiar, that investigates a case end to end, with automation that runs only after a human reviews the plan. Here is where each earns its place, sourced from both companies' own materials.

Torq
Soarcery
Core idea
An agentic orchestrator, Socrates, plans and delegates to specialized Torq HyperAgents, layered on the Torq Hyperautomation no-code workflow engine.12
One agent, the Familiar, investigates a case end to end. Spells are plan-first automations a human reviews before they run.
The thinking
Socrates is described as "the agentic quarterback, calling, delegating, reasoning and building the Torq HyperAgents needed to take action," grounded in a Context Graph and memory layer.13
The Familiar reasons through the full Investigation itself and cites its evidence, informed by a native multi-engine verdict spread rather than a single scan result.
The acting
HyperAgents execute across 300 pre-built integrations and 4,000+ pre-built steps. Torq states its platform helps teams "Close Over 90% of Security Cases. Autonomously."2 Human review is framed as a configurable dial: "the balance between human and AI decision-making is a dial, not a switch."3
The Seal is the default gate: consequential actions wait on explicit human approval, every time, with a receipt. It is not an opt-in setting.
Maintenance
The underlying Hyperautomation engine is no-code, and the newer Agentic Builder turns natural-language intent into "production-ready Torq HyperAgents," reducing but not eliminating the workflow-authoring step.1
Spells are described in plain language. There is no flowchart to redraw when a connected tool changes shape.
Auditability
Torq states "every reasoning step, every verdict, and every action is logged."3 Its own case management page states "low-confidence cases can be auto-closed or merged" while "high-confidence cases are escalated with full context attached," and that "every state change is logged."4
The Seal's approval receipts form one replayable trail per Investigation: evidence, reasoning, the approver, and the action, in one place.
Where it wins
A materially larger connector library today (300 integrations, 4,000+ steps), enterprise deployment history at named large-enterprise customers, and a workflow engine teams can port existing playbooks into.25
Investigation depth from a single accountable agent, a native multi-engine verdict spread, and an approval gate that ships as the default rather than a configuration choice.
Honest risk
"Over 90% autonomous" is a platform-wide figure from Torq's own marketing, worth asking what fraction of your case mix that applies to and where the human dial is set by default in your deployment.2 Pricing is not public: engagement starts with a sales conversation, and AI usage is metered separately through an AI Credits system on top of the base contract.67
Soarcery is a newer platform. It has not run at Torq's enterprise scale or integration count yet, and that gap is real.
The architectural difference

Where the two platforms actually diverge.

One agent versus an orchestrator delegating to a system of agents

Torq's model is a coordination layer. Socrates sits as "the core orchestrator of the Torq AI SOC Platform, planning and coordinating specialized Torq HyperAgents to investigate, reason, and take action across the threat lifecycle."1 That means a case can pass through several specialized agents, each with its own role, authority, and limits, before Socrates assembles the outcome. Soarcery takes the opposite bet: one agent, the Familiar, carries the Investigation from first alert to final recommendation itself. There is no hand-off between specialized sub-agents to reason about or configure guardrails for. One reasoning trail, one accountable agent, per case.

Where the automation lives

Underneath Socrates sits Torq's Hyperautomation engine: a no-code workflow builder with 300 pre-built integrations and 4,000+ pre-built steps.2 The newer Agentic Builder lets a user "describe needs in natural language," after which "Socrates plans the approach, selects appropriate tools and integrations, and defines guardrails, turning natural language intent into production-ready Torq HyperAgents."1 Generating a workflow from a prompt is a real improvement over hand-drawing one, but the artifact produced is still a workflow that has to be reviewed and maintained as your stack drifts. Soarcery's Spells are plan-first by design: the Familiar proposes a plan in plain language, a human reviews that plan before it ever executes, and the Seal enforces approval on the consequential steps regardless of how the plan was generated.

The default posture: autonomy-first versus approval-first

Torq's own materials lead with autonomy. The platform's positioning states it helps teams "Close Over 90% of Security Cases. Autonomously,"2 and frames human oversight as adjustable: "the balance between human and AI decision-making is a dial, not a switch."3 That is an honest and defensible design choice, and Torq does log reasoning steps and support human-on-the-loop review.3 Soarcery starts from the other end. The Familiar investigates and recommends, but the Seal is the default gate on consequential actions, not a dial an admin has to remember to turn down. Every approval produces a receipt, every time, with no configuration required to get that behavior.

Where Torq wins

To be fair to a platform with real scale behind it.

  • A materially larger connector library today. 300 pre-built integrations and 4,000+ pre-built steps is a lot of ground already covered, and it matters on day one of a deployment.2
  • Proven enterprise deployment history. Torq's customer logos include named large-enterprise customers, a credible, referenceable track record a newer entrant does not yet have.25
  • A mature workflow engine for teams with an existing playbook library. If your SOC already has a large investment in built-out Torq workflows, an Agentic Builder that can extend them from natural-language prompts is a genuine productivity gain, not just marketing.1

Fair fight

If your SOC already runs on a substantial library of Torq workflows, migrating away from that investment is a real cost. Soarcery is the better fit when what you want is one agent that reasons through a full Investigation end to end, a native multi-engine verdict spread informing that reasoning, and an approval gate that is the default behavior, not a setting someone has to remember to configure.

Settle it with evidence

Watch the difference on a real case.

Three minutes, ungated. Then bring your own alerts and compare for real.

Sources

Where this comparison comes from.

Every claim about Torq above traces back to one of these, almost entirely Torq's own site and product pages, confirmed by direct fetch where noted.

  1. 1Torq, "Socrates: Agentic AI in the SOC", torq.io/socrates. Orchestration model, "agentic quarterback" quote, Agentic Builder natural-language workflow generation.
  2. 2Torq, "The Torq AI SOC Platform", torq.io/ai-soc-platform. "Close Over 90% of Security Cases. Autonomously," 300 pre-built integrations, 4,000+ pre-built steps, Universal Auto Triage, customer logos.
  3. 3Torq, "Torq HyperAgents", torq.io/hyperagents. Context Graph and memory, "dial, not a switch," "every reasoning step, every verdict, and every action is logged," human-on-the-loop reviews.
  4. 4Torq, "Torq Case Management: Built for Enterprise-Scale SOCs", torq.io/blog/torq-enterprise-case-management. "Low-confidence cases can be auto-closed or merged; high-confidence cases are escalated with full context attached," "every state change is logged." Confirmed by direct fetch.
  5. 5Torq homepage, torq.io. Headline and customer logos, including named large-enterprise customers.
  6. 6Torq, demo request page, torq.io/demo. No public list pricing page found, engagement is sales-gated.
  7. 7Torq Knowledge Base, "AI Pricing Model: Monitor and Track AI Credit Consumption", kb.torq.io. AI Credits usage-based pricing layer on top of the base contract.