Summary
- Sekoia says Elevate completed more than 425,000 autonomous investigations during early access.
- The system gathers evidence and returns audit-ready verdicts that analysts can inspect, correct, or override.
- The launch moves agentic security tooling further from summarisation towards delegated operational investigation.
French cybersecurity company Sekoia has moved its Elevate agentic investigation platform into general availability after an early-access programme that the company says reached more than 2,000 customers.
The launch is more consequential than another supplier adding an AI assistant because of the work Sekoia is delegating to the system. Elevate is designed to investigate alerts, collect and correlate evidence, and produce a verdict for analysts to review.
Sekoia says the platform completed more than 425,000 autonomous investigations during early access. It also says each investigation creates a traceable record of the searches and evidence behind the verdict, while analysts can correct or override conclusions.
Those figures are vendor-reported and have not been independently audited.
The product nevertheless illustrates a wider change in security operations tooling. Early generative-AI products were largely used to summarise alerts, explain technical data, or help analysts write queries. Agentic platforms are increasingly being asked to perform significant parts of an investigation before a person becomes involved.
That creates a different procurement and governance problem. Detection accuracy remains important, but customers also need to understand which data an agent can access, what actions it may take, how its conclusions are recorded, and what happens when the automated judgement is wrong.
Sekoia’s current Elevate documentation emphasises human review of investigation verdicts. Analysts receive the evidence, confidence assessment, and reasoning context and can override the result.
The wider Sekoia platform also advertises response capabilities that can isolate hosts, disable credentials, or block activity, illustrating how quickly agentic systems can move from interpreting an incident towards affecting production environments.
The risk changes materially at that point. A flawed summary may waste an analyst’s time; an incorrect containment decision can interrupt systems, lock out legitimate users, or alter evidence during an investigation.
European customers also face governance obligations that extend beyond model performance. Organisations operating under DORA, NIS2, data-protection requirements, and internal audit regimes may need to show how a security decision was reached and preserve evidence around material incidents.
Auditability is therefore becoming part of the product proposition for agentic security. Sekoia is explicitly marketing traceable evidence and analyst override as part of Elevate rather than treating them as supporting features.
The market is already crowded with suppliers promising AI agents that reduce security-operations workload. That makes the boundaries of an agent more useful than the label itself. Procurement teams need to distinguish between a system that retrieves information, one that forms an investigative judgement, and one that is authorised to make consequential changes in production.
Sekoia’s early-access statistics do not independently establish that autonomous investigations are more accurate or more effective than conventional workflows. Evidence from production use, including false verdicts, escalation rates, and human reversals, will be more useful for that assessment.
The launch does, however, put another European provider into a market where AI is moving from an advisory interface towards an operational actor. Customers will increasingly need to govern those systems on the basis of authority, evidence, and accountability rather than simply model capability.





