French SIEM, SOAR and threat intelligence platform, formerly Sekoia.io, built around AI SOC agents
Review by EuropeanStack EditorialUpdated Verified
Sekoia has a clear argument: a European SIEM, SOAR, and threat intelligence platform that treats portability and automation as design goals. It is worth shortlisting against Splunk, and because SentinelOne also sells a SIEM, Singularity AI SIEM, it is relevant to SentinelOne buyers too. The caveats matter. Pricing is opaque, residency depends on the region you choose, support runs through a portal with no published hours, and the agentic AI claims lack independent proof. Run a proof of concept on your own data before signing.
Sekoia, known as Sekoia.io until its June 2026 rebrand, is a French security operations platform combining a cloud-native SIEM (Sekoia Defend) with built-in SOAR playbooks, cyber threat intelligence (Sekoia Intelligence), asset discovery (Sekoia Reveal) and AI SOC agents (Sekoia Elevate). It is sold to security teams and to managed security service providers through a multi-tenant design.
Headquarters
Rennes, France
Founded
2022
Pricing
Employees
51-200
Contact Sales
Contact Sales
Contact Sales
Contact Sales
Billing: quote-based contract
A security operations centre drowns in alerts long before it runs out of tools. Analysts triage hundreds of events from firewalls, endpoints, and cloud services, most of them benign, while a SIEM bill grows with every log source added. Sekoia, known as Sekoia.io until June 2026, sells a way out of that pattern: a single cloud-native platform that combines detection, automation, threat intelligence, and AI agents that investigate alerts on the analyst's behalf.
The company is French. Its registered company is SEKOIA.IO SAS (SIREN 913 174 744) in Rennes, with an office in Paris. The company register dates the current SAS to 3 May 2022, while FrenchWeb's 2020 funding coverage traces its roots to a security services firm founded in 2008 whose platform launched in early 2020. Its leadership team is CEO Freddy Milesi, CTO Georges Bossert, and CFO Thérèse Favet. In June 2026 it rebranded to Sekoia, adopted the sekoia.com domain, and began calling its platform an Autonomous Agentic SOC.
Funding came in three announced rounds. Omnes and Alliance Entreprendre backed a β¬10 million round in October 2020, according to FrenchWeb. A β¬35 million Series A in May 2023 brought in Banque des Territoires, Bright Pixel, Omnes, Seventure, and BNP Paribas DΓ©veloppement. The β¬26 million Series B on 9 April 2025 was led by Revaia, with UNEXO, Bright Pixel, Omnes, and Bpifrance, according to Omnes's press release. That release says the round brought total fundraising to β¬60 million, the figure Sekoia's about page also uses. Added together, the announced rounds come to β¬71 million, so the company's own figures are inconsistent and we do not know which is right.
Four modules make up the platform. Defend is the SIEM with native SOAR playbooks, and Intelligence is the threat intelligence feed. Reveal discovers assets and maps alerts to them, while Elevate adds AI SOC agents. It targets in-house security teams and managed security service providers (MSSPs) alike.
Sekoia Defend collects and analyses security logs in the cloud and wraps SOAR playbooks around the results. Detection logic uses Sigma rules, the open format shared across much of the industry. Data is normalised to OCSF, and analysts hunt with an Events Query Language.
The practical benefit is portability. Detection content written in Sigma is not trapped in a proprietary query dialect, which lowers the cost of leaving. Playbooks automate response steps such as enriching an indicator or disabling an account. They can also post notifications to a webhook, which the documentation illustrates with Slack and Microsoft Teams.
The company's own pages are inconsistent about integration counts, citing 40-plus on its homepage and 300-plus on its about page. Its documentation describes an API-first design with hundreds of pre-built integrations. Check your specific log sources against the catalogue rather than relying on either number.
Intelligence supplies information on attacker infrastructure and campaigns, produced by the company's threat research team. It works standalone or alongside Defend, where it enriches alerts with context. The vendor says more than 1,500 detections are enriched with intelligence.
Fusing threat intelligence with detection is the company's historical strength. Many SIEM buyers have to purchase and wire together a separate intelligence feed. Here it is part of the same product family, which also suits MSSPs who need current indicators for many customers.
Elevate is the newest module and the centre of the rebrand. According to the vendor, agents investigate each alert against context from Reveal (assets), Intelligence (external threat data), and Defend (detections and cases). They can isolate hosts, disable credentials, or block activity automatically, or after a one-click approval.
The vendor publishes figures for it: 90% less manual triage effort, 10 times faster response workflows, and 24/7 analysis. We found no independent benchmark behind those numbers. Treat them as marketing until you test the agents on your own alert volume.
The human-approval option is the sensible default. Letting an agent disable a production account automatically is a decision your risk team should make deliberately. The feature is promising, but agentic SOC tooling is new across the industry and the public evidence base is thin.
Sekoia built multi-tenant communities for MSSPs, so a provider manages many customer environments from one platform. The company says it is recruiting service partners and expanding its managed SOC offering. For an in-house team with a single environment, this matters less.
Sekoia does not publish prices. The website carries no pricing page, and the modules are quoted through sales, either separately or as a platform. Defend, Intelligence, Reveal, and Elevate can be bought in combination, and MSSPs have their own partner programme.
We could not find an official statement of the pricing metric, so we cannot tell you whether the bill follows assets, data volume, or something else. That is the first question to ask in a quote. Splunk has historically priced by data ingested, so a SIEM that decouples cost from volume would be a meaningful advantage. Confirm it in writing before assuming it.
The value case is consolidation: one contract for SIEM, SOAR, and threat intelligence rather than three. Gartner Peer Insights lists Sekoia Defend at 4.8 stars, but the sample is small, at 13 ratings in the listing we saw. Capterra shows just 3 users. Without public prices or large review samples, buyers must rely on a proof of concept.
Sekoia is a French company and subject to EU law, but its hosting is a choice rather than a default. The documentation lists six regions. FRA1 is in France on OVH, FRA2 is in France on OVH SecNumCloud, and MCO1 is in Monaco on MonacoCloud. UAE1 is in Dubai on Azure, USA1 is in Virginia on OVH, and SGP1 is in Singapore on OVH and Akamai. The docs don't explicitly name a default region, though FRA1 (France, OVH) uses the base app URL.
That is why we omit the EU-hosting flag on this entry. A customer who picks FRA1 or FRA2 keeps data in France. Picking Monaco, which is not an EU member, or Dubai, Virginia, or Singapore does not. Confirm the region in your contract.
FRA2 is the notable option. The documentation describes it for organisations that need PCI DSS compliance and French hosting, on a SecNumCloud-qualified environment. SecNumCloud is the French ANSSI cloud standard designed to shield data from extraterritorial laws.
Sekoia's Trust Center lists ISO/IEC 27001:2022, SOC 2 Type 1 and PCI DSS, plus alignment with GDPR, NIS2, DORA and Spain's ENS. Note that SOC 2 Type 1 assesses whether controls are designed properly at a point in time, not whether they operated effectively over a period, which is what a Type 2 report covers. DPAs, a sub-processor list and a pentest report are also published there, with several documents behind an access request. Request the certificates and their scope statements during due diligence.
Mid-size and large French and EU security teams replacing a legacy SIEM. If you want a European SIEM with SOAR and intelligence built in, Sekoia is a strong candidate. Ask for FRA1 or FRA2 in writing.
MSSPs and managed SOC providers. The multi-tenant design and the partner programme fit service providers better than a single-tenant tool would.
Teams running a French stack. Sekoia receives events from HarfangLab through a syslog connector, and Sekoia playbooks can act on HarfangLab endpoints. The pairing covers endpoint and SIEM with two French vendors.
Not the best fit for organisations deeply invested in Splunk apps and custom dashboards, where migration effort is high. Teams wanting one vendor for endpoint, SIEM, and honeypots might prefer TEHTRIS, and open-source-minded teams may look at Elastic. Wider options appear in the cybersecurity category.
Sekoia has a clear argument: a European SIEM, SOAR, and threat intelligence platform that treats portability and automation as design goals. It is worth shortlisting against Splunk, and because SentinelOne also sells a SIEM, Singularity AI SIEM, it is relevant to SentinelOne buyers too. The caveats matter. Pricing is opaque, residency depends on the region you choose, support runs through a portal with no published hours, and the agentic AI claims lack independent proof. Run a proof of concept on your own data before signing.
Yes. Sekoia.io rebranded to Sekoia in June 2026 and now uses sekoia.com. The legal entity is still SEKOIA.IO SAS, registered in Rennes, and the platform keeps its Defend, Intelligence, Reveal and Elevate modules.
It depends on the region you choose. The documentation lists six regions: two in France on OVH (FRA2 is SecNumCloud), Monaco, Dubai, Virginia in the US, and Singapore. Choose a French region for EU residency, because Monaco is not an EU member.
It is worth shortlisting. Sekoia Defend is a cloud-native SIEM with SOAR playbooks, and SentinelOne also sells a SIEM, Singularity AI SIEM. Splunk has a far larger app ecosystem, so check that your data sources and detections are covered before migrating.
Sekoia does not publish prices and quotes through sales. The modules, Defend, Intelligence, Reveal and Elevate, are sold separately or together, and managed security providers have their own partner programme.
Yes. The platform has multi-tenant communities designed for MSSPs, and the company says it is recruiting service partners to grow its managed SOC offering. Vendor support runs through the support.sekoia.io portal with no published hours, so confirm out-of-hours coverage in your contract.
Award-winning cybersecurity solutions for consumers and enterprises
Alternative to Norton, Mcafee, Crowdstrike
Client-side encryption for your cloud storage files
Alternative to Dropbox, Google Drive
Search, observability, and security platform built on Elasticsearch and the ELK Stack