Draft 0.1 · Open for public comment until Wednesday, November 11, 2026

The AI SOC Truth Test · Draft 0.1

AI SOC claims,
measured.

Every SOC vendor now says “AI-powered,” and many say “agentic.” The AI SOC Truth Test gives MSPs and MSSPs five questions to check any of those claims. CYREBRO AI created the test, so we’ve published our own answers first.

Read it in under a minute No sign-up to read it Download draft 0.1 (PDF)

Disclosure: CYREBRO AI created the AI SOC Truth Test and is one of the platforms it measures. This is an open draft (version 0.1), not independent or neutral third-party research. It publishes measurements and gives no grades, rankings, badges or endorsements. How it’s governed

Why this exists

“AI-powered” is on every SOC. What it means isn’t.

If you’re building your business on someone else’s SOC, you need a simple way to tell real automation from a new label on the same work. Until now there hasn’t been one.

Gartner calls the gap “agent washing”

“the rebranding of existing products, such as AI assistants, robotic process automation (RPA) and chatbots, without substantial agentic capabilities.”

Gartner, Inc., “Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027,” press release, June 25, 2025.

Five questions, same for everyone

Zero-touch rate, alert time, human role, build burden and multi-tenant readiness. Any platform should be able to answer them.

We answer first

A company that calls out agent washing has to show its own work. CYREBRO AI’s initial answers are published below.

Open to challenge

This is draft 0.1. Comment on it until November 11, apply to the independent review panel, or submit your platform for version 1.0.

The five measures

Five questions any AI SOC should be able to answer

Here’s the one-minute version. Open any measure below to see how draft 0.1 defines it, what a vendor should publish, and the open question we want your view on.

Using these with a vendor? Copy them straight into your RFP or vendor questionnaire.

Zero-touch rate

Of all the alerts the platform handles, what share does it take from first signal to closed verdict with no human touching them?

Why it matters

It’s the plainest test of “agentic.” If people still review most alerts, the AI is assisting, not operating.

How draft 0.1 measures it

The share of alerts, over a stated period, that reach a final verdict and are closed without any human action. Any human review, approval, edit or reopening counts as a touch.

What a vendor publishes

The rate, the period it covers, the number of alerts in that period, and what the vendor counts as a touch.

Source

The vendor’s own reporting or public claims, with the source stated.

Open question for comment: Should alerts that the platform closes on its own, and a person later reopens, count against the rate?

Alert time

How long does it take from the moment a log arrives to the moment the platform reaches a verdict?

Why it matters

Speed claims are easy to make and hard to compare. Fixing where the clock starts and stops makes them comparable.

How draft 0.1 measures it

Elapsed time from log ingestion to verdict, as the platform records it. The clock starts when the log is ingested, not when an alert is raised, and stops at the verdict, not at a later notification.

What a vendor publishes

The typical figure, the period it covers, and how the two timestamps are recorded.

Source

The vendor’s own reporting or public claims, with the source stated.

Open question for comment: Should version 1.0 ask for a median and a slow-case figure (such as the 90th percentile) instead of a typical figure?

Human role

When a person is involved, who is it, when do they step in, and what do they do?

Why it matters

“AI-powered” can still mean an analyst behind every alert. A partner needs to know whose people do the work, and when.

How draft 0.1 measures it

A plain description, not a number. Who: the vendor’s analysts, the partner’s analysts, or the client. When: every alert, a sample, or escalations only. What: investigation, approval, or remediation.

What a vendor publishes

The description, and whether it changes by service tier.

Source

The vendor’s own reporting or public claims, with the source stated.

Open question for comment: Should the test separate people who approve an action from people who carry it out?

Build burden

Who builds and maintains the detection logic, and what else does a partner have to buy, deploy or run?

Why it matters

If the partner has to write the rules or bring a separate SIEM, the work and the cost move to the partner.

How draft 0.1 measures it

A plain description of who writes and tunes the detections, and which components, such as a SIEM, are included and which a partner must supply.

What a vendor publishes

The description, and a list of anything a partner must supply.

Source

The vendor’s own reporting or public claims, with the source stated.

Open question for comment: Should the test also ask how much work it takes to bring a new client on board?

Multi-tenant readiness

Was the platform built to serve many clients from one place, with each client’s data kept separate?

Why it matters

MSPs and MSSPs run many clients at once. A single-tenant platform stretched across clients adds work and risk.

How draft 0.1 measures it

A plain description of how clients are kept separate, and how a partner manages them together and one at a time.

What a vendor publishes

The description, and whether multi-tenancy was built in or added later.

Source

The vendor’s own reporting or public claims, with the source stated.

Open question for comment: What evidence of client separation should version 1.0 ask vendors to point to?

CYREBRO AI’s initial answers

We go first

Here are CYREBRO AI’s answers under draft 0.1, from our own reporting. They apply the same rules we ask of every vendor. Our complete answers, including the zero-touch rate, come with version 1.0.

CYREBRO AISelf-reported · draft 0.1
Not independently reviewed
02 · Alert time
Typically under one second

from log ingestion to verdict.

01 · Zero-touch rate
To be published with version 1.0

Measured the way the final methodology defines it, once the comment period has shaped that definition.

03Human role

CYREBRO AI’s escalation desk (or the partner’s analyst) on escalation only, with remediation by the partner or client, guided by step-by-step recommendations.

Published
04Build burden

Detection logic built and maintained by CYREBRO AI, with CYREBRO Hyper-SIEM built in.

Published
05Multi-tenant readiness

Multi-tenant by design.

Published
Source: CYREBRO AI’s own reporting, as published with draft 0.1 on October 12, 2026. Challenge an answer

What the test is, and isn’t

Measurements in the open. No grades, no badges.

It is

  • An open draft (version 0.1), clearly labeled as a draft
  • Measurements, sourced from each vendor’s own reporting or public claims
  • Created by CYREBRO AI, and says so plainly
  • Applied the same way to every vendor, including CYREBRO AI
  • Open to public comment and to an independent review panel

It is not

  • A finished standard, or something a platform can pass
  • Grades, scores, rankings, badges, or endorsements
  • Presented as independent or neutral third-party research
  • A comparison chart naming competitors
  • A gated lead form. You can read the whole method without signing up.

Draft log · live

Every comment, update and change, in the open

The comment period runs in public. This log shows published comments and our replies, progress updates, and every change to the draft, newest first. It refreshes on its own while you read.

Loading the draft log…

Take part

Shape version 1.0

Three ways in. Each one goes to the same small team, and you’ll hear back by email. Prefer email? Write to comments@soctruthtest.com.

Comment on the draft

Tell us what’s missing, unclear or unfair: in a measure, in the method, or in CYREBRO AI’s own answers. Public comment closes Wednesday, November 11, 2026.

  • You choose whether your comment appears in the draft log, and under what name.
  • Every comment is read and considered for version 1.0, published or not.
  • The review panel may read private comments when it audits the log.
Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please choose one.
Please choose a topic.
Please write your comment.
May we publish your comment in the draft log?
Or email comments@soctruthtest.com

Disclosure and governance

Who made this, and who keeps it honest

A test written by a vendor only works if everyone can see who wrote it and how it’s checked. Here’s ours.

Who made it

CYREBRO AI created the AI SOC Truth Test and is one of the platforms it measures. We published our own answers before inviting anyone else’s.

The test grades, ranks and endorses no one, CYREBRO AI included.

The review panel

An independent panel reviews the method for version 1.0 and audits the draft log. Members and their conflict disclosures are published with version 1.0.

Not on the panel:

  • Paul Warnagiris (board member and investor)
  • CYREBRO AI staff
  • The partners quoted at launch

Moderation

Until the panel is seated, CYREBRO AI moderates the draft log under a published rule. We publish every on-topic comment whose author agrees to it, edit only to remove other vendors’ names and personal details, and mark every edit.

The panel then audits the full log.

What happens when

From draft to version 1.0

0.1
Mon, Oct 12, 2026

Draft 0.1 published

The five measures and CYREBRO AI’s initial answers go public. Comments open.

We are here
11/11
Wed, Nov 11, 2026

Public comment closes

Every comment is read and considered for version 1.0.

We are here
1.0
Week of Nov 30, 2026

Version 1.0

The named review panel, CYREBRO AI’s complete answers including the zero-touch rate, and vendor self-reports.

We are here

Questions

Fair questions about a test like this

Is the AI SOC Truth Test independent?

No. CYREBRO AI created it, and we say so wherever it appears. What makes it fair is that the questions, the method and our own answers are all public; the same rules apply to every platform, ours included; and an independent review panel oversees version 1.0. CYREBRO AI staff, Paul Warnagiris (a board member and investor) and the partners quoted at launch can’t sit on that panel.

Can a platform pass or fail?

No. The test publishes measurements, not grades. There are no scores, rankings or badges, and no platform, including CYREBRO AI’s, can claim to have passed it.

Why hasn’t CYREBRO AI published its zero-touch rate?

Because the comment period may change how the zero-touch rate is defined. Publishing a number before the definition is settled would defeat the purpose. CYREBRO AI’s zero-touch rate will be published with version 1.0, measured the way version 1.0 defines it.

Where do the answers come from?

From each vendor’s own reporting or public claims, with the source stated. Draft 0.1 doesn’t independently check them. How version 1.0 should handle evidence is one of the questions open for comment.

Can I use the five questions with my current vendor?

Yes, that’s the point. Copy them into an RFP or a vendor review and ask anyone. You don’t need to sign up or tell us.

Will you compare vendors?

Draft 0.1 names no other vendor. In version 1.0, vendors that submit a platform will have their own answers published as they submitted them, with sources. Nothing is ranked or graded.

What happens to my comment?

We read every comment and consider it for version 1.0. If you agreed, we publish it in the draft log, usually within two business days, sometimes with a reply. Version 1.0 will say what changed because of public comment.

How are review panel members chosen?

Applications are open now. How members are chosen will be published alongside the named panel in version 1.0, together with each member’s conflict disclosure.

For reporters and analysts

Citing the test accurately

Suggested citation

The AI SOC Truth Test, draft 0.1. Created by CYREBRO AI. Published October 12, 2026. soctruthtest.com

Please include

CYREBRO AI created the AI SOC Truth Test and is one of the platforms it measures. Draft 0.1 is open for public comment until November 11, 2026.

Media questions: comments@soctruthtest.com

Hold every AI SOC to the same five questions

Starting with us.

Privacy notice

This notice covers what you send through this site, by form or by email.

What we collect

The details you enter: your name, work email, organization and role, plus your comment, application or submission. We also note how you reached the page (for example, a campaign link or referring site). This site sets no cookies and loads nothing from third parties until you send a form.

How we use it

To read and respond to what you send; to consider it for version 1.0; to publish your comment in the draft log, only if you agree and only under the name you choose; to contact panel applicants and submitting vendors about version 1.0; and, only if you ask, to tell you when version 1.0 is published. The review panel may read private comments when it audits the draft log.

Where it’s kept

In a customer relationship management (CRM) system run for CYREBRO AI by Elano, its launch partner for this test. We don’t sell it or share it with other vendors.

Your choices

To see, correct, unpublish or delete what you sent, email comments@soctruthtest.com. For everything else, see the CYREBRO AI privacy policy.