Comparison · 8 reference competitors
Where CyberCLI lines up.
And where it doesn't.
We picked 8 reference players — the cloud SIEMs, the AI SOC startups, the managed SOCs, the open-source / sovereign peers — and compared them on 8 dimensions a Founder Pro buyer actually decides on. Every cell is honest as of 2026-06-03; public pages are the source of truth. We update when competitors close a gap.
| dimension | CyberCLI Sovereign AI SOC | Microsoft Sentinel Cloud SIEM | Elastic Security SIEM + XDR | Wazuh OSS SIEM/XDR | Prophet Security AI SOC startup | Panther AI SOC platform | Arctic Wolf Managed SOC | LimaCharlie API-first SecOps | Tracecat Open SOAR |
|---|---|---|---|---|---|---|---|---|---|
| Hash-chained audit log Every decision is tamper-evident — verifiable by anyone, after the fact. | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
| Sovereign by default Single binary on-prem. Your data never leaves the box without explicit opt-in. | ✓ | ✗ | ~ | ✓ | ✗ | ✗ | ✗ | ~ | ✓ |
| Local AI lane Ollama on-prem option. Works air-gapped; pays $0 in inference token taxes. | ✓ | ✗ | ~ | ✗ | ✗ | ✗ | ✗ | ~ | ~ |
| AI shows its work The agent's plan + queries + evidence + trust-level cleared, visible per signal. | ~ | ~ | ~ | ✗ | ✓ | ✓ | ~ | ✓ | ✓ |
| Human-in-the-loop approval Approve / Defer / Reject with operator note — hash-chained on the audit log as a forensic record. Engine state wire-through ships in v1.x. | ~ | ~ | ~ | ✗ | ✓ | ✓ | ✓ | ~ | ✓ |
| OSS-extending, not OSS-locked Built on Wazuh + 30 OSS connectors. We orchestrate the tools you already run. | ✓ | ✗ | ✓ | ✓ | ✗ | ~ | ✗ | ~ | ✓ |
| Trust Ladder + Cyber Guild Progressive autonomy (L0-L7) with named roles. Buyers know what the AI may + may not do. | ✓ | ✗ | ✗ | ✗ | ~ | ~ | ✗ | ~ | ~ |
| $299 Founder lifetime lock Lock 2026 pricing forever — first 10K seats. No other vendor in the set runs this. | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
✓ = ships today · ~ = partial / requires extra config · ✗ = does not ship
What we're betting will matter to you
Almost nobody in this set offers a tamper-evident hash-chained audit log. Sentinel keeps its logs in your tenant but you have to trust Microsoft's word that nobody mutated them. CyberCLI's chain is verifiable by anyone, after the fact, without a network call. A regulator, your CTO, your insurer — anyone with the binary and the chain file can re-derive every entry hash.
$ cybercli audit verify
✓ 297 entries verified · chain intact · no tamper Everyone else in the AI SOC category defaults to their cloud or to a frontier API. CyberCLI defaults to Ollama on your hardware; we'll wire managed frontier (Anthropic, OpenAI, Gemini) if you pay for it and you pick which provider. Your data never leaves the box without an explicit opt-in.
Prophet, Panther, Tracecat show the AI's reasoning prose. CyberCLI shows the structured trace today — who decided, on which model, against which evidence, at which trust level — every field tied to the audit hash. Freeform rationale prose ships in v1.x when AI providers project it. Approve / Defer / Reject lands on the audit log as a forensic record now; the engine state machine wire-through ships in v1.x.
The other vendors in this table either gate on consumption (Sentinel, Wazuh Cloud, Elastic), per-seat tiers that rise yearly (Prophet, Panther, LimaCharlie), or premium MDR retainer (Arctic Wolf, Red Canary). $299 once, locked at 2026 pricing forever. The tactic doesn't scale to 10M seats. It doesn't need to.