Everyone is automating the SOC. Far fewer are asking who is attacking the model doing the automating.
Palo Alto's Cortex XSOAR is the reference automation platform and HiddenLayer is a focused defender of AI models. We do both halves, for teams that also need the governance to prove the AI is fit to be trusted with a mission.
Our AI security work sits on top of an operation that already blocks more than 100,000 threats a day, so the orchestration is tuned against real alert volume rather than a demonstration data set. The AI-assurance side runs as structured programmes with adversarial testing before a model is trusted with anything that matters.
Side by side
| Attribute | Represented by UnstratAI security | HiddenLayerAI Detection & Response1United States | Palo Alto NetworksCortex XSOAR2United States |
|---|---|---|---|
| What the offer covers12 | Both halves: AI SOAR for machine-speed response, and AI security programmes that harden the customer's own models | Protection of AI and machine-learning models in production | Security orchestration, automation and response across the security stack |
| Model attack classes addressed12 | Adversarial testing for evasion, extraction and data poisoning, before an AI capability is trusted with a mission | Prompt injection, PII leakage, inference attacks, evasion, model tampering, model extraction and theft, and data poisoning or model injection | Not addressed in the datasheet |
| Framework mapping12 | Not published | MITRE ATLAS and OWASP LLM integration, mapping to 64+ adversarial AI attack techniques | Not published in the datasheet |
| How the model is observed12The non-invasive design is a genuine deployment advantage where the model owner cannot expose training data to a vendor. | Not published | Non-invasive. It observes vectorised model inputs only, without access to training data, features or the model itself | Not applicable |
| Automation reach12 | Force-multiplies a small security team to machine speed; integration count not published | Not applicable | 1,000+ integrations, playbook-driven automation, case management with a collaborative War Room and native threat-intelligence management |
| Published automation outcomes12 | Not published as automation metrics. The wider operation blocks 100,000+ threats daily | Not published | Customer-reported: weekly alerts reduced from 10,000 to 500, response time from 3 days to 25 minutes, 30% of incidents automated and one full-time analyst saved |
| Multi-tenant operation12 | Not published | Not published | Full multitenancy for managed security service providers, on a cloud-native SaaS platform with an on-premises option |
| Governance for AI in sensitive environments12 | Governance frameworks for AI deployed in sensitive environments, with adversarial testing before trust is granted | Not published as a governance framework; the product provides detection and response for models in production | Not addressed in the datasheet |
| Availability and commercial entry12 | Not published | Available through the Azure, AWS and Google Cloud marketplaces; recognised as a Gartner Cool Vendor for AI Security | 30-day free trial offered |
| Origin and political exposure12 | Independent, non-aligned origin, with no political exposure to any major-power ecosystem | United States | United States (Palo Alto Networks) |
Competitor values are quoted from the vendor documents listed under Sources, as published on the date shown. Configurations vary, so treat every row as a starting point for the evaluation rather than a like-for-like test result.
What the table means
Two problems that keep getting sold as one
Securing an organisation with AI and securing the organisation's AI are separate engineering problems with separate failure modes. XSOAR is the mature answer to the first: 1,000+ integrations, playbooks, case management, and customer-reported reductions from 10,000 weekly alerts to 500. HiddenLayer is a focused answer to the second, covering prompt injection through to model theft and mapping to 64+ techniques in MITRE ATLAS and OWASP LLM. A buyer who purchases only the first ends up automating decisions made by a model nobody has tested adversarially.
The deployment constraint nobody mentions until integration week
HiddenLayer's non-invasive design is worth studying, because it observes vectorised inputs only and never touches training data, features or the model. For a defence ministry or a bank, that constraint is often the reason a project is allowed to proceed at all. Anyone proposing AI security for your models should be asked the same question early: what exactly do you need access to, and can the answer survive your data-classification rules.
Automation is only as sovereign as the platform it runs on
A SOAR platform ends up holding your playbooks, your case history and your integrations with every other tool you own. Cortex XSOAR is cloud-native SaaS with an on-premises option, which is more flexibility than most competitors offer, and its multitenancy is genuinely useful for a national MSSP model. The residual question is jurisdictional rather than technical. Our position is that the automation runs for you and reports to you, from a supplier with no foreign-government reporting line.
Questions buyers ask
How do you secure an AI model against prompt injection and data poisoning?
Test it adversarially before it is trusted, then watch it in production. Our programmes cover evasion, extraction and poisoning red-teaming before an AI capability is given a mission. HiddenLayer approaches the production half well: non-invasive monitoring of vectorised model inputs, covering prompt injection, PII leakage, inference attacks, model tampering and poisoning, mapped to 64+ techniques across MITRE ATLAS and OWASP LLM. If you already run models in production and have no adversarial test history for them, start with the test.
What is the best alternative to Cortex XSOAR for a government that wants sovereign SOAR?
Be clear about what you would give up. XSOAR publishes 1,000+ integrations, full multitenancy for service providers and customer-reported results such as response time falling from 3 days to 25 minutes. Our AI SOAR runs inside an operation blocking over 100,000 threats a day, and it comes from a non-aligned supplier with no obligation to report to a foreign government. We do not publish an integration count, so ask for the list against your actual tool estate before deciding.
Can AI-driven security operations replace human analysts?
No, and the vendors do not claim it either when you read carefully. XSOAR's own customer figures describe 30% of incidents automated and one analyst's time saved, which is a force multiplier rather than a replacement. We ship AI-assisted operations with defence in depth and human oversight for the same reason: an automated action taken on a bad inference is still your outage.
What governance do we need before deploying AI in a defence or intelligence environment?
At minimum: a documented threat model for the model itself, adversarial testing against evasion, extraction and poisoning, a decision on what data the security tooling may see, and a rule for which actions the system may take without a human. We deliver that as a structured programme. Neither the HiddenLayer nor the XSOAR datasheet describes a governance framework, because they are products rather than programmes, so expect to build that layer regardless of which tools you buy.
Sources
- 2. Palo Alto Networks, Cortex XSOAR (datasheet, cortex_ds_xsoar_101023) (copy held on this site)Retrieved: 2026-07-31 · Integration count, multitenancy for MSSPs, playbook and case management description, and the customer-reported automation figures.
