Skip to main content

Everyone is automating the SOC. Far fewer are asking who is attacking the model doing the automating.

Palo Alto's Cortex XSOAR is the reference automation platform and HiddenLayer is a focused defender of AI models. We do both halves, for teams that also need the governance to prove the AI is fit to be trusted with a mission.

In service, not experimental

Our AI security work sits on top of an operation that already blocks more than 100,000 threats a day, so the orchestration is tuned against real alert volume rather than a demonstration data set. The AI-assurance side runs as structured programmes with adversarial testing before a model is trusted with anything that matters.

Side by side

AttributeRepresented by UnstratAI securityHiddenLayerAI Detection & Response1United StatesPalo Alto NetworksCortex XSOAR2United States
What the offer covers12Both halves: AI SOAR for machine-speed response, and AI security programmes that harden the customer's own modelsProtection of AI and machine-learning models in productionSecurity orchestration, automation and response across the security stack
Model attack classes addressed12Adversarial testing for evasion, extraction and data poisoning, before an AI capability is trusted with a missionPrompt injection, PII leakage, inference attacks, evasion, model tampering, model extraction and theft, and data poisoning or model injectionNot addressed in the datasheet
Framework mapping12Not publishedMITRE ATLAS and OWASP LLM integration, mapping to 64+ adversarial AI attack techniquesNot published in the datasheet
How the model is observed12The non-invasive design is a genuine deployment advantage where the model owner cannot expose training data to a vendor.Not publishedNon-invasive. It observes vectorised model inputs only, without access to training data, features or the model itselfNot applicable
Automation reach12Force-multiplies a small security team to machine speed; integration count not publishedNot applicable1,000+ integrations, playbook-driven automation, case management with a collaborative War Room and native threat-intelligence management
Published automation outcomes12Not published as automation metrics. The wider operation blocks 100,000+ threats dailyNot publishedCustomer-reported: weekly alerts reduced from 10,000 to 500, response time from 3 days to 25 minutes, 30% of incidents automated and one full-time analyst saved
Multi-tenant operation12Not publishedNot publishedFull multitenancy for managed security service providers, on a cloud-native SaaS platform with an on-premises option
Governance for AI in sensitive environments12Governance frameworks for AI deployed in sensitive environments, with adversarial testing before trust is grantedNot published as a governance framework; the product provides detection and response for models in productionNot addressed in the datasheet
Availability and commercial entry12Not publishedAvailable through the Azure, AWS and Google Cloud marketplaces; recognised as a Gartner Cool Vendor for AI Security30-day free trial offered
Origin and political exposure12Independent, non-aligned origin, with no political exposure to any major-power ecosystemUnited StatesUnited States (Palo Alto Networks)

Competitor values are quoted from the vendor documents listed under Sources, as published on the date shown. Configurations vary, so treat every row as a starting point for the evaluation rather than a like-for-like test result.

What the table means

Two problems that keep getting sold as one

Securing an organisation with AI and securing the organisation's AI are separate engineering problems with separate failure modes. XSOAR is the mature answer to the first: 1,000+ integrations, playbooks, case management, and customer-reported reductions from 10,000 weekly alerts to 500. HiddenLayer is a focused answer to the second, covering prompt injection through to model theft and mapping to 64+ techniques in MITRE ATLAS and OWASP LLM. A buyer who purchases only the first ends up automating decisions made by a model nobody has tested adversarially.

The deployment constraint nobody mentions until integration week

HiddenLayer's non-invasive design is worth studying, because it observes vectorised inputs only and never touches training data, features or the model. For a defence ministry or a bank, that constraint is often the reason a project is allowed to proceed at all. Anyone proposing AI security for your models should be asked the same question early: what exactly do you need access to, and can the answer survive your data-classification rules.

Automation is only as sovereign as the platform it runs on

A SOAR platform ends up holding your playbooks, your case history and your integrations with every other tool you own. Cortex XSOAR is cloud-native SaaS with an on-premises option, which is more flexibility than most competitors offer, and its multitenancy is genuinely useful for a national MSSP model. The residual question is jurisdictional rather than technical. Our position is that the automation runs for you and reports to you, from a supplier with no foreign-government reporting line.

Questions buyers ask

How do you secure an AI model against prompt injection and data poisoning?

Test it adversarially before it is trusted, then watch it in production. Our programmes cover evasion, extraction and poisoning red-teaming before an AI capability is given a mission. HiddenLayer approaches the production half well: non-invasive monitoring of vectorised model inputs, covering prompt injection, PII leakage, inference attacks, model tampering and poisoning, mapped to 64+ techniques across MITRE ATLAS and OWASP LLM. If you already run models in production and have no adversarial test history for them, start with the test.

What is the best alternative to Cortex XSOAR for a government that wants sovereign SOAR?

Be clear about what you would give up. XSOAR publishes 1,000+ integrations, full multitenancy for service providers and customer-reported results such as response time falling from 3 days to 25 minutes. Our AI SOAR runs inside an operation blocking over 100,000 threats a day, and it comes from a non-aligned supplier with no obligation to report to a foreign government. We do not publish an integration count, so ask for the list against your actual tool estate before deciding.

Can AI-driven security operations replace human analysts?

No, and the vendors do not claim it either when you read carefully. XSOAR's own customer figures describe 30% of incidents automated and one analyst's time saved, which is a force multiplier rather than a replacement. We ship AI-assisted operations with defence in depth and human oversight for the same reason: an automated action taken on a bad inference is still your outage.

What governance do we need before deploying AI in a defence or intelligence environment?

At minimum: a documented threat model for the model itself, adversarial testing against evasion, extraction and poisoning, a decision on what data the security tooling may see, and a rule for which actions the system may take without a human. We deliver that as a structured programme. Neither the HiddenLayer nor the XSOAR datasheet describes a governance framework, because they are products rather than programmes, so expect to build that layer regardless of which tools you buy.

Sources

  1. 1. HiddenLayer, AI Detection & Response (datasheet, March 2024) (copy held on this site)Retrieved: 2026-07-31 · Non-invasive observation of model inputs, the attack classes covered, MITRE ATLAS and OWASP LLM mapping, and marketplace availability.
  2. 2. Palo Alto Networks, Cortex XSOAR (datasheet, cortex_ds_xsoar_101023) (copy held on this site)Retrieved: 2026-07-31 · Integration count, multitenancy for MSSPs, playbook and case management description, and the customer-reported automation figures.
Next step on this comparison

Send us the requirement and the systems you are weighing. We will map this table onto it.