In conjunction with

Learns Your Context. Earns Your Trust. Elevates You.

COMPANY OVERVIEW

Legion Security was founded in 2024 and is based in New York City. The company builds an agentic security operations platform for enterprise teams, centered on KindFire — an adaptive AI agent designed to emulate the reasoning of a human security analyst. Rather than asking teams to rebuild their processes around a new tool, Legion operates through a browser-native interface that observes how analysts actually investigate, capturing institutional knowledge and converting it into repeatable agentic workflows.

In July 2025, Legion raised $38 million across a seed and Series A round led by Coatue, with participation from Accel and Picture Capital, alongside angel investors from Wiz, Google, and CrowdStrike. The platform is used by organizations including Virgin Money, IQ-EQ, WELL Health Technologies, and the University of Tulsa, and holds SOC 2, HIPAA, ISO 27001, and ISO 42001 certifications.

CORE FOCUS

Legion's core discipline is scaling security operations without surrendering human oversight. The platform learns from an organization's existing analysts, tools, and playbooks, then deploys AI agents that carry that tribal knowledge across triage, investigation, and response — preserving the judgment of the team that trained them instead of imposing a generic detection model.

The key differentiator is the progression from observation to autonomy. Legion earns trust incrementally: it watches first, then works alongside the analyst with a human confirming every step, and only then extends into independent operation. Governance and analyst review remain in the loop at each stage of that progression.

PRODUCTS & TOOLS

KindFire – The adaptive AI agent at the center of the platform, built to emulate how human security analysts reason through an investigation.

Learning Mode – Observes analyst investigations, playbooks, and past cases through the browser, transforming institutional knowledge into agentic workflows.

Companion Mode – Executes complete workflows inside the analyst's browser with full human oversight at every step.

Autonomous Mode – Operates as an autonomous extension of the security team, scaling trusted expertise across investigations.

Market Segment:

SOC Automation

Categories:

SOC AutomationAI SOC