Breaking
$37M Series B closed July 2025, led by Theory Ventures 300+ organizations now run the AI SOC analyst SOCs investigate fewer than 10% of alerts - Dropzone aims for 100% NPS of 66, roughly twice the industry average 14 US patents on AI security agents Total funding to date: $57.35M $37M Series B closed July 2025, led by Theory Ventures 300+ organizations now run the AI SOC analyst SOCs investigate fewer than 10% of alerts - Dropzone aims for 100% NPS of 66, roughly twice the industry average 14 US patents on AI security agents Total funding to date: $57.35M
Company Profile · Cybersecurity & AI

Dropzone AI

The analyst that never sleeps, never burns out, and never skips an alert. Seattle's answer to the question every security team is too tired to ask.

EST. 2022SEATTLE, WAAI SOC ANALYST~71 STRONG
Dropzone AI
EXHIBIT A: The Dropzone AI banner. Somewhere behind it, an AI is reading the 4,000th alert of the night and not complaining once.
FILED FROM SEATTLE, WASHINGTON SECTOR: SECURITY OPERATIONS STATUS: SERIES B
Who they are now

It is 3 a.m. The alerts keep coming. Nobody is panicking.

Somewhere in a security operations center, a queue is filling up. Phishing reports, an odd login from a new country, an endpoint behaving strangely, a cloud config that drifted. On a normal night, a tired human would investigate maybe a tenth of them and triage the rest by gut. On a Dropzone AI night, every single one gets investigated - pulled apart, cross-referenced, and written up in a report a human can read in under a minute.

That is the company in 2026: an autonomous AI SOC analyst, deployed at more than 300 organizations, doing the unglamorous middle of security work - the investigation - so the humans can do the part that actually requires a human. It is not a chatbot bolted onto a dashboard. It is an agent that behaves, more or less, like a competent tier-1 analyst who happens to work all 168 hours of the week.

"Reinforcing SOCs with AI so they can better operate and defend as if they had an unlimited number of tier-1 analysts."- Edward Wu, Founder & CEO
The problem they saw

Defenders have to win every time. Attackers only have to win once.

This is the asymmetry that keeps security people up at night, and it gets worse the more tools you buy. Every new detection system is a new firehose of alerts. The industry got very good at surfacing problems and never quite figured out how to understand them at scale. So the alerts pile up, and the humans, being only human, look at the few that seem scariest and wave the rest through.

The dirty secret of the modern SOC is that most alerts are never investigated. Not because anyone is lazy - because there are simply not enough hours, or analysts, or patience. The bottleneck was never detection. It was the fifteen quiet minutes it takes a skilled person to chase one alert across a dozen disconnected tools and decide whether it matters.

"Surfacing an alert doesn't change the game. You need to help me understand them."- "Michael," a SOC manager whose offhand remark became a company
The founders' bet

A detection expert decided detection wasn't the point.

Edward Wu spent eight years at ExtraHop building the AI and machine-learning detection engine that helped invent the network detection and response category. He knew detection cold. Which is exactly why his conclusion was uncomfortable: better detection would not save the SOC. The work that mattered - the reasoning - was the work no one had managed to automate, because traditional code is bad at judgment.

Then large language models arrived, and Wu saw the gap he could close. Not the alerting. The thinking. He left ExtraHop, where he had been the AI lead, and in 2022 founded Dropzone AI on a single contrarian wager: that a machine could perform the cognitive part of a security investigation - the cross-tool sleuthing, the context-weighing, the "is this actually bad?" - well enough to trust. A computer-science PhD dropout with 30-plus patents to his name, betting that the reasoning, not the data, was the moat.

"Human strategy, machine scale." - the four-word philosophy: defenders set the direction, agents do the legwork.- Dropzone AI's stated operating principle
The short, busy history

From offhand remark to front-line agent

2022

The bet is placed

Edward Wu leaves ExtraHop after eight years and founds Dropzone AI in Seattle, wagering that LLMs can automate security investigation - not just detection.

2023

$3.5M seed

Decibel Partners and Pioneer Square Ventures back the earliest version of the autonomous AI SOC analyst.

April 2024

$16.85M Series A

Theory Ventures leads. Coverage notes the agent reduces manual investigation work by roughly 90%. Gartner names Dropzone a Cool Vendor.

July 2025

$37M Series B

Theory Ventures leads again, joined by Madrona, Decibel, Pioneer Square Labs, and IQT. Total raised hits $57.35M. Listed in the Gartner Hype Cycle and CB Insights AI 100.

2026 (planned)

Beyond triage

AI Threat Hunter and AI Threat Intel Analyst extend the platform from reacting to alerts to proactively hunting threats.

The product

No playbooks. Just an investigation, end to end.

Most automation in security is a flowchart wearing a trench coat: if this, then that, and pray the attacker read the same script. Dropzone's AI SOC analyst skips the playbooks. Hand it an alert - phishing, endpoint, network, cloud, identity, insider threat - and it investigates the way a person would, pulling evidence from across your stack, weighing your organization's context, and producing a report that ends with a verdict: true positive, or false.

The result is fewer false-positive rabbit holes, faster real-incident response, and an audit trail for every decision. It plugs into the SIEM, EDR, email, cloud and identity tools security teams already own, which is a polite way of saying it does not ask you to rip anything out.

FLAGSHIP

AI SOC Analyst

Autonomously triages and investigates alerts across every major domain, then writes a high-fidelity report classifying each as real or noise.

EXPANDING

AI Threat Hunter

Runs federated hunts across SIEM, EDR and cloud to surface threats that never tripped an alert in the first place.

EXPANDING

AI Threat Intel Analyst

Reads security advisories and turns raw intelligence into ready-to-run hunt packs for the team.

An alert is a question. Dropzone's pitch is that the machine can now write the answer - and show its work.- The product, in one line
The proof

The numbers the skeptics asked for.

Skepticism is the correct posture toward any product with "AI" in the name, so here is what is measurable. More than 300 organizations have deployed it. Customers include UiPath, Zapier, Pipe, Mysten Labs, Assala Energy and Indiana Farm Bureau Insurance. The MSSP CBTS reports offloading 30-50% of its alert volume to the agent. The company's Net Promoter Score sits at 66 - roughly double the industry norm.

300+
DEPLOYMENTS
66
NPS SCORE
14
US PATENTS
$57.35M
RAISED

The gap Dropzone is selling against

% OF SECURITY ALERTS THAT ACTUALLY GET INVESTIGATED · ILLUSTRATIVE
Typical understaffed SOC<10%
CBTS, alert volume offloaded to Dropzone30-50%
Dropzone AI's stated target100%
The whole business is the distance between that first bar and the last one. Figures from public company statements; treat as directional, not audited.
UiPathZapierPipeMysten LabsIndiana Farm Bureau InsuranceAssala EnergyCBTS
"Dropzone AI SOC analyst's performance is exceptional, delivering detailed, high-fidelity alerts within minutes."- Andrew Marsh, Director of Information Security, Indiana Farm Bureau Insurance

The investor list reads like a thesis. Theory Ventures led twice. Madrona, Decibel and Pioneer Square Labs round out the cap table. And IQT - the strategic investor known for bridging startups to national-security missions - is on it, which tells you who else is watching this category.

The mission

Level the field for the people playing defense.

Strip away the funding and the patents and the mission is almost stubbornly simple: close the asymmetry gap. Give a five-person security team the investigative throughput of a fifty-person one. Not by hiring - the people don't exist and the budgets don't either - but by handing every defender an effectively unlimited bench of tier-1 analysts who happen to be made of software.

It is a defensive mission in an industry that loves to romanticize offense. The attackers get the movie montages. Dropzone is building for the person who has to read the alert.

The attackers get the movie montages. Dropzone is building for the person who has to read the 4,000th alert.- The mission, minus the press release
Why it matters tomorrow

AI is writing the attacks now, too.

Here is the part that should sharpen the skeptic's attention. The same technology Dropzone uses to investigate is being used, on the other side, to generate phishing, probe systems, and scale attacks that used to require human effort. The volume problem is about to get worse, not better. A SOC that investigates a tenth of its alerts today will be investigating a smaller fraction tomorrow if nothing changes.

Dropzone's bet, placed in 2022, is increasingly a bet on arithmetic: if machines are generating the threats, machines have to do the first pass of investigating them, or the math simply does not close. The next two products - the threat hunter and the intel analyst - push the company from reacting to alerts toward going looking for trouble before it announces itself.

Back where we started

It is 3 a.m. again. The queue is empty.

Return to that operations center. Same hour, same flood of alerts, same tired humans. Except now every alert has been read, investigated, and ranked, and the three that actually matter are sitting at the top with the evidence already attached. The humans are not triaging on instinct. They are deciding what to do about real things.

That is the whole pitch, and it is a quiet one. No movie montage. Just an empty queue at 3 a.m. and a team that gets to spend its attention on the threats worth losing sleep over - which, it turns out, is the most radical thing you can offer a security operations center.