What is our primary use case?
I use Torq as my case management and alert system. Working as a SOC analyst, the first thing I do every morning is get into Torq, review all the open cases and incidents, understand their severity, investigate them, and close them if they are legitimate. I also investigate whether there is anything malicious. I use Torq daily.
We build workflows inside Torq—automations that can automate every action that we do manually. For example, we send Slack messages to users who we think shared corporate data, or investigate specific machines where we suspect there is some sort of SQL injection. We can automate every type of security-related incident through the workflows in Torq.
What is most valuable?
All the workflows are something really particular. From what I have seen in the past, I have never seen this maturity of automated processes, and the whole idea of drag and drop automation is really simple. This is something I have never seen before. Even with our previous vendor, we did not have this type of maturity. We needed to manually create our own tasks, and it took much longer than what we are doing with Torq.
AI is helping us summarize security alerts. The first thing I do in the morning is get into cases and review all the open cases and incidents. The first thing I see is the AI summary, and it is already telling me all the details that I need to know. Of course, we configured it so that all the relevant details appear in the AI summary, but I almost never need to check the actual details in the logs of the case because I have this summary. On the workflow aspect, I have created multiple tasks that work with AI. For example, I summarize some sort of log and extract only the relevant data from it. I created an agent that can automate processes and make manual API calls to review and collect data that I need for some specific alerts. Recently, they upgraded the Hyperagents and added many automated processes that I am looking forward to using. For example, they created a prompt that can help analyze JSON, which is really good for me because I needed to use it and looked for something like this. They have an option to output from an LLM as JSON, which also really helped me. I am using it on a daily basis.
In the previous system, we were not happy with it. We saw that there were many processes we needed to do manually, while there are options around the market that can help us do those processes automatically. For example, for collecting data, we needed to create the HTTP request ourselves, while in Torq, there are already multiple custom-made tasks that collect the API data themselves, and we do not need to build the whole HTTP request. We looked for a way to save time and automate processes, and Torq really answered those questions.
What needs improvement?
This is exactly what we discussed two days ago with the Torq team. We told them where we want to see improvements. For example, we have MCP that we are working with our cloud security platform, and we wanted to connect this MCP to the case management. When I go inside a case, I want to have a search bar where I can search details about my cloud and everything in my cloud, details about the specific vendors of the alert, not only the alert itself. Currently, we have a search bar for the alert itself, but we do not have a search bar for the connectors. This is one place for improvement.
We already talked about some filtering that they can add. They have a dashboard case dashboard, which is a separate page from the cases itself. We thought about adding a specific widget to the cases page so that we can see statistics inside the cases page. However, there were a few things before that we wanted them to work on, and they have already solved them. For example, we wanted to implement Torq to have access only within our VPN, and as far as I know, they worked on it. A month ago, it succeeded, and we are currently only connecting inside of the VPN.
For how long have I used the solution?
I have been using Torq for the past four to five months.
Buyer's Guide
Torq
August 2026
Learn what your peers think about Torq. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.
What do I think about the stability of the solution?
As far as I know for now, I have never seen any message from them that there is maintenance and we need to wait or something like that.
What do I think about the scalability of the solution?
I would rate scalability about nine.
How are customer service and support?
I would rate customer service nine.
Which solution did I use previously and why did I switch?
Our previous solution was Cortex. When we reviewed multiple SOAR solutions, we saw that all the new SOAR companies are doing basically the same thing. We then looked for the specific company that could help us automate and create automated processes with the most mature solution. Torq really answered those questions and really helped us with it. When we started the process and began working with Torq and seeing all the system, we saw that it became really easy to create a workflow. I do not need to think too much. I know I have many drag and drop tasks that can automate a process, which I could have done manually for months.
How was the initial setup?
The setup was easy. All of our security operations team got into Torq and started working on workflows in parallel, which made the entire onboarding process really easier. Something that should have taken half a year took two to three months, and then we finished everything and migrated everything.
What about the implementation team?
Only our teams implemented Torq.
What was our ROI?
The main thing that I got when we started working with Torq is time. I used to have much more time to review alerts, and most of the alerts were manually closed rather than automatically closed. I had most of my day investigating alerts and solving them. A huge part of them are false positives and things that are legitimate and just need a quick check or sending a message.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert. I have all the information that I need. I do not need to connect to different vendors to receive this information. The main thing I got from Torq is time, and this free time helps me to build another automated system, learn, and there is no need to explain what time is and how important it is.
I used to spend something like three to four hours each day working on cases. Now when we are working in Torq, in the first hour and a half to two hours, I am solving all the cases and the open cases, and I am free to do whatever I need.
What's my experience with pricing, setup cost, and licensing?
Unfortunately, I am not aware of the pricing itself. This is something that my manager would be able to answer, but I am not aware of the price.
What other advice do I have?
I would definitely recommend Torq. I have no doubt, really. When we looked for another vendor, Torq really answered all our questions. It really helps us to receive the best solution for our SOAR.
We already connected Torq with our EDR, SIM logs, and DLP systems. When we connected it, the whole idea of Torq was collecting all the data to a specific place. We created alerts in the SIM and then automatically sent them to Torq. We do not handle the alerts in the SIM, only on Torq. When we collected the data from all the vendors, it is really easy when everything is in one place. We have everything in Torq, and then we do not need to connect to each system to review all the data.
I believe we looked for a maturity that they did not have at first, but right now I can see and tell that they have this maturity, and we are going to use the Agentic AI. It used to be like a six, and right now it seems like an eight, maybe nine even when we review it. I would rate this review an eight overall.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.