TL;DR
Your security platform vendor now offers an AI agent as an add-on, sometimes at no extra cost. That sounds like a gift. But these agents are built to work best inside that one vendor’s own tools. Point them at the rest of your stack and support gets thin, ramp times stretch into months, and the bill climbs as you grow. The agent is only as useful as your loyalty to that vendor. There is another way to buy: an AI teammate that sits above the stack you already own and works across all of it, no matter who made each tool.
Introduction
When your platform vendor bundles a free AI agent, the price tag is not the real cost. The real cost is what it quietly assumes: that you will run everything else on their tools too. That assumption has a name. It is called lock-in, and agentic add-ons are the newest way to sell it.
Why the add-on is built to keep you inside
These agents are trained and tuned on the alerts their own platform produces. That is what makes them look so sharp in a demo. It is also the catch.
Independent reviews of the big platform agents say the same thing over and over. The agent is optimized for its own vendor’s alerts. Connecting tools the vendor did not make is possible, but it is not first class. Coverage of non native data sources is limited.
So the agent shines on the vendor’s turf and struggles at the edge. If your whole stack is theirs, that is fine. Most stacks are not. The average security team runs dozens of tools from many vendors, and the agent only reasons cleanly over a slice of them.
The costs that do not show up on the invoice
Free or bundled pricing hides three real costs. None of them appear on the quote.
First, ramp time. These platforms are powerful and complex. Independent analysts report that some enterprise agentic platforms take six to twelve months to configure and tune to real value. That is not live in days. That is a project that eats a year.
Second, cost as you grow. Bundled often means bundled for now. Pricing tends to climb as you add workflows, agents, and data volume. The entry price and the price at scale are different animals.
Third, exit cost. This is the quiet one. When the agent lives inside one platform and only works well on that platform’s data, leaving the platform means leaving the agent. Your automation is now a reason you cannot switch. That is the whole point of lock-in.
Four questions that reveal the lock-in
Four questions that reveal the hidden cost
Ask these before you sign. If the answers point back to one vendor’s stack, that is the lock-in.
You can surface all of this before you sign. Ask four plain questions and listen for hedging.
- Non native data. Does the agent work as well on tools this vendor did not make?
- Ramp time. Is this value in days, or months of configuration and tuning?
- Cost as you scale. Does the bill climb with every new workflow and gigabyte?
- Exit cost. If we leave this platform later, do we lose the agent too?
If the honest answers keep pointing back to one vendor’s stack, you are not buying an agent. You are buying deeper into a platform.
The other way to buy: above the stack
Two ways to add an AI agent to your SOC
One works best only inside its maker’s tools. The other works across the tools you already own.
There is a different model that does not assume loyalty. Instead of living inside one platform, the agent sits above your whole stack and works across the tools you already own.
This flips every one of those four costs. It works on your existing EDR, SIEM, and cloud, whoever built them. It connects and shows value fast, because there is nothing to standardize on first. And because it is not welded to one platform’s data, changing a tool underneath does not cost you the agent.
That is the Secure.com model. Governed AI teammates that ride on top of the stack you already own, not another reason to marry a single vendor.
How Secure.com helps
Secure.com gives you governed AI security teammates that work above the stack you already own, so the value is not tied to one vendor’s ecosystem.
- Teammates work across your existing tools, whoever made them, with no rip and replace.
- Value shows up fast because there is no year long platform migration first.
- Your team sets scope and approves consequential actions, so authority stays human.
- Every action is logged for a clean audit trail.
- Because it is not locked to one platform’s data, switching a tool underneath does not cost you the teammate.
The takeaway
A free agentic add-on is only free if you were always going to run everything on that one vendor. For everyone else, the hidden costs, thin support at the edge, long ramp, climbing bills, and no easy exit, add up to a lot. Ask the four questions before you sign. And remember there is a model that does not trade your flexibility for an agent: one that sits above the stack you already own.
FAQs
Do I need one vendor’s whole platform to use their AI SOC agent?
Why do agentic SOC add-ons cause lock-in?
How long do these platforms take to deploy?
What is an above the stack security agent?
What should I ask a vendor to check for lock-in?
More from Secure.com