Miju Labs

The security dossier

Commercial buyers

The weakest section in the dossier, said plainly: no job posting, contract or methodology section anywhere names a paid external annotator at a security vendor. What is evidenced is a segment that needs a scoreboard and is losing the only neutral one.

low confidence7 minupdated 2026-08-30security vendors · MSSPs · insurance · AI assurance · MITRE

Start with the finding rather than the hope: no job posting, contract or methodology section anywhere in this research names a paid external annotator at a security product company.

That sentence is the honest summary of the entire commercial segment. Every other page in this dossier rests on documents — pay bands pulled from applicant-tracking APIs in The labs as buyers, named subcontractors in Government buyers, a published solicitation with a price on it. This page rests on inference about companies that would plausibly buy, and has no instance of one that demonstrably has.

The hole in this section

Across every search: no verified case of an AI SOC, AI pentest or AI appsec vendor commissioning a published third-party evaluation of its own product, and no verified case of one buying labelled cyber data from an expert-data vendor. Loginsoft — the one company openly selling "Security Data for AI Training" — names no clients for that line on its own site (Loginsoft). Treat this segment as a hypothesis with a mechanism, not a market with a customer. Nothing in a plan should depend on it closing first.

What is actually evidenced

Three things, and they are structural rather than transactional.

Ten funded AI SOC vendors now need a way to compare themselves. Exaforce raised $125M Series B on 12 May 2026 at a reported $725M valuation on top of a $75M Series A (SiliconANGLE). Torq raised a $140M Series D at $1.2B (Torq). Legion Security has $38M across a seed and a July 2025 Series A led by Coatue, with 25 staff (Calcalist). Prophet Security took $30M in August 2025 (Built In SF); Conifers.ai $25M from SYN Ventures (SecurityWeek); Tracebit a March 2026 Series A reported variously as $20M, $25M and £15M [WEAK — sources conflict] (SecurityWeek). Radiant Security, Dropzone, ReliaQuest, Intezer, 7AI, Anvilogic, Swimlane and Tines fill out the field.

Every one of them faces the same question from a buyer: how is this better than the other nine? And none of them discloses buying external evaluation data. They capture expert knowledge from customers in-product instead. ReliaQuest says its AI is "trained on real-world SOC data, not generic models or synthetic datasets." Prophet "learns from analyst feedback over time." Legion ships a browser extension that "observes how analysts interact with tools like Chrome, Edge, or Island, and learns their decision-making patterns," on the stated view that "real analyst behavior holds more value than any off-the-shelf playbook or pre-trained model" (Legion).

Legion is the important one to understand, because it has proven half the thesis and disproven the other half. It has demonstrated that analyst behaviour is the valuable artefact. It has also demonstrated the business model not to copy: it sells the capture mechanism to the customer, so the resulting data stays inside each customer's tenant and never aggregates into a saleable corpus. See Defensive supply for who those analysts are and what they cost.

Second, independent evaluation capacity is being vacated exactly as consolidation starts. Microsoft, SentinelOne and Palo Alto Networks all withdrew from the 2026 MITRE ATT&CK Evaluations, announced around 22 September 2025, citing reallocation of resources to product roadmaps (Cybersecurity News). MITRE's evaluation is the only vendor-neutral operational benchmark in the defensive market, and it is losing its largest participants at the moment vendors are publishing their own benchmarks instead.

Meanwhile the consolidation arrived: Cribl acquired Radiant Security's AI SOC technology on 19 August 2026, its second security deal of the year (SiliconANGLE).

Why those two facts belong together

Consolidation markets reward whoever owns the comparison metric — an acquirer needs a number to justify a price, and ten near-identical vendors need a number to differentiate. The one neutral scoreboard is losing its anchor participants. The buyer-side pitch to this segment is "an eval set you can cite that you did not write," and it is stronger now than it was twelve months ago. It is still a pitch, not a purchase order.

Third, some enterprises do buy adversarial testing — from AI-security firms, not from data vendors. Snowflake is a Gray Swan AI enterprise customer, using it to test Cortex Code and Snowflake Intelligence agents, and Snowflake Ventures also invested (Forbes). Gray Swan's broader self-claimed list adds Deloitte, ElevenLabs, Intercom, Anaconda, OpenHands and AIUC [WEAK — self-claimed] (RL List). And SpecterOps appears on both sides of the market: it built UK AISI's corporate cyber range, and its CTO is cited as a user of OpenAI's GPT-5.6-Cyber. Security consultancies are becoming suppliers of evaluation content and consumers of frontier cyber models simultaneously.

That last pattern is the one to watch, because it means the consultancies are competitors for the same expert labour described in Offensive supply before they are customers.

MSSPs and integrators: deploying, not buying

The systems integrators are moving fastest and disclosing least. Accenture and Anthropic launched Cyber.AI on 25 March 2026, with Claude as "the reasoning engine at the core," orchestrating autonomous agents across identity security and cyber defence; Accenture reports cutting internal scan turnaround "from three to five days to under one hour" and expanding security testing coverage "from approximately 10% to over 80%" (Accenture). ReliaQuest announced agentic cyber defence built on Claude (Cybersecurity Insiders).

Neither announcement discloses training data, expert knowledge capture or evaluation methodology. Accenture in particular sits on a proprietary agent library and enormous consultant headcount, which makes it a plausible buyer of evaluation data and an equally plausible competitor that produces it in-house [UNVERIFIED — assessment, not sourced]. A firm that already employs security consultants at that scale does not obviously need to buy expert hours.

Insurers and AI assurance: the most credible emerging buyer

Insurance is the only mechanism in this section that creates a recurring, contractual reason to test.

AIUC has built AIUC-1, described as the first AI agent certification standard. It requires AI companies to implement "50+ technical, operational and legal safeguards" across six risk areas including Security, and to undergo "frequent, rigorous, third-party technical testing to show the safeguards' effectiveness," including "advanced adversarial attempts to jailbreak models, create harmful content or leak data based on the latest AI security research" (AIUC). The design is deliberately SOC 2-shaped: certificates come with independent audit reports. Schellman is accredited as the first AIUC-1 auditor and separately sells AI red teaming (AIUC; Schellman). AIUC-1 has been added to the Cloud Security Alliance's STAR Registry (CSA), and ElevenLabs secured AI agent insurance backed by AIUC-1 certification.

AIUC secured Beazley paper for its liability product in May 2026 (The Insurer) — headline verified, article body behind robots.txt, so terms could not be established. Armilla runs a comparable verification-plus-insurance model (Armilla). The Big Four are all reported to be targeting AI assurance [WEAK] (IMP.NEWS), and KPMG has announced expanded AI assurance capabilities (KPMG).

The catch a cyber specialist must not paper over: AIUC-1's security testing is AI-system security — jailbreaks, prompt injection, tool misuse, data leakage — not offensive cyber capability. Those are adjacent skills, not the same skill. An assurance-driven business would be a different product line from selling zero-day-class evaluation environments to frontier labs. Worth tracking; not worth building for first.

What enterprises pay, for calibration only

All vendor-published, so [WEAK] throughout — every source here has an interest in the number (Repello; AI Vyuh):

Engagement shapePublished range
Red-team-as-a-service, per engagement$10,000–$100,000
Per-test, usage-based by system type$8,000–$150,000
Hybrid platform plus services, annual$75,000–$400,000/yr
Single text-only chatbot, annual audit$20,000–$40,000
RAG app on internal docs, quarterly$60,000–$120,000
Multi-agent system, regulated data, continuous$200,000–$500,000+

These are services prices, delivered as consulting hours — gross billings to an enterprise, not net revenue on a data product, and the distinction matters more here than anywhere (GMV is not revenue). They tell you what an enterprise will tolerate for adversarial testing. They tell you nothing about what a lab pays per hour of expert cyber trajectory, which remains the missing number across this entire dossier and is discussed in Sizing the cyber pot.

The verdict on this segment

Security product companies are more plausibly competitors for the same expert labour pool than near-term buyers of expert cyber data. They have money, they have a comparison problem, and the neutral referee is walking off the pitch — which is a mechanism. What they do not have, anywhere in the public record, is a single instance of paying an outside party for annotated cyber data.

Sell to the labs first (The labs as buyers) and to UK AISI and ARIA second (Government buyers). Come back here when one of these ten vendors publishes a third-party evaluation with somebody else's name on it — that will be the first real signal, and it costs nothing to watch for.