SAASPOCALYPSEverdict #7AI-AD00
scanned 2026.08.11 · 18:02
subject of investigation

7ai.com

agentic security platform
verdictCONTESTED
wedge score
49
/100
wedge thesis

the door is distribution + regulatory posture: they're selling enterprise-managed agentic SOC as a service, so the weakest surface is channel and partner distribution rather than a deep technical or data moat.

real walls — pick your flank·ship in 3 months·run for $46.00/mo
the doornetwork
wedge

where the walls are.

methodology →
the door

no network effect to overcome — users don't compound users.

watch out

their capital wall is real — ongoing capex puts a floor under any clone.

capital
7.0/10
investment the incumbent had to make
why this scoremedium confidenceEnterprise-managed SOC requires significant non-software spend (human analysts, SLAs, procurement) and operational...

Enterprise-managed SOC requires significant non-software spend (human analysts, SLAs, procurement) and operational costs that are hard for small teams to match.

  • Product is an enterprise-managed agentic SOC as a service requiring managed services and contracts.
  • Estimated competing cost includes contracted analyst time and ops amortized (~$19k).
  • Wedge notes highlight enterprise sales, SLAs, and procurement burden as 'nightmare'.
technical
6.0/10
depth of the underlying engineering
why this scoremedium confidenceIntegrations, reliable agent playbooks, and human-in-the-loop orchestration require nontrivial engineering and...

Integrations, reliable agent playbooks, and human-in-the-loop orchestration require nontrivial engineering and security expertise but are not uniquely proprietary.

  • Challenges list integration with CloudTrail, EDR, SIEM APIs and authoring reliable agent playbooks.
  • LLM-proposed stack uses common frameworks (Next.js, Supabase, Cloudflare) indicating standard tech.
  • Detected stack signals: CDN Cloudflare; product relies on connectors and orchestration.
networkdoor
2.0/10
users compound users
why this scorehigh confidenceNo evidence of marketplace, UGC, or multi-sided liquidity; distribution is the wedge, not network effects.

No evidence of marketplace, UGC, or multi-sided liquidity; distribution is the wedge, not network effects.

  • Wedge thesis states distribution and partners are the door, implying no inherent network moat.
  • Report notes customers buy trust and operations rather than community or marketplace effects.
  • Deterministic distribution signals show no knowledge graph or organic ownership signals.
switching
5.0/10
stickiness of customer data + workflow
why this scoremedium confidenceThere's moderate switching friction from integrations, approvals, and SOC workflows, but connectors and data are...

There's moderate switching friction from integrations, approvals, and SOC workflows, but connectors and data are exportable and not fully locked-in.

  • Challenges include workflow lock-in elements: approvals, escalation rules, and audit trails.
  • Integrations with common log sources are straightforward, reducing lock-in risk.
  • Customers buy managed service/trust which can create contractual switching costs.
data
3.0/10
proprietary data accumulates over time
why this scoremedium confidenceNo strong proprietary telemetry or unique corpus; product leans on integrations and human operations rather than...

No strong proprietary telemetry or unique corpus; product leans on integrations and human operations rather than exclusive accumulated data.

  • Take_sub explicitly says product relies more on integrations and human-in-the-loop than proprietary telemetry.
  • Challenges and stack imply use of common log sources (CloudTrail, EDR) which are accessible to competitors.
  • No mention of proprietary training corpora, behavioral flywheels, or non-exportable datasets.
regulatory
6.0/10
real licenses, not SOC 2 theater
why this scoremedium confidenceSelling enterprise security and SOC services implies regulatory/compliance expectations and SLAs that raise barriers,...

Selling enterprise security and SOC services implies regulatory/compliance expectations and SLAs that raise barriers, but no explicit regulated licenses were cited.

  • Wedge and take note enterprise-managed SOC requires contracts, SLAs, and compliance posture.
  • Challenges list enterprise procurement and trust-building for security teams, implying regulatory scrutiny.
  • Report does not list explicit regulated duties (HIPAA/FINRA/KYC), so score is mid-range.
take

the blunt take.

7AI sells outcomes and managed service credibility to large orgs — that's expensive to duplicate, but small teams can wedge in by owning a vertical or partnerships where enterprise procurement is simpler.

The product leans on integrations and human-in-the-loop managed services more than proprietary telemetry; customers buy trust and operations rather than unique data, so targeted resellers or niche integrations can undercut the generalist pitch.

cost

cost of competing.

what they charge
Enterprise / Managed service
custom / demo required
/ per org / month
no public pricing; positioned as managed outcomes
annual:custom
what running yours costs
01 · Vercel (hobby tier)$0.00
02 · Supabase (Postgres + Auth, Launch)$25.00
03 · Cloudflare R2 (logs & artifacts light)$1.00
04 · Monitoring (Sentry / Axiom free)$0.00
05 · Domain$1.00
06 · Ops & human-in-loop (contracted analyst time amortized)$19.00
TOTAL / mo$46.00
▸ break-even:depends — pricing is enterprise and opaque; if they charge >$5k/mo for a managed pilot, a focused small-provider can break even within a few customers, otherwise depends on contract size.
build

what you're up against.

2 weeks research & integrations · 4 weeks MVP agent flows · 4 weeks partner outreach & pilot · ongoing ops tuning
easy
medium
hard
nightmare
01
easy
Integrating with common log sources
Connectors for CloudTrail, EDR, and SIEM APIs are straightforward and many have SDKs.
02
medium
Authoring reliable agent playbooks
Translating detection logic into deterministic flows that don't produce noise requires iteration and domain knowledge.
03
medium
Human-in-the-loop orchestration
Workflows, approvals, and escalation rules plus audit trails add product complexity beyond simple automation.
04
hard
Establishing trust for security teams
Customers demand explainability, provenance, and reproducible reasoning — UX and logging are critical.
05
nightmare
Enterprise sales & procurement
Selling managed SOC capabilities requires contracts, SLAs, and compliance posture that can consume a small team's bandwidth.
stack

their position.

detected signals· measured
cdnCloudflare
recommended stack · inferred
inferNext.js + Vercel (hobby)inferSupabase (Postgres + Auth, Launch)inferCloudflare (CDN + R2)inferOpen-source connectors (CloudTrail, CrowdStrike APIs)inferZapier/Temporal or simple worker queue for agent orchestration
rivals

who else has tried this.

option A
Wazuh (self-host)
open-source SIEM/EDR you can run and script agent workflows around.
option B
Elastic SIEM + detection rules
free-to-start if you already ingest logs; build playbooks on top.
option C
Hire a boutique MSSP
lower-tech substitute: pay a small managed provider to triage alerts without building agents.
compare

similar scans.

same shape - different moat
ready to wedge in?
Get the wedge plan. Cancel some plans.
▸ generated with love, by a heartless robotverdict v2.5 · saaspocalypse.dev