SentinelOne unveiled a series of AI security offerings at RSA Conference 2026 on March 23, headlined by Purple AI Auto Investigation, a one-click capability that launches complete agentic investigations. The feature autonomously gathers cross-stack evidence, synthesizes threat data, and constructs complete attack timelines in real time without requiring analysts to manually correlate data across multiple tools.
The announcement also included Prompt AI Agent Security and Prompt AI Red Teaming, two products designed to secure AI agents and agentic workflows in enterprise environments. The former monitors agent behavior for policy violations and adversarial manipulation, while the latter provides automated red teaming capabilities that probe AI deployments for prompt injection vulnerabilities, data leakage risks, and authorization bypass opportunities.
SentinelOne simultaneously released AI data pipeline functions that the company claims reduce noise by up to 80 percent before ingestion into Singularity AI SIEM, and announced support for on-premises and air-gapped environments with zero cloud dependency. The on-premises capability targets regulated industries and sovereign deployments where data cannot leave a defined geographic or network boundary.
The breadth of the launch positions SentinelOne as competing directly with CrowdStrike’s Charlotte AI AgentWorks and Palo Alto Networks’ XSIAM platform for the emerging AI-native SOC market, with differentiation on autonomous investigation depth and support for disconnected environments.
Source: SentinelOne Press Release.