← Back to blog

Everyone is shouting the same sentence

Every vendor in this category is saying the same sentence. We built the best AI SOC. From every angle, on every channel, continuously. This chapter is about what that does to a market, and it is the only one in this log that ends without a resolution, because I have not found one.

The observation

Spend a week reading what is published about autonomous security operations and the messages become indistinguishable. Autonomous triage. Analyst-grade investigation. Reduce alert fatigue by some large percentage. AI-powered, agentic, tier-one replacement. Every company, including the ones whose product is a summarisation wrapper and the ones who have genuinely built something, saying the same words with the same confidence.

I am not exempt from this. Read my landing page from June and it is the same sentence in different fonts. That is part of why this observation took so long to arrive: from inside, your version feels substantiated, because you know what is underneath it. The buyer does not, and cannot, and has no reason to assume yours is the one with something underneath.

What that does to the mechanism

In a market where every message is identical, the message stops carrying information. If every vendor asserts the same capability with the same conviction, the assertion is not a signal — it is table stakes noise, and the buyer has to decide on something else.

The uncomfortable possibility is that the something else is volume. Who they have heard of. Who was in the room. Who had a booth, a podcast slot, a peer who mentioned it, a consistent presence over eighteen months. All of which is bought, one way or another, with money or with time, and neither of which correlates with whether the architecture is real.

The question I cannot answer. Does this buyer evaluate architecture, or do they buy the loudest voice? Nothing in my funnel tells me. I have fewer than twenty touches and zero conversions, which is consistent with both explanations and evidence for neither.

The case for "it does not matter"

Put fairly, because I think it is at least partly true.

Nobody buying a security product for a fifty-person company is reading an architecture document. They are busy, they are generalists, and the difference between a genuine multi-agent evidential system and a well-marketed summariser is invisible from outside — both produce a confident verdict in a chat channel. Evaluating the difference would require running both against known-bad traffic for a month, which nobody has time to do.

So they use proxies: brand recognition, peer recommendation, who the distributor carries, who showed up. And those proxies are purchasable. On this reading, the correct strategy is to get the product to adequate and spend everything else on being heard, and every hour I spent on evidential fusion was an hour not spent on the thing that decides outcomes.

The case for "it does"

Also fairly. This category has a property most do not: the product's failures are eventually visible and expensive. A summariser that closes a real intrusion as benign produces a breach conversation, and that conversation happens at the service provider who resold it. Providers talk to each other.

So the architecture may not decide the first sale, and may decide the fifth, and almost certainly decides the renewal. A well-marketed product that is shallow underneath accumulates a specific kind of reputation among practitioners, slowly, and the market for this is small enough that it circulates.

On this reading, distribution and substance are not alternatives. Distribution is what gets you evaluated at all; substance is what happens after. Being unable to do the first means never reaching the second, which describes my position exactly and is not the same as the first one not mattering.

Where that leaves me

With no resolution, which is why this chapter has no closing argument.

What I have decided, provisionally, is that the only asset available to someone who cannot outspend anyone is specificity. Not louder claims — a different kind of object entirely. Numbers with methods attached. Failures published at the same length as successes. A measurement that says the constants could not be calibrated, and what was done about it. None of that is persuasive in the way marketing is persuasive, and none of it can be produced by a company that does not actually have the thing.

That is a bet, not a conclusion. It might be the correct read of a market where trust is the scarce good. It might equally be a technical founder constructing a rationalisation for continuing to do the part he enjoys. I genuinely do not know which, and I would rather say so than write a confident ending onto the one question this whole project has not answered.

Who is writing this

I am Ivan Melekhin. Twenty-five years in cybersecurity, most of the last decade running security operations — building and operating distributed SOC and MSSP teams across Asia-Pacific, with a long detour through OT and maritime environments. This log is the build record for an autonomous SOC investigation agent I started in January 2026, written as the decisions happened rather than tidied up afterwards. I am on LinkedIn if you want to argue with any of it.