Legion launches DragonClaw AI layer for security teams
Fri, 31st Jul 2026 (Today)
Legion Security has launched DragonClaw, an AI agent orchestration layer for security operations teams. The product is available to existing customers.
DragonClaw is aimed at Security Operations Centre analysts and security leaders who need to query security systems or trigger actions using natural language. The layer uses an organisation's existing security work, tools, processes and reasoning as context when deciding which agents to call and what tasks to perform.
It can be used to investigate issues such as the organisational impact of a newly disclosed common vulnerabilities and exposures entry, or to examine how internal processes, tools and staff make decisions during security operations.
Legion is positioning the launch around a persistent problem in security operations: teams often automate parts of their work, but many investigations still rely heavily on analysts because each organisation follows its own procedures for deciding which alerts to prioritise and how to respond. Static reporting also limits senior leaders who need current answers and follow-up detail rather than periodic summaries.
According to Legion, DragonClaw lets users ask for an answer or a completed action in their own words, without custom integration work. The orchestration layer interprets intent, selects the agents needed for a task and can coordinate agents that take action as well as those that return information.
Guardrails are built into the product, with explicit permission required before any action is executed. The system also uses only approved tools and credentials drawn from secure vaults.
Security context
The launch reflects a broader push across cybersecurity vendors to apply AI agents to operational work that has traditionally required manual handling. In practice, one of the central challenges has been adapting AI systems to each customer's specific workflows, approval structures and investigative habits rather than relying on generic automation.
Legion said its wider platform learns from the security workflows analysts already use, then turns those actions into deterministic and agentic workflows. It said this can be done without requiring integrations, a claim that may draw interest from security teams struggling to connect and maintain a patchwork of tools.
DragonClaw builds on that model by making stored security context directly usable across different roles. That includes analysts handling live investigations, managers reviewing operational performance and Chief Information Security Officers preparing for board-level discussions.
The company is headquartered in Tel Aviv and says it is backed by Coatue, Accel and Picture, with investors from Island, CrowdStrike, Wiz and Google DeepMind.
Michael Gladishev, Co-Founder and Vice President of Research and Development at Legion Security, outlined the rationale behind the new layer.
"Security teams need AI tools that actually understand how their organization works. That's been Legion's whole premise from day one: agentic security has to be trusted and bespoke, or it's not usable in a real SOC. DragonClaw puts that belief into practice, giving every person on a security team, from analyst to CISO, a way to act on their own organizational context in real time, without asking them to trust a black box to get there," Gladishev said.
The emphasis on context and permissions addresses a common concern in cybersecurity over whether autonomous systems should be allowed to act directly in production environments. By requiring explicit approval before execution and restricting actions to approved tools and credentials, Legion is framing the product as a supervised operational layer rather than a fully independent actor.
That distinction matters for security teams that must balance speed with control. Analysts and managers may welcome systems that reduce repetitive investigative work, but organisations also need a clear record of how decisions are made and which systems are authorised to take action.
Legion said DragonClaw is intended to work alongside human judgement rather than replace it, particularly where risk exposure depends on local processes and business context that do not fit neatly into a standard checklist.