Challenges
- A lean security team responsible for 24/7 coverage across a large and fast-growing company, lacking a unified way to monitor and make sense of data spread across multiple tools and telemetry sources.
- Alert investigations often required hours of manual work, aggregating data from multiple sources and following up with individuals involved before reaching a verdict.
- Customer datasets ranged widely in sensitivity, requiring security controls that could address both the most critical and routine data without gaps.
- Expanding business requirements and new data types continually introduced new monitoring needs, outpacing what a small team could handle without additional tooling.
Solutions
- Exaforce agentic SOC platform and MDR service provides 24/7 detection, triage, and investigation across Invisible’s broad environment from a single platform.
- Exabots automatically triage alerts and deliver enriched, readable verdicts with supporting evidence, cutting investigation time from hours of manual source-chasing to minutes.
- Unified visibility across cloud, identity, productivity, and SaaS environments gives the security team full context on every finding, from the most critical incidents to signals that would previously have gone unreviewed.
- Exaforce integrates new data sources and custom detection logic on request, keeping coverage current as Invisible's business requirements and technology stack evolve.
Keeping pace at a leading AI company
Invisible Technologies helps businesses make AI work. The company designs custom AI solutions across industry verticals, handles AI model training, and sources domain experts for targeted model development. That breadth of work means Invisible handles customer data across a wide range of sensitivity levels, from proprietary business data to operational AI training sets, making a strong security posture central to maintaining customer trust.
When Patrick McKinney, VP of Security at Invisible, joined as the first security hire, he was immediately responsible for fraud, corporate, and production security, each producing signals across different tools and data sources. There was no practical way for one person to keep up. Exaforce centralized visibility and handled 24/7 triage and investigation, allowing the team to stay on top of activity without adding headcount.
The impact was immediately apparent to Cory Roop, Director of Production Security. For a team that had previously relied on manual log exports and spreadsheet analysis, the contrast was stark: rather than forwarding raw alerts, the platform distills findings into clear, actionable summaries with full supporting context, laying out what happened, who was involved, where the activity originated, and what to examine next. Investigations that once required additional queries and context gathering were already done, allowing the team to move from digging for answers to making decisions in minutes.
"The time to detect, contain, and respond to incidents has gone from hours or days to minutes. I was looking at an alert this morning that would have been a multiple-hour investigation. Exaforce summarized everything I needed to close it out in a couple of minutes,” said Corey Roop, Director of Production Security at Invisible Technologies
One example illustrated the speed difference clearly. An AWS machine account had flagged activity originating from a residential IP address, the kind of finding that would normally trigger a high severity alert and a multi-step investigation to determine whether the address matched a known employee. Exaforce surfaced that the IP belonged to a shared workspace used by multiple employees, and this was a benign support scenario. An alert that could have consumed several hours was resolved in minutes.
The investigation experience differs from traditional SIEMs in a meaningful way. When the team queries Exaforce about access patterns or anomalous activity, the platform returns an answer, and the tier 3 analyst questions used to get the evidence. That guidance replaces the manual pivoting between consoles that traditional tools require, keeping investigations moving without requiring the analyst to know in advance what to look for.
"Everything we've done since Exaforce came in, the efficiency has gone up at least 10x, including response, visibility, investigations, all of it,” said Patrick McKinney, VP of Security. “It's just way faster. And it's allowed us to scale smarter, not with people, so we can actually address other areas of security that need that human resource.”
Exaforce enables Invisible Technologies’ security team to monitor employees, identities, applications, and infrastructure at scale without increasing headcount. The result is a lean operation that investigates faster, maintains 24/7 coverage, and scales seamlessly with the business.

