Summary
BreachRx has launched the Rex Platform, an agentic AI incident command center designed to handle multiple simultaneous breaches — a scenario the company argues is now the norm in an era of AI-accelerated attacks. The platform evolves from BreachRx’s earlier generative AI engine, Rex AI, which launched in March 2025, into a full-featured operations center where entire response teams coordinate.
At the heart of the platform is the Maestro orchestration agent, which tracks incident progress and delegates work to a roster of specialized AI agents. These handle severity assessment, playbook execution, regulatory disclosure requirements across jurisdictions, executive report drafting, document analysis, and tabletop exercises. A key differentiator is that Rex operates out-of-band — completely independent from potentially compromised corporate networks — so response coordination continues even when the corporate environment is frozen or under investigation.
BreachRx, which counts Coinbase, American Express, and Commvault among its 100+ customers, raised a $15M Series A in May 2025 led by Ballistic Ventures. The company cites the Cloud Security Alliance’s “AI Vulnerability Storm” report, which warns AI can shrink the time between vulnerability exposure and active exploitation to hours.
Source
SiliconANGLE | GlobeNewsWire | SC World
Commentary
The premise here is sound: incident response was designed for a world where major breaches happen one at a time, and organizations struggle to handle even that. AI-accelerated attacks are already producing scenarios where multiple incidents hit simultaneously, and most security teams still coordinate through a patchwork of Slack channels, shared docs, and tribal knowledge. Having AI agents handle the grunt work — regulatory lookups, report drafting, playbook tracking — frees human analysts to focus on the decisions that actually require judgment.
The out-of-band design is the smartest architectural choice. Too many IR platforms assume the corporate network is still functional during an incident, which is exactly when it might not be. That said, the real test for any agentic IR platform is whether it can earn trust from the legal and compliance teams who ultimately own breach response decisions. AI-generated disclosure recommendations are only useful if the people signing off on them actually believe the output.
