Cotool website screenshot

Cotool

Cotool is an AI platform for the defensive security "blue team" — AI agents that scale detection, response, and threat hunting across an organization's security stack. Its three products, Detect, Respond, and Hunt, let teams author detections from natural-language descriptions, automate alert response and playbook execution with human-in-the-loop controls, and monitor threat intelligence for relevance and coverage gaps. Cotool's stated mission is to "scale defensive security with tokens," giving defenders machine-speed operational advantages instead of being limited by headcount, improving coverage and cutting mean-time-to-respond (MTTR). Cotool is a San Francisco company backed by Andreessen Horowitz (a16z), Y Combinator, WndrCo, and Homebrew. As of this profile it publishes a product and marketing site only — no public API, developer documentation, SDK, or MCP server was found.

Cotool is profiled on the APIs.io network. Tagged areas include Company, AI, Cybersecurity, Security Operations, and Threat Detection.

Cotool’s developer surface includes engineering blog and 9 more developer resources.

11.4/100 minimal ▬ flat Agent 4/100 human only Full breakdown ↓
scored 2026-07-27 · rubric v0.5
0 APIs
CompanyAICybersecuritySecurity OperationsThreat DetectionIncident ResponseThreat HuntingBlue TeamSOC Automation

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 11.4/100 · minimal
Contract Quality 0.0 / 25
Developer Ergonomics 0.4 / 20
Commercial Clarity 4.2 / 20
Operational Transparency 0.0 / 13
Governance 0.0 / 12
Discoverability 6.8 / 10
Agent readiness — 4/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/cotool: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Cotool Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Resources

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Access & Security 1

Authentication, authorization, and security posture

Commercial 2

Pricing, plans, and the legal terms of use

Company 5

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: cotool
name: Cotool
description: Cotool is an AI platform for the defensive security "blue team" — AI agents that scale detection, response, and
  threat hunting across an organization's security stack. Its three products, Detect, Respond, and Hunt, let teams author
  detections from natural-language descriptions, automate alert response and playbook execution with human-in-the-loop controls,
  and monitor threat intelligence for relevance and coverage gaps. Cotool's stated mission is to "scale defensive security
  with tokens," giving defenders machine-speed operational advantages instead of being limited by headcount, improving coverage
  and cutting mean-time-to-respond (MTTR). Cotool is a San Francisco company backed by Andreessen Horowitz (a16z), Y Combinator,
  WndrCo, and Homebrew. As of this profile it publishes a product and marketing site only — no public API, developer documentation,
  SDK, or MCP server was found.
url: https://raw.githubusercontent.com/api-evangelist/cotool/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- homebrew
x-tier: stub
x-tier-reason: portfolio-lead
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-07-22'
  method: derived
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-18'
image: https://www.cotool.ai/images/og.jpg
tags:
- Company
- AI
- Cybersecurity
- Security Operations
- Threat Detection
- Incident Response
- Threat Hunting
- Blue Team
- SOC Automation
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://www.cotool.ai
- type: About
  url: https://www.cotool.ai/about
- type: Blog
  url: https://www.cotool.ai/blog
- type: PrivacyPolicy
  url: https://www.cotool.ai/privacy-policy
- type: TermsOfService
  url: https://www.cotool.ai/license
- type: LinkedIn
  url: https://www.linkedin.com/company/cotool-ai
- type: Twitter
  url: https://x.com/cotoolai
- type: DomainSecurity
  url: security/cotool-domain-security.yml
- type: WellKnown
  url: well-known/cotool-well-known.yml
- type: LLMsTxt
  url: llms/cotool-llms.txt
x-enrichment:
  date: '2026-07-19'
  status: backfilled
  pass: local-v1
  note: backfilled from .gitignore signal + verified work evidence