sequenced.ai
Articles/Agents & support/Blueprint//8 min read

Trend Micro connects security AI to the TrendAI Vision One platform

Trend Micro’s enterprise business is now TrendAI, combining Vision One investigation, AI application protection and credit-based licensing.

By Sequenced deskAI-assisted, source-led · how we work
Visit Trend Micro website ↗
TrendAIEnterprise businessPart of Trend Micro
Vision OneSecurity platformRisk, detection and response
Trend CompanionAI assistanceAlerts, queries and case context
Shared creditsLicensingUnits vary by capability
Trend Micro mark
Trend Microtrendmicro.com · independent research

Represent this company? Verify your work email to access its workspace, or send the desk a factual correction.

Trend Micro’s enterprise business is now TrendAI, combining Vision One investigation, AI application protection and credit-based licensing.

In brief
  1. 01What it does Applies AI to security investigation and offers protection for AI applications within its enterprise platform.
  2. 02Best fit Security teams connecting endpoint, cloud and identity evidence while adding AI-specific controls.
  3. 03Buying question Which credit-consuming capabilities, data volumes and deployment options does the proposed workflow require?

01 / ProductTrendAI is the enterprise business within the Trend Micro identity

Trend Micro announced on 23 March 2026 that its enterprise business would operate as TrendAI. That is an enterprise-business branding change, not a reason to create a second company blueprint. This article retains Trend Micro as the corporate identity and uses the current TrendAI name for its enterprise offer. The distinction also explains why readers encounter both names across product, documentation and commercial pages.

TrendAI Vision One connects cyber-risk exposure management with detection, investigation and response. Its relevance to AI spans two different jobs: using AI to help security analysts and protecting AI applications themselves. The first concerns the operator’s investigation workflow. The second concerns the inputs, outputs and attack surface of systems that use models. A purchase can involve either or both, with different technical and commercial requirements.

Trend Companion is the assistant integrated into the platform. The company documents alert explanations, natural-language search assistance, command-line interpretation and case summaries. It describes a mixture of models and retrieval within Trend Cybertron. These are vendor-described capabilities, not evidence that every investigation will be correct or faster. Sequenced has not tested the product or validated its detection and response claims.

02 / AudienceChoose between investigating with AI and protecting an AI service

A SOC with endpoint and cloud telemetry may want an easier way to understand a Workbench alert and identify the next useful query. That is an analyst-assistance problem. Trend Companion is relevant when it can interpret the same underlying evidence the analyst would otherwise assemble manually. Its value depends on coverage, connected identities and the quality of the event data, not merely the fluency of the explanation.

A product-security team operating a customer-facing AI application has a different requirement: examine requests and responses for attack patterns or sensitive material. The credit documentation identifies hosted and self-hosted AI Scanner and AI Guard options. Those components need to be evaluated in the application’s actual request path. Their existence should not be confused with a general promise that all model misuse can be prevented.

Compare Palo Alto Networks when consolidating enterprise security and AI protection is the main decision. Compare SentinelOne when endpoint-linked investigation and security operations are central. These comparisons are about the data and operational control each platform can bring to a workflow. They do not establish an independent ranking of detection quality, and feature names alone cannot resolve the migration effort.

03 / WorkflowProposed workflow: turn one alert into a reviewable investigation

Begin with a contained test environment and a representative alert already understood by the security team. Record its raw events, affected endpoint, associated account and expected benign or suspicious interpretation. This proposed workflow evaluates the assistant’s usefulness without treating its output as an incident verdict. Keep response actions under the team’s existing approval process during the assessment.

Ask the assistant to summarise the alert and identify the observed events that support its interpretation. Review the underlying evidence before accepting the narrative. Distinguish a recorded process execution from an inference about intent. If the summary attributes behavior to an account, verify that the identity mapping is correct and that shared or service accounts have not been treated as a named person.

Use the documented query-assistance function to investigate related activity. Inspect the proposed search, including its time window and the data sources it can see. A missing event may mean that a sensor is absent, a log is outside retention or the query is too narrow. Ask the analyst to record those possibilities rather than allowing the assistant to turn an empty result into a statement that no related activity occurred.

For an unfamiliar command line, use the assistant’s explanation as a starting point and compare it with the actual command and host context. Legitimate administration can resemble suspicious activity. Preserve arguments, timestamps and relevant change records in the case, then have the responsible analyst decide whether escalation is justified. The purpose is to make the reasoning inspectable, not to add an authoritative-sounding paraphrase to an incomplete alert.

If the organisation also evaluates AI application protection, run that as a separate branch of the pilot. Prepare authorised test prompts, expected normal requests and examples of content that policy should block or flag. Compare hosted and self-hosted routes against the application’s data handling requirements. Measure legitimate requests incorrectly blocked, unwanted requests missed and the effect on response latency. These are proposed evaluation measures, not measured Trend Micro results.

Close the pilot with an evidence-backed case and a small consumption record. Count the protected assets, ingested data, retained data and AI-protection requests that were actually used. This gives the buyer a way to map the technical workflow to licensing. It also exposes dependencies: an apparently simple AI summary may rely on separately licensed telemetry and retention, while application protection introduces a different usage unit.

04 / PricingCredits are shared currency, but the charging units differ

The TrendAI Flex licensing description presents a shared licensing model across security capabilities. The operational credit-requirements table is more useful for estimating a particular workflow because it identifies whether consumption follows assets, data volume, API calls or instances. A single number of credits is not meaningful without those underlying quantities.

For AI Application Security, the current table lists hosted AI Scanner and AI Guard at 800 credits for 150,000 API calls in its monthly column, with an annual quantity shown separately. The self-hosted option is listed at 600 credits per instance monthly and 7,200 annually. This is a published credit requirement, not a public currency price. The contractual price of credits and applicable commitments need a quote.

Keep SIEM ingestion and retention distinct. The table prices third-party analytic ingestion at three credits per GB and archival ingestion at one credit per GB, while retention is a separate line. A request to retain more history can therefore change the estimate even if event volume stays constant. Confirm the account’s exact drawdown rules and licensing term rather than multiplying a single endpoint price by the entire environment.

OfferCommercial basisBoundary
AI Scanner / AI Guard, hosted800 credits per 150,000 API calls in monthly tableCredit requirement; currency price requires quote
AI Scanner / AI Guard, self-hosted600 credits/instance monthly; 7,200 annuallyAWS-hosted customer deployment; scan results sent to platform
Third-party analytic ingestion3 credits per GB of data usageRetention is priced separately
Third-party archival ingestion1 credit per GB of data usageArchival use differs from frequent analytic querying

Commercial terms from Vision One credit requirements, consulted 24 September 2026.

05 / DifferenceThe platform can relate AI assistance to operational security context

Trend Companion’s useful characteristic is its position inside a security platform with alerts, cases and telemetry. An analyst does not simply want a definition of a suspicious command; they want to know why that command matters on this machine, for this account and at this time. Bringing the explanation close to the evidence can shorten the distance between understanding an alert and deciding what further information is needed.

The broader enterprise offer also puts AI application protection beside existing security operations. That may suit organisations whose product-security and SOC teams need a common view of the systems they protect. It does not eliminate the need for a clear handoff: a model input policy, an endpoint containment decision and a cloud permission change belong to different owners and require different proof that the intended outcome occurred.

06 / LimitsData handling and deployment details need a product-specific answer

The Companion FAQ says customer data is not used to train Companion and describes filtering common personal information from prompts. It also says the architecture uses third-party and proprietary models. Those statements should be read together: a no-training statement is not proof that no data leaves the customer environment. Ask for the processing and retention terms applicable to the selected tenant and feature.

The hosted and self-hosted AI-protection options have a meaningful distinction in the credit documentation: the self-hosted route runs in the customer’s AWS environment and sends scan results to Vision One. Confirm exactly which results and metadata are sent, which regions and versions are supported and who operates the instances. A self-hosted scanning component does not establish that the complete enterprise platform is an offline deployment.

Finally, map every proposed capability to a current product entitlement. Corporate and product naming is changing, and an older document may still describe a previous bundle or route. Require the demonstration and order to use the same feature names, quantities and operational scope. If the quote describes endpoints but the pilot requires third-party log analytics or AI API scanning, reconcile those gaps before extrapolating cost.

07 / DecisionUse the company’s breadth only where it simplifies a real workflow

Trend Micro is a credible AI-related enterprise-security candidate because its offer connects operational AI assistance and protection for AI applications. The practical decision is which of those jobs the organisation needs first. Prove one investigation or application-control path, keep evidence and policy ownership clear, and translate measured usage into the exact credit model. The rebrand does not remove the need to verify the underlying feature and service boundaries.

Security operations

Alerts need clearer explanations and follow-up queries

Evaluate Companion on known cases and verify evidence, identity and search scope.

Start with analyst assistance
AI product team

A model service needs input and output controls

Test hosted or self-hosted protection against permitted and unwanted application requests.

Measure the request path
Platform consolidation

Several security capabilities share a budget

Map assets, data and AI calls to the actual credit schedule and quoted commitments.

Price the complete scope
What should we explore next?

A business worth understanding.

Suggest your business or one you find interesting. Tell us what you want to understand about its product, positioning, design or workflows.

Suggestions are free. Selection and publication stay with the desk.

Sources
Filed under Agents & supportCompany Trend MicroNot affiliated with Trend MicroRequest a correctionRequest a refresh by email

Continue reading

All in this category