A security team that cannot send its data anywhere has spent years watching AI happen to everyone else. This conversation looks at what changes when the model, the data, and the verdict all stay inside the building.
Crogl arrived at Black Hat USA 2026 with two announcements behind it. The week before the show, the company made a free download of its AI SOC agent generally available. On the morning of this conversation, it went public with a major global partner tied to the U.S. Department of Defense. Monzy Merza, Co-Founder and CEO of Crogl, ties both back to a position the company took three years ago, which is that customers should control their own data and a security product should be secure.
What does sovereignty mean in security operations? Less about geography, more about control and choice. Merza points to the electric utility that wants current AI technology inside an OT environment and historically had one path, which ran through the internet. Crogl is built to run closed off from the internet with its capability intact, which is what critical infrastructure operators, large banks, and defense organizations need to satisfy their own regulators.
There is a second reason, and it lands on intellectual property. A large financial institution holds knowledge about its customers that nobody else holds. If an outside party takes that data and builds derivative work from it, the institution has given away something it never intended to sell.
Can a sovereign deployment still be flexible? Merza makes the case that it can when the architecture is right. Customers bring whatever model they want, including models they build. Crogl creates a semantic layer across data stores without transforming, normalizing, or moving the data, so a field labeled one way in one data lake connects to its counterpart in the next. Federated querying and federated search were base principles from the start, and the company holds a patent on the approach. One customer runs a hundred terabytes a day across six data lakes.
The operational math is where it gets interesting for the business. An analyst who might close ten alerts in a shift can work fifty or sixty when the rest arrive with a verdict and documentation already attached. Risk drops because alerts actually get investigated, audit cycles move faster because the evidence is there when the auditor asks, and cost follows the data rather than the pipeline.
The reaction from practitioners is the part Merza keeps returning to. Rather than worrying about being replaced, the people he talks with are glad to skip the seventeen thousandth phishing email and spend that time on a blast radius question they could not get to before. One person went from a fresh install to a submitted investigation report in under ten minutes and posted about it publicly.
This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight
GUEST
Monzy Merza, Co-Founder and CEO of Crogl | On LinkedIn: https://www.linkedin.com/in/monzymerza/
RESOURCES
Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas
Learn more about Crogl: https://www.crogl.com
Download Crogl: https://www.crogl.com/download
Crogl newsroom: https://www.crogl.com/newsroom
Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings
KEYWORDS
monzy merza, crogl, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, sovereign ai, ai soc, autonomous investigation, threat hunting, air gapped deployment, ot security, federated search, knowledge graph, alert triage, soc analyst workload, audit evidence, data sovereignty