Penthropic Security

Ready to strengthen your security programme?

Book a Discovery Call

AI Security Company · London

AI that checks.
Evidence that proves.
A fix you approve.

The platform watches your estate and your vendors around the clock, cross-checks what it is told against what is actually exposed, and raises a finding the day a control regresses. Nothing changes in your environment until a person you name says yes.

Finding Illustration

Vendor attests to MFA on all administrative access. The exposed admin login accepts a password alone.

Claimed
SOC 2 Type II report, CC6.1: multi-factor authentication is enforced for all privileged access.
Observed
Admin sign-in returned a session after username and password. No second factor requested.
Source
vendor-upload/soc2-2026.pdf p.41 · probe 2026-09-14 09:12 UTC · ISO 27001:2022 A.8.5
Fix proposed. Waiting for approval by the named owner.
An illustrative finding: what was claimed, what was observed, the source of each, and its approval state.
Fixed-fee or retainer Start within 2 weeks Reply within 1 business day
24/7
Platform keeps watch
<1 day
Response time
CISSP · CCSP
Certified practice
London
UK-based, UK-hosted

What the AI does on its own

It reads, it looks, it writes up what it found.

Three jobs run without anyone asking. Every output names what it read and what it could not read, so you can check the work instead of trusting it. How the AI works sets out each job, the guardrails and the audit trail.

Reads vendor evidence

The SOC 2 report, policy or DPA a vendor uploads is read, not filed. Each high-stakes questionnaire answer is compared with the document behind it, and with what is exposed on the vendor's own estate.

Carries: the evidence it relied on, and the answers it could not verify.

Investigates alerts

A detection is written up before a person has to open it: the logs, hosts and identities examined, the timeline reconstructed, and the gaps in the data.

Carries: what it examined, and a plain statement of what remains unknown.

Watches the attack surface

Domains, certificates, exposed services, email authentication and cloud posture are checked on a cadence. When a control that passed last time fails this time, a finding is raised that day.

Carries: the last result that passed, the result that failed, and when each was taken.

What it reads

Your tools carry on.
Their evidence lands here.

Penthropic does not ask you to replace what you already bought. It reads it. Three security tools connect and start sending within minutes, and anything that can send JSON over HTTPS pushes its events in without waiting for us to write a connector for it.

Polled every five minutes

Three connect straight away

CrowdStrike Falcon detections, AWS CloudTrail and the Okta System Log. Okta gives us every sign-in and every administrative change. CloudTrail arrives through a cross-account role you create yourself, so we never hold an access key of yours.

Everything else you run

If it speaks JSON, it connects

Create a connector, take the token it shows you once, and point your tool at the endpoint. It posts JSON over HTTPS and the events land in the same timeline as the rest. You do not need us to build a connector first.

Before you connect anything

We start from the outside

Your DNS records, your certificates and your email authentication are readable by anyone, so those are what we read first. You have a picture on day one, before a single credential changes hands.

Into your estate
The Penthropic agent runs on macOS and Windows and reports disk encryption, firewall state, installed software, browser extensions, patch level, exposed services and file permissions. It opens no network port and reaches us by outbound connection only. It is in beta and the builds are not code signed yet, so installing one means clicking past your operating system's warning.
Back out again
Findings can be raised as Jira issues, and alerts delivered to a Slack channel your team already watches. Connect CrowdStrike Falcon and its host inventory and Spotlight vulnerability data land in your asset register every hour.
What we cannot see
We will tell you which parts of your estate we cannot read, by name, on the same page as the parts we can. A connector that has stopped collecting is not allowed to look like one that had nothing to report.

What it never does on its own

No change without a named person saying yes.

The AI can propose a fix. It cannot run one. Every action passes through the same gate, and the record of who opened it is part of the evidence.

  1. Finding raised

    What was claimed, what was observed, and the source of each. The control and framework clause it maps to.

  2. Fix proposed

    The exact change, the system it touches, and what the AI expects to see afterwards. Written before anything moves.

  3. Approved by you

    A person you have named approves or declines. Approval covers this one change, not the class of change.

  4. Action recorded

    Who approved, when, what ran and what it returned, kept on the approval record itself.

  5. Closure re-verified

    The finding is not closed because the fix ran. It is closed when the next check observes the control working.

Three gates, and one switch that stops everything

An action class must be armed for your tenant, you must approve the specific action, and the platform-wide switch must be on. Turning that switch off stops every automated change. Ask to see it during onboarding.

What you get out

Answers you can hand to a regulator, an insurer or a customer.

Not a dashboard to interpret. Three things, each with the source attached.

A register of risks with owners and dates

Each risk names the person responsible, the date it was raised, the date it was last verified, and the framework clauses it bears on.

  • ISO 27001:2022, SOC 2, DORA, NIS2, GDPR, FCA
  • Exceptions carry an expiry date, not a permanent pass

An evidence pack an auditor can open

For each control: the check that ran, when, what it returned, and the document or probe it came from. Files, not screenshots.

  • Board pack on the cadence you set
  • Approval log with names and timestamps

Findings that name the control and the source

Claimed, observed, delta, control. The same four fields whether the subject is your own cloud account or a vendor's SOC 2 report.

  • What it could not read is stated, never hidden
  • Closed only after re-verification

The platform at work

From signal to fix, live.

Signals stream in from across your estate. The platform flags what's real, ranks what matters, and drives each fix through your approval, with the evidence filed as it goes.

Signals in
  • Attack Surface
  • Vulnerabilities
  • Dark Web
  • Cloud & SaaS
  • Identity & Email
  • Vendors · TPRM
Your whole estate, streaming in continuously.
Penthropic Cyber · Unified
  1. Flags

    Watches every signal and flags what's genuinely a risk, no alert noise.

  2. Prioritises

    Ranks what matters by real-world exploitability and business impact.

  3. Fixes

    Drives each fix through, Autopilot acts only with your approval.

  4. Proves

    Files signed evidence as it goes, ready for your board and insurers.

Actions out
Top actions Prioritised
  • Patch exposed service
  • Rotate leaked credential
  • Review vendor risk
Board pack · Evidence Vault updated

How it works

Connect. Baseline. Operate.

From install to a live risk picture in the portal, then an operating rhythm of flag, fix, and prove.

01

Connect

Install the Penthropic agent, connect AWS, Okta or CrowdStrike, point anything else at the JSON endpoint, and bring your vendor list into TPRM.

02

Baseline

The platform maps your estate and builds your risk picture: a security score, a risk register, and your external attack surface.

03

Operate

Approve prioritised fixes, watch your score climb, and pull board packs when you need them. Advisers and vCISO support on tap.

What the platform solves

Findings buried in spreadsheets One ranked risk register
No idea what to fix first Top actions, by risk and cost
Fixes that stall for months Driven to done, with your approval
Audit-time evidence scrambles Evidence filed as you go
Vendor risk in email threads Live TPRM assessments

Why Penthropic

Finding risk is easy.
Fixing it is the job.

Most tools stop at the finding: a scan, a score, a PDF of problems. Penthropic is built around the fix. Each flagged risk lands in one register, gets ranked by what it would actually cost you, and moves through approval to done, with the evidence to prove it.

Behind the platform is a boutique London practice, CISSP and CCSP certified, working to ISO 27001:2022, SOC 2, DORA, NIS2 and FCA expectations. Advisory and vCISO support are there when you want humans in the loop.

Certified practitioner: CISSP · CCSP
Fixed-fee, outcome-based engagements
London-based, globally-aware

Get in Touch

Let's talk about
your security programme.

Whether you're preparing for an audit, designing a TPRM programme, or looking for ongoing security leadership, we'd love to help.

hello@penthropic.ai
London, United Kingdom
We reply within one business day
No sales pressure, ever
Discovery call is always free