The AI does the work. A person you name approves the change.
Every finding from every module lands in one Risk Register with a live Security Score and a ranked list of Top actions. The AI triages, investigates, cross-checks and proposes fixes. Nothing runs against your estate until someone on your side approves it, and every step is written to a tamper-evident log.
- findingEndpoint running an out-of-date package with a known CVE
- proposalUpdate the package through the Penthropic agent
- risk levelLow-risk write · approval required by policy
- approvalWaiting for a named approver in the Approvals queue
- executionRuns only after approval, with the tool the policy allows
- verifyRe-checked after the change before the finding closes
- auditProposal, decision, tool call and outcome appended to the hash chain
What the AI does without being asked
These are the jobs that run in the client portal today. Each one writes its output to the same register, so there is one score, one action list and one evidence trail rather than a dashboard per tool.
Triage on every new alert
Every alert is triaged as it arrives. A daily analyst sweep, an incident analyst and an evidence reviewer run on their own schedules. A monthly report is drafted from the record.
Case files, not tickets
Every alert becomes a case. The platform reconstructs the timeline, pulls the entities, gathers the evidence and drafts the closure report with citations to the log lines it used. An analyst approves and signs it.
Proposed fixes, held for approval
Remediation is proposed, never taken. You approve in the Approvals queue. Endpoint fixes run through the Penthropic agent with a verify step after the change. Cloud fixes use an opt-in, write-scoped role you grant.
The one fix that breaks the most paths
Reasons over the network the Sentinel appliance and the edge agent mapped, and names the choke-point fix that removes the most routes to what matters.
Cheap checks free, reasoning where it counts
Deterministic rules do the routine work at no credit cost. The AI reasons only where a rule cannot decide. The credit cost is shown before, during and after the scan.
Reads the evidence, not the tick box
Reads the SOC 2 report, ISO certificate, policies and DPA a vendor uploaded and checks every high-stakes questionnaire answer against them, citing the page. Contradictions surface before signature. See third-party risk.
Where a person sits in the loop
Tools sit in a registry with four risk levels: read-only, low-risk write, high-risk write and destructive. High-risk and destructive tools always require approval. Anything client-facing or critical is forced through a human review gate before it leaves the admin side.
-
Finding
A module raises a finding into the Risk Register with its source and severity.
-
Proposal
The AI drafts a remediation with the tool it intends to use and the risk level that tool carries.
-
Approval
A named person on your side approves or rejects in the Approvals queue. The decision is recorded with who and when.
-
Execution
Only the allow-listed tool runs, only after approval. There is no raw shell execution anywhere in the platform.
-
Verification
The change is re-checked before the finding closes. A control is reported as verified only when it has been checked, not when it has been configured.
Configured and verified are different words. The platform says a control is verified only when it has looked. A fix that was approved and run but not yet re-checked stays open.
Every statement carries its source
A closure report cites the log lines it used. A vendor cross-check cites the page of the document it read. AI outputs carry a confidence and the evidence behind them, so a reviewer can open the source rather than take the summary on trust.
When the AI could not finish reading, it says so. A truncated or unfinished read is reported as unfinished, never as a pass.
- Case closure
- Report drafted with citations to the specific log lines. Signed by an analyst before it leaves the admin side.
- Vendor evidence
- High-stakes answers checked against the uploaded SOC 2 report, ISO certificate, policies and DPA, with the page cited. The vendor's own words are kept so they can be contradicted later.
- Drift
- When a vendor resubmits, the new answers are compared with the old ones and the differences are named.
- Unfinished reads
- A read the model did not complete is marked unfinished. It is never rounded up to a pass.
Controls enforced in code, not in a policy document
Each of these is a control the platform applies to every AI job.
- Tenancy
One tenant per job
Every AI job is scoped to a single tenant and the tenant id is asserted at the boundary before the job runs.
- Isolation
Cross-tenant output rejected
Output that references another client is rejected before it is stored or shown.
- Secrets
No secrets in prompts
Content is redacted before it reaches the model.
- Injection
Prompt-injection markers neutralised
Markers in ingested content are neutralised and counted, so the count can be read by a person.
- Tools
A registry with four risk levels
Read-only, low-risk write, high-risk write, destructive. High-risk and destructive tools always require approval.
- Allow-lists
Explicit tool allow-lists per agent
An agent can call only the tools it is listed for. There is no raw shell execution.
- Audit
Every step audited
Every proposal, decision, tool call and outcome is written to a hash-chained, tamper-evident log.
- Cost
Tokens and cost per job
Per-job token use and cost are logged. For the AWS scan the credit cost is shown before, during and after.
- Resilience
A fallback model for every workflow
Every workflow has a defined fallback model.
- Evidence
Confidence and evidence on every output
AI outputs carry a confidence and the evidence they rest on.
A record an auditor can check without us
The audit log is hash-chained: each entry commits to the one before it, so an edited or missing entry breaks the chain. Case evidence sits in an evidence locker with chain of custody. Audit packs from the AI control plane are signed with Ed25519 and can be verified with a standalone verifier that runs outside the platform.
- Region
- Data is processed in AWS London (eu-west-2), except by the processors named in the privacy policy.
- Models
- Frontier models from Anthropic (Claude), called through Penthropic's own guardrailed client. Anthropic is disclosed as a processor in the privacy policy.
- Tenant scope
- One tenant per job, asserted at the boundary. Output that references another client is rejected.
- Log integrity
- Hash-chained entries. Per-job tokens and cost recorded alongside the decision.
An AI control plane for the AI your people already run
The same platform inventories and governs AI use inside your business. The endpoint agent already collects installed software, browser extensions and listening ports, so a local model server, an AI command line tool or an AI browser extension shows up in the inventory without a separate deployment. A discovered item is marked discovered, not registered, until a person confirms it.
- Inventory
AI inventory from telemetry
Registered AI assets alongside items discovered on endpoints: local model servers, AI CLIs, browser extensions.
- Shadow AI
Shadow-AI detection
AI tools nobody registered, surfaced from the same endpoint telemetry as Shadow IT.
- Policy
Usage policies with exceptions
AI usage policies with exceptions and approvals, and control evidence recorded against each.
- Frameworks
Evidence packs mapped to four frameworks
NIST AI RMF, ISO/IEC 42001, the EU AI Act and the OWASP LLM Top 10.
- Signed packs
Ed25519 signed audit packs
An auditor verifies a pack with a standalone verifier outside the platform.
- Vendors
AI vendor risk
An AI tool promoted from the inventory lands in the vendor register as an AI vendor, with its provenance.
Attacks your LLM application the way an attacker would
On a schedule, against the target you register, with the results diffed against a pinned baseline so a regression is a named change rather than a new score.
A grade never ships alone
The per-case verdicts always travel with the grade. A number without the cases behind it is not published.
Captured responses are redacted
A redactor removes secrets from the responses the suite captures before they are stored.
A CI gate
Run the suite in your pipeline and fail the build on a regression against the pinned baseline.
A named analyst in the portal Early access
Annabel reads your tenant's own programme state and answers with the source line for every statement, or says what she could not read. Any change you ask for is staged for your explicit confirmation. She proposes; she never acts.
Annabel is in early access and is not available to every client yet. She is not a vCISO. The fractional vCISO is a human service on the advisory side.
- Reads
- Your own programme state: the register, the score, the actions, the evidence.
- Answers
- With the source line for each statement, or a plain statement of what she could not read.
- Changes
- Staged for explicit confirmation. Nothing is applied on her own authority.
- Availability
- Early access. Ask whether your tenant is included.
See what the AI would propose for your estate
Thirty minutes on what the AI would propose for your estate, and who on your side would approve it.
Book a call