The AI layer

The AI does the work. A person you name approves the change.

Every finding from every module lands in one Risk Register with a live Security Score and a ranked list of Top actions. The AI triages, investigates, cross-checks and proposes fixes. Nothing runs against your estate until someone on your side approves it, and every step is written to a tamper-evident log.

Autopilot · proposal traceIllustration
  1. findingEndpoint running an out-of-date package with a known CVE
  2. proposalUpdate the package through the Penthropic agent
  3. risk levelLow-risk write · approval required by policy
  4. approvalWaiting for a named approver in the Approvals queue
  5. executionRuns only after approval, with the tool the policy allows
  6. verifyRe-checked after the change before the finding closes
  7. auditProposal, decision, tool call and outcome appended to the hash chain
The shape of a real trace. The content is illustrative, not a client record.
Day to day

What the AI does without being asked

These are the jobs that run in the client portal today. Each one writes its output to the same register, so there is one score, one action list and one evidence trail rather than a dashboard per tool.

Detections & SIEM

Triage on every new alert

Every alert is triaged as it arrives. A daily analyst sweep, an incident analyst and an evidence reviewer run on their own schedules. A monthly report is drafted from the record.

Incidents

Case files, not tickets

Every alert becomes a case. The platform reconstructs the timeline, pulls the entities, gathers the evidence and drafts the closure report with citations to the log lines it used. An analyst approves and signs it.

Autopilot

Proposed fixes, held for approval

Remediation is proposed, never taken. You approve in the Approvals queue. Endpoint fixes run through the Penthropic agent with a verify step after the change. Cloud fixes use an opt-in, write-scoped role you grant.

AI Attack-Path Review

The one fix that breaks the most paths

Reasons over the network the Sentinel appliance and the edge agent mapped, and names the choke-point fix that removes the most routes to what matters.

AI Security Scan · AWS

Cheap checks free, reasoning where it counts

Deterministic rules do the routine work at no credit cost. The AI reasons only where a rule cannot decide. The credit cost is shown before, during and after the scan.

Vendor Risk

Reads the evidence, not the tick box

Reads the SOC 2 report, ISO certificate, policies and DPA a vendor uploaded and checks every high-stakes questionnaire answer against them, citing the page. Contradictions surface before signature. See third-party risk.

The gate

Where a person sits in the loop

Tools sit in a registry with four risk levels: read-only, low-risk write, high-risk write and destructive. High-risk and destructive tools always require approval. Anything client-facing or critical is forced through a human review gate before it leaves the admin side.

  1. Finding

    A module raises a finding into the Risk Register with its source and severity.

  2. Proposal

    The AI drafts a remediation with the tool it intends to use and the risk level that tool carries.

  3. Approval

    A named person on your side approves or rejects in the Approvals queue. The decision is recorded with who and when.

  4. Execution

    Only the allow-listed tool runs, only after approval. There is no raw shell execution anywhere in the platform.

  5. Verification

    The change is re-checked before the finding closes. A control is reported as verified only when it has been checked, not when it has been configured.

Configured and verified are different words. The platform says a control is verified only when it has looked. A fix that was approved and run but not yet re-checked stays open.

Grounding

Every statement carries its source

A closure report cites the log lines it used. A vendor cross-check cites the page of the document it read. AI outputs carry a confidence and the evidence behind them, so a reviewer can open the source rather than take the summary on trust.

When the AI could not finish reading, it says so. A truncated or unfinished read is reported as unfinished, never as a pass.

Case closure
Report drafted with citations to the specific log lines. Signed by an analyst before it leaves the admin side.
Vendor evidence
High-stakes answers checked against the uploaded SOC 2 report, ISO certificate, policies and DPA, with the page cited. The vendor's own words are kept so they can be contradicted later.
Drift
When a vendor resubmits, the new answers are compared with the old ones and the differences are named.
Unfinished reads
A read the model did not complete is marked unfinished. It is never rounded up to a pass.
Guardrails

Controls enforced in code, not in a policy document

Each of these is a control the platform applies to every AI job.

  • Tenancy

    One tenant per job

    Every AI job is scoped to a single tenant and the tenant id is asserted at the boundary before the job runs.

  • Isolation

    Cross-tenant output rejected

    Output that references another client is rejected before it is stored or shown.

  • Secrets

    No secrets in prompts

    Content is redacted before it reaches the model.

  • Injection

    Prompt-injection markers neutralised

    Markers in ingested content are neutralised and counted, so the count can be read by a person.

  • Tools

    A registry with four risk levels

    Read-only, low-risk write, high-risk write, destructive. High-risk and destructive tools always require approval.

  • Allow-lists

    Explicit tool allow-lists per agent

    An agent can call only the tools it is listed for. There is no raw shell execution.

  • Audit

    Every step audited

    Every proposal, decision, tool call and outcome is written to a hash-chained, tamper-evident log.

  • Cost

    Tokens and cost per job

    Per-job token use and cost are logged. For the AWS scan the credit cost is shown before, during and after.

  • Resilience

    A fallback model for every workflow

    Every workflow has a defined fallback model.

  • Evidence

    Confidence and evidence on every output

    AI outputs carry a confidence and the evidence they rest on.

Audit trail

A record an auditor can check without us

The audit log is hash-chained: each entry commits to the one before it, so an edited or missing entry breaks the chain. Case evidence sits in an evidence locker with chain of custody. Audit packs from the AI control plane are signed with Ed25519 and can be verified with a standalone verifier that runs outside the platform.

Region
Data is processed in AWS London (eu-west-2), except by the processors named in the privacy policy.
Models
Frontier models from Anthropic (Claude), called through Penthropic's own guardrailed client. Anthropic is disclosed as a processor in the privacy policy.
Tenant scope
One tenant per job, asserted at the boundary. Output that references another client is rejected.
Log integrity
Hash-chained entries. Per-job tokens and cost recorded alongside the decision.
Your own AI use

An AI control plane for the AI your people already run

The same platform inventories and governs AI use inside your business. The endpoint agent already collects installed software, browser extensions and listening ports, so a local model server, an AI command line tool or an AI browser extension shows up in the inventory without a separate deployment. A discovered item is marked discovered, not registered, until a person confirms it.

  • Inventory

    AI inventory from telemetry

    Registered AI assets alongside items discovered on endpoints: local model servers, AI CLIs, browser extensions.

  • Shadow AI

    Shadow-AI detection

    AI tools nobody registered, surfaced from the same endpoint telemetry as Shadow IT.

  • Policy

    Usage policies with exceptions

    AI usage policies with exceptions and approvals, and control evidence recorded against each.

  • Frameworks

    Evidence packs mapped to four frameworks

    NIST AI RMF, ISO/IEC 42001, the EU AI Act and the OWASP LLM Top 10.

  • Signed packs

    Ed25519 signed audit packs

    An auditor verifies a pack with a standalone verifier outside the platform.

  • Vendors

    AI vendor risk

    An AI tool promoted from the inventory lands in the vendor register as an AI vendor, with its provenance.

LLM Security Audit

Attacks your LLM application the way an attacker would

On a schedule, against the target you register, with the results diffed against a pinned baseline so a regression is a named change rather than a new score.

25test cases in the suite
9 of 10OWASP LLM Top 10 categories covered. LLM05, supply chain, is not tested.
11of the 25 cases run inside your network in the appliance variant

A grade never ships alone

The per-case verdicts always travel with the grade. A number without the cases behind it is not published.

Captured responses are redacted

A redactor removes secrets from the responses the suite captures before they are stored.

A CI gate

Run the suite in your pipeline and fail the build on a regression against the pinned baseline.

Ask Annabel

A named analyst in the portal Early access

Annabel reads your tenant's own programme state and answers with the source line for every statement, or says what she could not read. Any change you ask for is staged for your explicit confirmation. She proposes; she never acts.

Annabel is in early access and is not available to every client yet. She is not a vCISO. The fractional vCISO is a human service on the advisory side.

Reads
Your own programme state: the register, the score, the actions, the evidence.
Answers
With the source line for each statement, or a plain statement of what she could not read.
Changes
Staged for explicit confirmation. Nothing is applied on her own authority.
Availability
Early access. Ask whether your tenant is included.

See what the AI would propose for your estate

Thirty minutes on what the AI would propose for your estate, and who on your side would approve it.

Book a call