Evidence

What we verified, and what changed

Every engagement write-up follows the same five headings, so you can compare them against each other and against anyone else's. Each one carries at least one number. Where a client has not agreed to be named, the sector and the shape of the business are given instead.

The structure

Case studies are easy to write badly. The usual version asserts a transformation, names no number, and cannot be checked. These use a fixed structure so that a reader can see exactly what was claimed and exactly what was measured.

The situation
The business, the regulatory pressure it was under, and what prompted the work.
What was verified
The specific controls, vendors or systems examined, and the sources used.
What was found
The gap between what was attested and what was actually exposed.
What changed
The remediation, who did it, and how the fix was confirmed.
Over what period
Start and end dates, and whether monitoring continued afterwards.

Published engagements

Client engagements are published only with written permission, and the detail is agreed with the client before it appears here.

Why these are empty. Penthropic will not publish a client name, a quote or an outcome that the client has not signed off, and will not invent one to fill a page. Three engagements are drafted and waiting on approval. In the meantime the demonstration below is a complete worked example you can check yourself, line by line.

A worked demonstration, in the meantime

Rather than describe the method, here it is applied end to end. The target is Penthropic's own domain, the sources are entirely public, and the findings are real, including the ones that are unflattering.

Read the demonstration

Want this run against your vendors?

A vendor verification engagement starts with the same passive sources, then adds the attestations your vendors have given you and looks for the gap.

Book a 30 minute call