Written up before anyone opens it
Triage runs as the alert lands. The platform reconstructs the timeline, pulls the entities, gathers the evidence and drafts the closure report, citing the log lines it used. Your analysts approve and sign.
See the fleet view in a sandbox tenant of your own?
Book a platform tourFor MSSPs and security firms
Every client runs the same platform in their own tenant. The AI takes the routine analyst pass in all of them at the same time. It triages the alert, builds the case, reads the vendor evidence, and drafts the write-up with citations to the log lines it used.
Your people do the part only your people can do. They judge it, they approve it, and their name goes on it. Your brand is on the front of all of it.
White-label to your brand One tenant per AI job Onboard a client in days
The margin problem
The routine work is the same in every tenant. Read the alert, pull the entities, check what the evidence actually says, write it up so somebody else can follow it. Twenty clients means twenty of those, every day, and on most platforms the only lever you have is hiring.
The AI takes that first pass in every tenant at the same time. Your analysts open a case that is already built.
Triage runs as the alert lands. The platform reconstructs the timeline, pulls the entities, gathers the evidence and drafts the closure report, citing the log lines it used. Your analysts approve and sign.
A daily analyst sweep, an incident analyst, an evidence reviewer and a monthly report, per tenant. Anything client-facing or critical is forced through a human review gate before it leaves the platform.
The SOC 2 report, ISO certificate, policy and DPA a vendor uploads are read, and high-stakes questionnaire answers are cross-checked against them with the page cited. A truncated read is reported as unfinished, never as a pass.
Where your people stay
Nothing reaches a client under your brand until one of your people has read it and said yes. Approval covers the specific action, not the class of action, and the approval is part of the record.
Triage starts on the alert itself. The case is opened in the tenant it belongs to and in no other.
Timeline reconstructed, entities pulled, evidence gathered into a locker with chain of custody, and the draft cites the log lines it used.
The exact change, the system it touches, and what the platform expects to observe afterwards. Written down before anything moves.
A named person on your side approves or declines. High-risk and destructive tools always require it. There is no path that skips this step.
Every proposal, decision, tool call and outcome goes to a hash-chained, tamper-evident audit log, with the token and cost for the job beside it.
Endpoint fixes run through the Penthropic agent, with a verify step after the change. Cloud fixes use an opt-in, write-scoped role the client grants. Neither runs on an approval nobody gave.
The claim you will test hardest
The cockpit is shared. The work is not. The tenant id is asserted at the boundary of every AI job, and output that references another client is rejected.
Your name on the front
Penthropic is the engine underneath. What your client signs into, and what lands in their inbox, is yours.
Your brand, your domain, your palette, your logo. The tenant-facing portal, the email templates and the report PDFs all take your parameters. Nothing says Penthropic to your client unless you decide it should.
The pipeline is productised: sources connected, an evidence baseline run, the policy set seeded, the first board pack generated. How long it takes depends on the client's estate, and we say which it is on the call rather than after.
Built for a fleet, not a tenant
Your clients get the full Penthropic portal under your brand. You get the layer above it: cross-tenant triage, fleet-wide rollouts and per-client commercials, for the book you already run.
One row per tenant, each carrying its own state: what the AI did overnight, what is waiting on an approval, what is overdue. Open a row to drop into that tenant's own cockpit.
Your analyst works alerts across the fleet from a single queue. Each one opens as a case the AI has already written up, in the tenant the alert belongs to and in no other.
Roll a detection pack, a playbook or an evidence request out to every tenant at once. The change is approved per tenant, with rollback per tenant, and every proposal, decision and outcome lands in the audit log.
The view your COO asks for: margin per tenant and per service, expansion signals drawn from product usage, and churn-risk flags before the renewal call rather than after it.
Partner FAQ
Short answers here. The long ones are a conversation, and we would rather have it on a first call.
Your brand, your domain, your palette, your logo. The tenant-facing portal, the email templates and the report PDFs are parameterised rather than re-skinned per partner. Penthropic sits underneath as the engine, and nothing says our name to your client unless you want it to.
Every AI job is scoped to one tenant. The tenant id is asserted at the boundary of the job, and output that references another client is rejected. What crosses tenants is your queue, not the work: each case is opened in the tenant the alert belongs to.
Secrets are redacted before the model sees a prompt, prompt-injection markers in ingested content are neutralised and counted, tools come from a registry with an allow-list written per agent, and every step is written to a hash-chained audit log. Ask to see those checks on the platform tour. We would rather you tested the claim than believed the sentence.
A base platform fee covers the cockpit, the white-label and your first clients. Clients beyond that are priced per seat or per service, with volume tiers. We will model your own client base on the first call rather than quote a margin figure at you here. No exclusivity, and no revenue-share clawback.
Days, not weeks. The onboarding pipeline is productised: signed manifests, source connectors wired, an evidence baseline run and a playbook seed. How long a given client takes depends on the estate and the regulator, so we quote it on a discovery call instead of publishing a number that would be wrong for half of you.
Become a partner
Tell us roughly how many clients you run today, the geographies you cover, and the services you sell. We come back with a margin model built on your numbers and a sandbox tenant of your own.