See the platform in your tenant?
Book a Discovery CallThe Penthropic Platform
One tenant that flags what matters, drives the fix, and files the proof, around the clock. Threat detection, AI investigation, estate mapping and pentest operations, run as a managed service or alongside your team. Nothing changes without your approval.
Inside the portal
Every capability on this page lands in the same five surfaces your team works in every day, one login, one audit trail.
A single score the board can track, moving as risks are found and fixed.
Findings from every module, scored by severity and real-world exploitability.
A ranked to-do list with Autopilot remediation that never acts without your approval.
Board-ready reporting generated from real activity, not screenshots and spreadsheets.
Every action signed and filed, ready for auditors and insurers when they ask.
The platform at work
Signals stream in from across your estate. The platform flags what's real, ranks what matters, and drives each fix through your approval, with the evidence filed as it goes.
Watches every signal and flags what's genuinely a risk, no alert noise.
Builds the case: root cause, blast radius and who's affected.
Safely proves what's exploitable, so you fix what matters first.
Files signed evidence as it goes, ready for auditors and insurers.
Four headline capabilities
Each spotlight below is the same screen your analysts and clients work in every day. The mockups are stylised but the layouts and flows are real.
Suricata, Zeek and Falco unified into one feed, MITRE-tagged, with a feedback loop that tunes false-positive rate week by week. Built for teams without a 24×7 SOC.
Connect a source →The platform reconstructs the timeline, pulls the entities, gathers the evidence, drafts the closure report. Your analysts approve and sign, they don't assemble.
Open a case →Hosts, identities, cloud accounts, SaaS, exposed services, connected and ranked by blast radius. Click any node and the right pentest tool is one click away.
Map your estate →Signed job manifests, runner pools, evidence locker, and audit-ready report, scope to sign-off in one workspace. The same studio your testers use, you can hand to your insurer.
Scope a pentest →Nine supporting capabilities
Everything below shares one identity model, one alert pipeline, and one evidence locker with the four spotlights above.
A scanner appliance inside your estate that finds weaknesses before attackers do, outbound-only, so it opens no doors of its own.
Sees your domains, exposed services, and shadow IT the way an attacker does, and alerts you the moment something new appears.
When it's serious, the investigation workspace holds up: chain-of-custody evidence, entity timelines, and reports your lawyer can use.
When something breaks, a guided intake tells you exactly what to do next, severity, containment, evidence, through to the closure report.
Connect AWS and see the misconfigurations, risky identities, and exposed keys that matter, ranked so you fix the right thing first.
Finds the dormant accounts, missing MFA, and risky OAuth grants that quietly accumulate, then keeps them from coming back.
Keeps criminals from sending email as you: SPF, DKIM and DMARC health, sender reputation, and spoofing alerts, managed for you.
Tests your people with realistic phishing before criminals do, and tracks whether the training actually changes behaviour.
Privacy operations as a running service instead of a once-a-year scramble: RoPA, DPIAs, and DSARs handled in workflow.
All platform services are delivered tenant-isolated, outbound-only where applicable, and with full audit trail. Run them as managed services or alongside your team, your choice.
Subscriptions
From-pricing, excl. VAT, per tenant, with the guided client portal included in every tier. Start with visibility, add compliance and continuous testing as you scale. Run managed or alongside your team.
Automated visibility and Cyber Essentials readiness for smaller companies.
1 entity · 25 employees · 25 external targets · 5 integrations · 10 vendors
Over 250 employees or multiple entities? See Enterprise.
Start MonitoringBuilt around compliance outcomes, a Cyber Essentials Plus / ISO 27001 programme.
1 entity · 75 employees · 100 external targets · 10 integrations · 3 cloud accounts
Over 250 employees or multiple entities? See Enterprise.
Configure & buyFor regulated, higher-risk or technically mature clients who need audit-ready assurance.
1 entity · 150 employees · 250 external targets · 25 integrations · 50 vendors
Over 250 employees or multiple entities? See Enterprise.
Scope AssureFor organisations above ~250 employees, multi-entity groups, and MSP/MSSP partners needing volume tiers.
Prices from, excl. VAT. 12-month agreement billed monthly. Rolling monthly +15%. 10% off annual prepayment. One-off onboarding from £1,000 depending on tier.
Every tenant is hard-partitioned at the storage and indexing layer. There are no cross-tenant queries, no shared indexes, and the platform's MSSP cockpit only ever surfaces metadata across tenants, never raw findings, log lines, or evidence. Sensitive fields are masked at output. We can walk you through the tenancy boundary architecture before you commit.
The platform runs in eu-west-2 (London) by default. All raw and normalised event storage, backups, and audit trails stay in-region. Anything that leaves the region (e.g. AI calls) is routed through controlled vendor endpoints with redaction; we can also run in fully-air-gapped mode for clients with that requirement.
For SIEM + AI Investigation: typically 1–2 weeks for connectors and rule-pack tuning. For Sentinel managed appliance: a single OVA / AMI deployed inside your estate, outbound-only, no inbound port. PhishSim + SAT: under a week for the first campaign. The platform doesn't require an agent on every endpoint, most signal comes from existing log sources and cloud APIs.
The platform ingests from CloudWatch, GuardDuty, CloudTrail, Suricata/Zeek/Falco, GWS, Okta, EntraID, common EDR/XDR products, and any source that can ship JSON or syslog. SOAR actions can fire into Slack, PagerDuty, ServiceNow, and your firewall/WAF via signed webhooks. If you have a source we don't yet ship a connector for, we'll write one, that's part of onboarding, not extra.
Both. Most clients start with managed, we run the platform, your team has access, and we handle tuning and on-call. You can move to self-managed at any point with the same tenant. There's also a hybrid: we operate the detection layer and you operate the response. We'll recommend whichever shape fits your team, we don't push the managed tier to lock revenue.
Your data is yours. On termination we provide a full export, events, findings, evidence, audit trail, in JSON / CSV / PDF as needed. After your export is acknowledged, your tenant is destroyed within 30 days and a cryptographic destruction certificate is issued. No vendor lock-in clauses, no surprise data-egress fees.
No. Advisory engagements (NIST, TPRM, vCISO, threat modelling) stand on their own, see the advisory page. The platform is there if you want continuous operations after the project, not a condition of working with us.
Get in touch
Tell us what you're trying to detect, investigate, or harden, we'll show you the relevant capability working inside a sandbox tenant first, before any commitment.