Penthropic Security

See the platform in your tenant?

Book a Discovery Call

Platform and Managed Operations

One AI layer runs the programme.
You approve the change.

Detection, investigation, the estate, the cloud, identity, email, your people and your vendors run in one tenant. The AI triages what arrives, investigates it, checks what it is told against what is actually exposed, and drafts the fix. Nothing runs against your estate until a person you name approves it, and every step is written to a hash-chained, tamper-evident log.

Platform · one finding, end to endIllustration
signalAn alert arrives from a connected source
triageTriaged on arrival, scored, written to the Risk Register
caseTimeline reconstructed, entities pulled, evidence gathered
proposeRemediation drafted, with the tool it intends to use
approve Held for a named approver in the Approvals queue
executeOnly the allow-listed tool runs, and only after approval
verifyRe-checked before the finding closes
recordProposal, decision, tool call and outcome appended to the chain
The shape of a real run. The content is illustrative, not a client record.
Tenant-isolated, outbound-only 13 capabilities, one tenant From £499/mo

Built for

Fintech SaaS Media and broadcast PE-backed firms Financial services Professional services

Inside the portal

Everything the AI finds lands in the same five places.

There is one register, one score and one ranked action list, not a dashboard per tool. Every capability on this page writes to them, and so does every vendor you assess.

13 capabilities feeding one tenant
1 register, score and action list
0 changes the AI makes on its own
Security Score

One number the board can track

A live score across every module. It moves when a control is verified, not when one is configured, so a fix that ran but has not been re-checked does not move it.

Risk Register

Every finding, one register

Findings from detection, the estate, the cloud, identity, email and your vendors, each with a severity, a named owner, the date it was raised and the date it was last verified.

Top actions · Autopilot

Ranked, with the fix already drafted

The AI ranks what to do next and drafts the remediation. Autopilot proposes; it never acts. You approve or decline in the Approvals queue, one change at a time.

Board Packs

The programme, written up on your cadence

Reporting drafted from the record of what actually ran: what was raised, what was approved, what was verified and what is still open. Not screenshots and spreadsheets.

Evidence Vault

The proof, filed as it goes

For each control: the check that ran, when it ran, what it returned, and the document or probe it came from. Files an auditor can open, with the approval log beside them.

The operating loop

The AI proposes. It does not act on its own.

Tools sit in a registry with four risk levels: read-only, low-risk write, high-risk write and destructive. High-risk and destructive tools always require approval, and anything client-facing or critical is forced through a human review gate before it leaves the admin side.

  1. Finding

    A module raises a finding into the Risk Register with its source, its severity and the control it bears on.

  2. Proposal

    The AI drafts the remediation, the tool it intends to use, and the risk level that tool carries.

  3. Approval

    A named person on your side approves or declines. The decision is recorded with who and when, and it covers this one change.

  4. Execution

    Endpoint fixes run through the Penthropic agent. Cloud fixes use an opt-in, write-scoped role you grant. There is no raw shell execution.

  5. Verification

    The change is re-checked before the finding closes. Configured and verified are different words here.

Guardrails the platform applies to every AI job, enforced in code rather than written in a policy document:

One tenant per job, asserted at the boundary Cross-tenant output rejected Secrets redacted before the model Injection markers neutralised and counted Explicit tool allow-lists per agent No raw shell execution Hash-chained audit log Tokens and cost logged per job A fallback model for every workflow

How the AI works sets out every guardrail, the audit trail and where a person signs.

Four headline capabilities

What the AI operates.

Each one feeds the same register and passes through the same gate. The panels beside them are illustrations of the shape of a run, not client records.

Threat detection · triage traceIllustration
sourcesFalcon detections, CloudTrail, Okta System Log, your own JSON
normaliseOne schema, one timeline, one tenant
correlateCross-rule correlation across sources
triage Triaged on arrival, scored and explained
sweepA daily analyst sweep re-reads the whole day
respondResponse actions proposed, never fired unapproved
registerA scored finding with an owner, not a queue entry
reportA monthly report drafted from the record
The shape of the pipeline. The content is illustrative, not a client feed.
Threat detection · SIEM

Every alert is triaged before anyone opens it.

CrowdStrike Falcon detections, AWS CloudTrail and the Okta System Log land in one feed, with whatever else you push in as JSON beside them. The AI triages each new alert as it arrives, a daily analyst sweep re-reads the day, and a monthly report is drafted from the record. What comes out is a scored finding with an owner, not a queue somebody has to work through.

Built for teams that do not have an analyst on the night shift.

  • RunsTriage on every new alert, a daily sweep, an incident analyst and an evidence reviewer, each on its own schedule.
  • CorrelatesAcross rules and across sources, so one incident is one case rather than nine alerts.
  • RespondsResponse actions are proposed and held in the Approvals queue. Nothing fires at your estate unapproved.
AI investigation · case fileIllustration
  1. AlertDetection arrives and a case is opened against it
  2. EntitiesHosts, identities and addresses pulled from the log lines
  3. TimelineReconstructed from the records, with the gaps named
  4. EvidenceCaptured to the locker with chain of custody
  5. ReportClosure drafted, citing the specific log lines it used
  6. SignedAn analyst reviews, approves and signs it
The shape of a case file. The content is illustrative, not a client incident.
AI investigation · case files

Every alert becomes a case file an analyst signs.

The platform reconstructs the timeline, pulls the entities, gathers the evidence and drafts the closure report with citations to the log lines it used. Your analysts approve and sign. They do not assemble. When the AI could not finish reading, the case says so: a truncated read is reported as unfinished, never rounded up to a pass.

  • GroundedEvery statement in the report carries the log line it rests on, so a reviewer can open the source instead of trusting the summary.
  • CustodyEvidence locker with chain of custody, ready for the lawyer and the insurer.
  • SignedNothing client-facing leaves the admin side without a human review gate.
Estate map · attack pathsIllustration
Endpoint Cloud Identity SaaS Vendors CHOKE POINT Crown jewels
Drawn to show the shape of the graph. Not a client estate.
Estate map · attack paths

The AI reads the map and names the one fix.

Hosts, identities, cloud accounts, SaaS and exposed services drawn as one connected graph, from what the Penthropic endpoint agent collects and what the Sentinel appliance sees inside the network. AI Attack-Path Review reasons over that graph and names the choke-point fix that breaks the most paths to what matters, rather than handing you a list ordered by severity.

  • One graphEndpoint, cloud, identity, SaaS and vendors on the same canvas, so a path that crosses two of them is still one path.
  • One fixAttack-Path Review names the choke point, and says which paths it removes.
  • DriftDiffed against the last map, so a new exposure is a named change and not a new number.
Pentest studio · scoped jobIllustration

Capability packs a scoped job can call

nmap nuclei ZAP semgrep gitleaks trivy checkov shodan

Before any of them touches the estate

Waiting for approval. The job manifest is signed and scoped. The runner stays idle until a named approver releases it.
The shape of a scoped job. The content is illustrative, not a client engagement.
Pentest studio · offensive operations

Offensive testing with a gate on every action.

Scope, signed job manifests, runner pools, the evidence locker and the report bundle, in one workspace. Approval gates sit in front of every action that touches your estate, and the retest that proves the fix is part of the same record. The bundle that comes out is the one you hand to your insurer.

  • ScopedSigned job manifests with a replay store, so what ran and against what is checkable afterwards.
  • GatedApproval gates on every action that reaches the estate, on the same rails as Autopilot.
  • BundledReport bundles for legal and the insurer, with the retest attached to the finding it closes.

What connects

Keep your tools.
Send us what they see.

Nothing here asks you to rip out a product you have already paid for. Three security tools connect and start sending within minutes. For everything else there is one endpoint that takes JSON, so a tool we have never heard of still reaches the same timeline, the same register and the same approval gate.

Polled every five minutes

CrowdStrike Falcon

Detections and alerts into the event store. Connect it once and the host inventory and Spotlight vulnerability data also land in your asset register every hour.

Polled every five minutes

AWS CloudTrail

Management events through a cross-account role you create yourself, so no access key of yours is ever held here. The same account is assessed for S3, IAM, security groups, CloudTrail, GuardDuty and Security Hub.

Polled every five minutes

Okta System Log

Every sign-in and every administrative change, which is the record that answers who did this and when, long before anyone asks you for it.

Everything else you run

One endpoint that takes JSON

Create a connector in the portal. It shows you a token once. Point your tool at the endpoint and it posts JSON over HTTPS, batched or one event at a time, and the events are normalised into the same timeline as the rest.

You are not waiting on a roadmap for a connector to be written. Two things it is not: there is no syslog listener, and there is no file drop.

Out the other side

Into the tools your team already watches

Findings can be raised as Jira issues. Alerts can be delivered to a Slack channel. Both are connected by you, in the portal, and both carry the finding's own reference so the trail back is one click.

Before any of that, we read what the internet can already see about you: DNS records, certificates and email authentication. That is a picture on day one with no credential shared. And where a source is one we do not read yet, it is named as one on the page rather than left off it.

Nine supporting capabilities

The rest of the estate, on the same rails.

Same tenant, same register, same approval gate, same evidence trail as the four above. Each one is a source the AI reads, not a separate product with its own dashboard.

Estate · internal

Sentinel managed appliance

A scanner appliance inside your estate, outbound-only, so it opens no inbound door of its own. It gives the estate graph the internal view an external scan cannot reach, and feeds Attack-Path Review.

Estate · external

Attack surface monitor

Domains, certificates, exposed services, email authentication and shadow IT checked on a cadence. When a control that passed last time fails this time, the finding is raised that day with both results attached.

Incidents

Forensics and DFIR

The workspace for the serious ones: evidence locker with chain of custody, entity and timeline reconstruction, and a report drafted from the record with citations rather than assembled by hand.

Incidents

Incident response centre

Guided intake, live severity and containment tracking, and the closure report. An incident analyst runs on its own schedule, and anything client-facing passes a human review gate first.

Cloud

Cloud security posture

Connect AWS and deterministic rules do the cheap work at no credit cost. The AI reasons only where a rule cannot decide, and the credit cost is shown before, during and after the scan. Fixes use an opt-in, write-scoped role you grant.

Identity

Identity security review

Dormant accounts, missing MFA and risky OAuth grants reviewed on a cadence rather than once a year, with each access review kept as evidence against the control it serves.

Email

Email security centre

SPF, DKIM and DMARC health, sender reputation and domain spoofing, checked continuously rather than at audit time. Your vendors' email posture is checked the same way, from outside.

People

PhishSim and awareness training

Lookalike-domain campaigns that an admin approves before they send, with the awareness training that follows tracked against the campaign, so the programme has a result and not an attendance list.

Privacy

Privacy centre

Records of processing, DPIA and DPA review, and DSAR fulfilment handled in workflow, so the GDPR evidence is a record of what ran rather than a once-a-year scramble.

All of it tenant-isolated, outbound-only where applicable, with the full audit trail. Run as a managed service or alongside your team. Vendors are assessed the same way on the third-party risk side.

Subscriptions

Subscriptions that grow with your security programme.

From-pricing, per tenant, with the guided client portal included in every tier. Start with visibility, add compliance and continuous testing as you scale. Run managed or alongside your team.

Monitor

Know what's exposed

From £499/mo

Automated visibility and Cyber Essentials readiness for smaller companies.

  • Guided client portal
  • Cyber health dashboard
  • Asset inventory
  • External attack-surface monitoring
  • Vulnerability & exposure monitoring
  • Risk register & remediation tracking
  • Cyber Essentials readiness
  • Policy & evidence vault
  • Automated monthly security report
  • Annual advisor call
  • Email support

1 entity · 25 employees · 25 external targets · 5 integrations · 10 vendors

Over 250 employees or multiple entities? See Enterprise.

Start Monitoring
Assure

Continuously test and prove it

From £2,999/mo

For regulated, higher-risk or technically mature clients who need audit-ready assurance.

  • Everything in Manage, plus:
  • Continuous external security testing
  • Web & API security scanning
  • Internal visibility via Sentinel managed appliance
  • Controlled vulnerability validation
  • Pentest Studio engagements and retests
  • Attack-path analysis
  • Detection validation
  • Executive testing trends
  • Quarterly human-led validation session
  • Priority support
  • 4-hour critical response, business hours

1 entity · 150 employees · 250 external targets · 25 integrations · 50 vendors

Over 250 employees or multiple entities? See Enterprise.

Scope Assure
Enterprise

For larger organisations and MSPs

Custom

For organisations above ~250 employees, multi-entity groups, and MSP/MSSP partners needing volume tiers.

  • Everything in Assure, plus:
  • Volume-banded per-employee pricing
  • Multi-entity & group structures
  • Scoped SIEM / log ingestion
  • Dedicated onboarding
  • Custom SLAs and contractual terms
  • MSP/MSSP partner tiers, MSP partner?
Talk to Us
Add-ons & overages
  • Continuous Testing for Manage +£600/mo
  • Additional entity +£350/mo
  • Additional 25 employees / endpoints from +£200/mo
  • Additional web app / API from +£150/mo
  • Additional 25 vendors +£150/mo
  • Incident-response retainer from £500/mo
  • Manual pentest from £5,000
  • Full fractional CISO from £3,000/mo, advisory

Prices from. 12-month agreement billed monthly. Rolling monthly +15%. 10% off annual prepayment. One-off onboarding from £1,000 depending on tier.

Platform FAQ

The questions buyers always ask first.

Still unsure? Send us a message and you will have a reply within one business day.

Every tenant is hard-partitioned at the storage and indexing layer. There are no cross-tenant queries and no shared indexes. Every AI job is scoped to a single tenant with the tenant id asserted at the boundary, and output that references another client is rejected before it is stored or shown. The MSSP cockpit only ever surfaces metadata across tenants, never raw findings, log lines or evidence. We can walk you through the tenancy boundary before you commit.

The platform runs in eu-west-2 (London). Raw and normalised event storage, backups and audit trails stay in region, except for the processors named in the privacy policy. Content is redacted before it reaches a model. Models are frontier models from Anthropic (Claude), called through Penthropic's own guardrailed client.

It triages every new alert as it arrives, runs a daily analyst sweep, opens and works a case for each incident, reviews evidence, checks your vendors' answers against the documents they uploaded, and drafts a monthly report. It also proposes remediation. It never applies one. Every proposal, decision, tool call and outcome is written to a hash-chained, tamper-evident log, and the per-job token use and cost are recorded alongside the decision.

Detection and AI investigation take roughly 1–2 weeks for connectors and rule-pack tuning. Sentinel is a single appliance image deployed inside your estate, outbound-only, with no inbound port. PhishSim and awareness training take under a week to the first campaign. The Penthropic endpoint agent is optional: it runs on macOS and Windows, is outbound-only, and collects only approved posture data such as installed software, browser extensions, listening ports and patch state. Most signal comes from log sources and cloud APIs you already have.

Three sources connect and are polled every five minutes: CrowdStrike Falcon detections, AWS CloudTrail through a cross-account role you create, and the Okta System Log. Connect CrowdStrike and its host inventory and Spotlight vulnerability data also land in your asset register every hour, and a connected AWS account is assessed for S3, IAM, security groups, CloudTrail, GuardDuty and Security Hub.

Anything else you run pushes events to a token-authenticated endpoint you create yourself, as JSON over HTTPS. That is the answer for a tool we have never heard of, and it means you are not waiting on us to write a connector. We do not accept syslog today, and there is no file drop.

Going the other way, findings can be raised as Jira issues and alerts delivered to a Slack channel. Where a source is one we cannot read yet, we say so by name rather than listing it as supported.

Both. Most clients start managed: we operate the platform, your team has access, and we handle tuning. You can move to self-managed at any point in the same tenant. There is also a split where we operate detection and you operate response. We recommend the shape that fits your team rather than the one that bills most.

Your data is yours. On termination we provide a full export: events, findings, evidence and the audit trail, in JSON, CSV or PDF. After your export is acknowledged, the tenant is destroyed within 30 days and a destruction certificate is issued. No lock-in clauses, no data-egress fees.

No. Advisory engagements stand on their own: fixed-fee assessments, third-party risk design, threat modelling sprints and fractional vCISO. See the advisory page. The platform is there if you want continuous operations after the project, not a condition of working with us.

Get in touch

See it running against your own estate.

Tell us what you are trying to detect, investigate or harden. We will show you that capability working in a sandbox tenant first, and who on your side would hold the approval.

  • hello@penthropic.ai
  • London, United Kingdom. Hosted in eu-west-2.
  • Reply within 1 business day
  • Sandbox-tenant demo before any commitment
  • No lock-in clauses, no egress fees