Penthropic Security

See the platform in your tenant?

Book a Discovery Call

The Penthropic Platform

The portal that keeps working
when the consultant goes home.

One tenant that flags what matters, drives the fix, and files the proof, around the clock. Threat detection, AI investigation, estate mapping and pentest operations, run as a managed service or alongside your team. Nothing changes without your approval.

Tenant-isolated, outbound-only 13 capabilities, one tenant From £750/mo

Inside the portal

Flag it. Fix it. Prove it.

Every capability on this page lands in the same five surfaces your team works in every day, one login, one audit trail.

Security Score

One number, live

A single score the board can track, moving as risks are found and fixed.

Risk Register

Every risk, one register

Findings from every module, scored by severity and real-world exploitability.

Top Actions · Autopilot

Fixes, not data dumps

A ranked to-do list with Autopilot remediation that never acts without your approval.

Board Packs

The story, ready to present

Board-ready reporting generated from real activity, not screenshots and spreadsheets.

Evidence Vault

Proof on demand

Every action signed and filed, ready for auditors and insurers when they ask.

The platform at work

From signal to fix, live.

Signals stream in from across your estate. The platform flags what's real, ranks what matters, and drives each fix through your approval, with the evidence filed as it goes.

Signals in
  • Cloud & SaaS
  • Identity
  • Endpoints
  • Edge & network
  • Email
  • Code & CI/CD
Your whole estate, streaming in continuously.
Penthropic Platform · One tenant
  1. Detects

    Watches every signal and flags what's genuinely a risk, no alert noise.

  2. Investigates

    Builds the case: root cause, blast radius and who's affected.

  3. Tests

    Safely proves what's exploitable, so you fix what matters first.

  4. Proves

    Files signed evidence as it goes, ready for auditors and insurers.

Actions out
Top actions Prioritised
  • Contain compromised host
  • Rotate leaked credential
  • Retest patched service
Case file opened · Evidence Vault updated
One tenant. Thirteen capabilities. From your sources to your board, end-to-end.

Built for

Fintech SaaS Media & Broadcast PE-backed firms Financial Services Professional Services

Four headline capabilities

Premium tools, plumbed together
not a list of features.

Each spotlight below is the same screen your analysts and clients work in every day. The mockups are stylised but the layouts and flows are real.

Threat Detection · pipeline
Suricata Zeek Falco CloudWatch GuardDuty SOURCES Ingest 15+ sources Correlate cross-rule + sigma Triage MITRE-tagged Auto-respond signed rollback MITRE ATT&CK COVERAGE 94% One feed. MITRE-tagged. Tuned by feedback loop.
Threat Detection · IDS & SIEM
codename Argus

See threats as they form,
not after the post-mortem.

Suricata, Zeek and Falco unified into one feed, MITRE-tagged, with a feedback loop that tunes false-positive rate week by week. Built for teams without a 24×7 SOC.

  • 15+ sources · MITRE ATT&CK Coverage tab
  • Cross-rule correlation engine + sigma → falco / zeek
  • SOAR auto-response with rollback & signed manifests
Connect a source →
AI Investigation · case timeline
Alert First probe AI summary cited to log lines Timeline reconstructed Entities people · keys · IPs Evidence locker signed Audit-grade report CASE OUTPUTS First probe detected on edge-vpn Burst detected 42 attempts · 11 IPs Auto-block fired signed manifest Credentials rotated 2 OAuth revoked Generate report → Court-ready · KID-signed Analyst approves and signs, they don't assemble.
AI Investigation · Case Files
codename Sleuth

Every alert becomes a case
in seconds, not hours.

The platform reconstructs the timeline, pulls the entities, gathers the evidence, drafts the closure report. Your analysts approve and sign, they don't assemble.

  • Auto-grounded AI summary with citations to log lines
  • Evidence locker with chain-of-custody & KID-aware signing
  • Court-ready report generation, ready for legal & insurer
Open a case →
Estate Map · blast-radius graph
HUB aws gws okta SCIM SSO edge-vpn vendor A vendor B repo CI/CD CLOUD IDENTITY EDGE VENDORS CODE edge-vpn · TIER-1 Blast radius 18 hosts CVEs (open) 3 Last pentest 14 days Run pentest tool Open AI assist Generate report Cross-source. Ranked by blast radius. Diff week over week.
Estate Map · Topology
codename Atlas

Your whole estate,
one connected graph.

Hosts, identities, cloud accounts, SaaS, exposed services, connected and ranked by blast radius. Click any node and the right pentest tool is one click away.

  • Cross-source map: AWS, GWS, Okta, edge, vendors, code
  • One-click nmap, nuclei, shodan, ZAP, semgrep per node
  • Drift diff week over week, never miss a new exposure
Map your estate →
Pentest Studio · scope to sign-off
SCOPE RUN SIGN-OFF Acme Web App Drafting Bambora Cloud Awaiting approval Helio Internal runner pool 3 / 8 Running Northwind ASM Running Acme Q1 retest Audit-ready manifest signed Helio external Signed off insurer pack sent Signed manifests, runner pools, evidence locker. One workspace.
Pentest Studio · Offensive Ops
codename Foundry

Offensive testing, run like
a real engineering pipeline.

Signed job manifests, runner pools, evidence locker, and audit-ready report, scope to sign-off in one workspace. The same studio your testers use, you can hand to your insurer.

  • 8 runner types · 12 capability packs · gitleaks/trivy/checkov live
  • KID-aware manifest rotation · replay store · detached signing
  • Audit-grade report bundles ready for legal & insurer
Scope a pentest →

Nine supporting capabilities

The rest of the platform.
Same tenant, same audit trail.

Everything below shares one identity model, one alert pipeline, and one evidence locker with the four spotlights above.

Sentinel

Sentinel Managed Appliance

A scanner appliance inside your estate that finds weaknesses before attackers do, outbound-only, so it opens no doors of its own.

  • Continuous internal & perimeter scanning
  • Outbound-only, no inbound exposure
  • Approval gates on every action
Deploy a Sentinel →
ASM

Attack Surface Monitor

Sees your domains, exposed services, and shadow IT the way an attacker does, and alerts you the moment something new appears.

  • External asset & exposed-service discovery
  • Shadow-IT & subdomain monitoring
  • Drift alerts on new exposures
Map your surface →
DFIR

Forensics & DFIR

When it's serious, the investigation workspace holds up: chain-of-custody evidence, entity timelines, and reports your lawyer can use.

  • Evidence locker with chain-of-custody
  • Entity & timeline reconstruction
  • Court-ready report generation
Open a case →
IR Centre

Incident Response Centre

When something breaks, a guided intake tells you exactly what to do next, severity, containment, evidence, through to the closure report.

  • Guided incident intake
  • Live severity & containment tracking
  • Closure & lessons-learned report
Activate IR →
Cloud Posture

Cloud Security Posture

Connect AWS and see the misconfigurations, risky identities, and exposed keys that matter, ranked so you fix the right thing first.

  • AWS connector & account discovery
  • Posture & misconfiguration findings
  • Cloud identity & key analysis
Connect AWS →
Identity

Identity Security Review

Finds the dormant accounts, missing MFA, and risky OAuth grants that quietly accumulate, then keeps them from coming back.

  • MFA & admin coverage scoring
  • Dormant account & OAuth grant review
  • Periodic access reviews
Review identities →
Email

Email Security Centre

Keeps criminals from sending email as you: SPF, DKIM and DMARC health, sender reputation, and spoofing alerts, managed for you.

  • SPF / DKIM / DMARC health
  • Blocklist & allowlist management
  • Domain spoofing alerts
Harden email →
PhishSim & SAT

PhishSim + Awareness Training

Tests your people with realistic phishing before criminals do, and tracks whether the training actually changes behaviour.

  • Lookalike-domain campaigns
  • Approved, effectiveness-tracked templates
  • Pass-rate & behaviour metrics
Run a campaign →
Privacy

Privacy Centre

Privacy operations as a running service instead of a once-a-year scramble: RoPA, DPIAs, and DSARs handled in workflow.

  • Records of Processing (RoPA)
  • DPIA & DPA review
  • DSAR fulfilment workflow
Operate privacy →

All platform services are delivered tenant-isolated, outbound-only where applicable, and with full audit trail. Run them as managed services or alongside your team, your choice.

Subscriptions

Subscriptions that grow
with your security programme.

From-pricing, excl. VAT, per tenant, with the guided client portal included in every tier. Start with visibility, add compliance and continuous testing as you scale. Run managed or alongside your team.

Monitor

Know what's exposed

From £499/mo

Automated visibility and Cyber Essentials readiness for smaller companies.

  • Guided client portal
  • Cyber health dashboard
  • Asset inventory
  • External attack-surface monitoring
  • Vulnerability & exposure monitoring
  • Risk register & remediation tracking
  • Cyber Essentials readiness
  • Policy & evidence vault
  • Automated monthly security report
  • Annual advisor call
  • Email support

1 entity · 25 employees · 25 external targets · 5 integrations · 10 vendors

Over 250 employees or multiple entities? See Enterprise.

Start Monitoring
Assure

Continuously test and prove it

From £2,999/mo

For regulated, higher-risk or technically mature clients who need audit-ready assurance.

  • Everything in Manage, plus:
  • Continuous external security testing
  • Web & API security scanning
  • Internal visibility via Sentinel managed appliance
  • Controlled vulnerability validation
  • Pentest Studio engagements and retests
  • Attack-path analysis
  • Detection validation
  • Executive testing trends
  • Quarterly human-led validation session
  • Priority support
  • 4-hour critical response, business hours

1 entity · 150 employees · 250 external targets · 25 integrations · 50 vendors

Over 250 employees or multiple entities? See Enterprise.

Scope Assure
Enterprise

For larger organisations and MSPs

Custom

For organisations above ~250 employees, multi-entity groups, and MSP/MSSP partners needing volume tiers.

  • Everything in Assure, plus:
  • Volume-banded per-employee pricing
  • Multi-entity & group structures
  • Scoped SIEM / log ingestion
  • Dedicated onboarding
  • Custom SLAs and contractual terms
  • MSP/MSSP partner tiers, MSP partner?
Talk to Us
Add-ons & overages
  • Continuous Testing for Manage +£600/mo
  • Additional entity +£350/mo
  • Additional 25 employees / endpoints from +£200/mo
  • Additional web app / API from +£150/mo
  • Additional 25 vendors +£150/mo
  • Incident-response retainer from £500/mo
  • Manual pentest from £5,000
  • Full fractional CISO from £3,000/mo, advisory

Prices from, excl. VAT. 12-month agreement billed monthly. Rolling monthly +15%. 10% off annual prepayment. One-off onboarding from £1,000 depending on tier.

Platform FAQ

The questions buyers
always ask first.

Still unsure? Drop us a message, we reply fast.

Every tenant is hard-partitioned at the storage and indexing layer. There are no cross-tenant queries, no shared indexes, and the platform's MSSP cockpit only ever surfaces metadata across tenants, never raw findings, log lines, or evidence. Sensitive fields are masked at output. We can walk you through the tenancy boundary architecture before you commit.

The platform runs in eu-west-2 (London) by default. All raw and normalised event storage, backups, and audit trails stay in-region. Anything that leaves the region (e.g. AI calls) is routed through controlled vendor endpoints with redaction; we can also run in fully-air-gapped mode for clients with that requirement.

For SIEM + AI Investigation: typically 1–2 weeks for connectors and rule-pack tuning. For Sentinel managed appliance: a single OVA / AMI deployed inside your estate, outbound-only, no inbound port. PhishSim + SAT: under a week for the first campaign. The platform doesn't require an agent on every endpoint, most signal comes from existing log sources and cloud APIs.

The platform ingests from CloudWatch, GuardDuty, CloudTrail, Suricata/Zeek/Falco, GWS, Okta, EntraID, common EDR/XDR products, and any source that can ship JSON or syslog. SOAR actions can fire into Slack, PagerDuty, ServiceNow, and your firewall/WAF via signed webhooks. If you have a source we don't yet ship a connector for, we'll write one, that's part of onboarding, not extra.

Both. Most clients start with managed, we run the platform, your team has access, and we handle tuning and on-call. You can move to self-managed at any point with the same tenant. There's also a hybrid: we operate the detection layer and you operate the response. We'll recommend whichever shape fits your team, we don't push the managed tier to lock revenue.

Your data is yours. On termination we provide a full export, events, findings, evidence, audit trail, in JSON / CSV / PDF as needed. After your export is acknowledged, your tenant is destroyed within 30 days and a cryptographic destruction certificate is issued. No vendor lock-in clauses, no surprise data-egress fees.

No. Advisory engagements (NIST, TPRM, vCISO, threat modelling) stand on their own, see the advisory page. The platform is there if you want continuous operations after the project, not a condition of working with us.

Get in touch

Want to see the platform
in your tenant?

Tell us what you're trying to detect, investigate, or harden, we'll show you the relevant capability working inside a sandbox tenant first, before any commitment.

hello@penthropic.ai
London, United Kingdom · eu-west-2
We reply within one business day
Sandbox-tenant demo before any commitment
No vendor lock-in clauses, no egress fees