Our story

Built by people who work the cases.

Pentra comes from practitioners in DFIR, offensive security, purple-teaming and assurance. We built it for the problems we kept running into on real incidents.

Why we started

Most of an investigation is stitching.

An alert names a host. The account behind it is in the identity provider, the process tree is in the EDR, the mail is in another console, and the last time this happened is in a closed ticket nobody remembers. Every analyst rebuilds the same picture by hand, and the picture is gone when the case closes.

Automation was meant to help. What we saw either ran a fixed playbook that broke on the first unusual case, or wrote a confident summary that did not survive the post-incident review. Neither could say "the evidence is not there, a person should look at this."

AI added a second problem. To be useful, an AI assistant needs to reach your EDR, your SIEM and your identity provider. Too often that reach comes from a permanent password tucked into a settings file, with no record of what was done with it.

Pentra answers both. Pentra Graph keeps the picture: identities, assets, evidence, prior cases and decisions, linked in time, with investigations that stop when the evidence is weak. Pentra Omni controls the access: each person and each AI assistant reaches only the tools they are allowed, one case at a time, and every action is recorded.

What we hold to

Rules we build to, and test.

Stop

Stop when the evidence is weak

A system that cannot say it does not know is not ready to close a case. Weak or contradictory evidence goes to a person instead of becoming a confident answer.

People

A person moves trust

Automation gathers evidence and makes suggestions. Changes to your case records and any containment action wait for a person to approve them.

Access

Access for a case, not forever

An AI assistant gets only the tools one investigation needs, for a limited time, with a second person's sign-off by default. No permanent keys.

Boundary

Your data stays yours

Each customer gets its own Omni, with its own data and its own encryption key. Your logs, credentials and cases are not used to train models for anyone else.

Trail

Every decision shows its work

The questions asked, the evidence reviewed and the reason for the verdict are kept with the case, so another analyst or an auditor can follow the same path.

Proof

We break our own controls

We deliberately break our own security controls to prove our tests catch it, and we keep the results as proof.

Who we are

Practitioners who still do the work.

We have worked in assurance and governance, offensive security, purple-teaming, and DFIR across enterprise, cloud, and industrial environments.

Assurance

Governance that ships

Program design, control selection, and executive-ready risk language, grounded in long-term advisory work.

Offense & purple

Attacker-literate defense

Manual testing and collaborative purple-team engagements make adversary paths visible, then turn those findings into better investigation practice.

DFIR & MDR craft

Response under pressure

Forensics, hunting, containment, and operator workflows from teams that have handled incidents and detection programs in enterprise and industrial environments, including specialized OT and ICS contexts.

Talk to us

If this is the problem you have, we would like to hear about it.

Tell us how your team investigates today and where the time goes. We read every message.

Go to contact form