Stop when the evidence is weak
A system that cannot say it does not know is not ready to close a case. Weak or contradictory evidence goes to a person instead of becoming a confident answer.
Our story
Pentra comes from practitioners in DFIR, offensive security, purple-teaming and assurance. We built it for the problems we kept running into on real incidents.
Why we started
An alert names a host. The account behind it is in the identity provider, the process tree is in the EDR, the mail is in another console, and the last time this happened is in a closed ticket nobody remembers. Every analyst rebuilds the same picture by hand, and the picture is gone when the case closes.
Automation was meant to help. What we saw either ran a fixed playbook that broke on the first unusual case, or wrote a confident summary that did not survive the post-incident review. Neither could say "the evidence is not there, a person should look at this."
AI added a second problem. To be useful, an AI assistant needs to reach your EDR, your SIEM and your identity provider. Too often that reach comes from a permanent password tucked into a settings file, with no record of what was done with it.
Pentra answers both. Pentra Graph keeps the picture: identities, assets, evidence, prior cases and decisions, linked in time, with investigations that stop when the evidence is weak. Pentra Omni controls the access: each person and each AI assistant reaches only the tools they are allowed, one case at a time, and every action is recorded.
What we hold to
A system that cannot say it does not know is not ready to close a case. Weak or contradictory evidence goes to a person instead of becoming a confident answer.
Automation gathers evidence and makes suggestions. Changes to your case records and any containment action wait for a person to approve them.
An AI assistant gets only the tools one investigation needs, for a limited time, with a second person's sign-off by default. No permanent keys.
Each customer gets its own Omni, with its own data and its own encryption key. Your logs, credentials and cases are not used to train models for anyone else.
The questions asked, the evidence reviewed and the reason for the verdict are kept with the case, so another analyst or an auditor can follow the same path.
We deliberately break our own security controls to prove our tests catch it, and we keep the results as proof.
Who we are
We have worked in assurance and governance, offensive security, purple-teaming, and DFIR across enterprise, cloud, and industrial environments.
Program design, control selection, and executive-ready risk language, grounded in long-term advisory work.
Manual testing and collaborative purple-team engagements make adversary paths visible, then turn those findings into better investigation practice.
Forensics, hunting, containment, and operator workflows from teams that have handled incidents and detection programs in enterprise and industrial environments, including specialized OT and ICS contexts.
Talk to us
Tell us how your team investigates today and where the time goes. We read every message.