We don't sell fear. We sell findings.

Pentoma is a San Francisco-based, founder-led team that turns AI-assisted offensive security into validated evidence. We test web apps, source code, and AI systems with agentic discovery, deterministic replay, and human validation — then ship reports your engineers can fix and your auditors can trust.

Our story

Offensive-security heritage, rebuilt for AI-assisted software.

SEWORKS has spent more than a decade in offensive security across mobile binary protection, application security, and adversarial testing for regulated industries. Pentoma brings that history into a product surface designed for today's engineering reality: web apps, source code, and AI features all ship together, and all of them need evidence.

Pentoma is an AI-assisted offensive security company. The old pen-test rhythm was periodic, document-heavy, and slow. Pentoma is built for the AI era: scoped engagements, controlled agent runs, deterministic replay, expert review, and audit-ready mappings that stay connected to the technical proof. Findings are not accepted because a model said so — they are accepted because a human reviewer signed off.

The voice is deliberate: technical, calm, and evidence-first. No fear theater. No inflated alert counts. Just the finding, the reproduction, the fix path, and the control it supports.

Principles

The product has a point of view.

Evidence over alarm

A finding is useful only when the team can reproduce it, reason about it, and prove the remediation path.

Calm over urgency

Security software should lower the pulse. Pentoma presents risk clearly without theater, fear, or noise.

Findings over volume

We optimize for confirmed issues with context, not dashboards full of low-signal alerts that teams learn to ignore.

Clarity over jargon

Reports should work for engineers, security leads, and auditors without translating between three separate tools.

Leadership

Built close to the work.

Pentoma is led from inside SEWORKS with a founder-level focus on practical security, engineering fit, and evidence quality.

MPH

Min Pyo Hong

Founder and CEO

Min has led offensive-security work at SEWORKS for over a decade across mobile, web, API, and application security. Pentoma is the AI-era version of that craft: agentic discovery paired with the human validation that makes a finding actually trustworthy. Direct outreach is welcome.

Connect on LinkedIn

Backed by

Capital and credibility from people who know offensive security.

Pentoma is built and operated inside SEWORKS, an offensive-security company founded in 2013 in San Francisco. SEWORKS is backed by strategic venture investors and is a member of the NVIDIA Inception program — the same balance sheet and trust footprint stand behind Pentoma.

Strategic investor

Qualcomm Ventures

Strategic investor

Fast Ventures

Program member

NVIDIA Inception

Investor and program affiliations belong to SEWORKS, the parent company. See the SEWORKS company page.

Strategic advisors

Industry veterans who guide the work.

SEWORKS' advisory board brings deep experience across national security, mobile threat intelligence, and enterprise venture — and helps Pentoma stay sharp as the threat landscape and AI-era engineering both evolve.

Andrew Kim

Former Sr. Intelligence Officer, CIA

Former Director of the CIA for K-Mission Center with Presidential Rank Award recognition for exceptional service to national security.

Zuk Avraham

Founder, ZecOps · Founder & Chairman, Zimperium

Serial cybersecurity entrepreneur. Founded ZecOps and previously Zimperium, leading a generation of mobile security and threat-intelligence innovation.

Perry Ha

Founder & Managing Director, Draper Athena

Venture-capital leader and technology investor. Serves on the Board of Trustees and Leadership Board at MIT, driving enterprise-technology innovation.

From SEWORKS

Pentoma is one of three SEWORKS products.

The team ships across the offensive-security stack — mobile hardening, credential leak monitoring, and AI-assisted pen testing — under the SEWORKS brand.

Milestones

From offensive-security practice to continuous evidence.

A decade of offensive-security work, the world’s first AI-powered pen testing service, and the unified Pentoma evidence model — in four dates.

  1. 2013

    Offensive-security work begins

    The founding team starts running offensive-security engagements together — building the practitioner depth that later becomes SEWORKS and Pentoma.

  2. 2015

    SEWORKS launches in San Francisco

    SEWORKS is established as a US-based offensive-security company, growing the practice across mobile binary protection, application security, and adversarial testing.

  3. 2018

    World's first AI-assisted pen-testing service

    SEWORKS ships Pentoma — the first AI-powered penetration testing solution, built on the proprietary GAMAN® AI engine. Agentic discovery and adversarial testing become a real product, not a research demo.

    Read the 2018 launch announcement
  4. 2026

    Pentoma unifies Web, Code, and AI Red Teaming

    Eight years after the original launch, Pentoma brings web pentesting, source-code analysis, and AI red teaming under one evidence model — agentic discovery, deterministic replay, expert validation, and reports that work for engineers and auditors alike.

Work with us

Help build security software that teams actually want to use.