Evidence over alarm
A finding is useful only when the team can reproduce it, reason about it, and prove the remediation path.
Pentoma is a San Francisco-based, founder-led team that turns AI-assisted offensive security into validated evidence. We test web apps, source code, and AI systems with agentic discovery, deterministic replay, and human validation — then ship reports your engineers can fix and your auditors can trust.
Our story
SEWORKS has spent more than a decade in offensive security across mobile binary protection, application security, and adversarial testing for regulated industries. Pentoma brings that history into a product surface designed for today's engineering reality: web apps, source code, and AI features all ship together, and all of them need evidence.
Pentoma is an AI-assisted offensive security company. The old pen-test rhythm was periodic, document-heavy, and slow. Pentoma is built for the AI era: scoped engagements, controlled agent runs, deterministic replay, expert review, and audit-ready mappings that stay connected to the technical proof. Findings are not accepted because a model said so — they are accepted because a human reviewer signed off.
The voice is deliberate: technical, calm, and evidence-first. No fear theater. No inflated alert counts. Just the finding, the reproduction, the fix path, and the control it supports.
Principles
A finding is useful only when the team can reproduce it, reason about it, and prove the remediation path.
Security software should lower the pulse. Pentoma presents risk clearly without theater, fear, or noise.
We optimize for confirmed issues with context, not dashboards full of low-signal alerts that teams learn to ignore.
Reports should work for engineers, security leads, and auditors without translating between three separate tools.
Leadership
Pentoma is led from inside SEWORKS with a founder-level focus on practical security, engineering fit, and evidence quality.
Founder and CEO
Min has led offensive-security work at SEWORKS for over a decade across mobile, web, API, and application security. Pentoma is the AI-era version of that craft: agentic discovery paired with the human validation that makes a finding actually trustworthy. Direct outreach is welcome.
Connect on LinkedInBacked by
Pentoma is built and operated inside SEWORKS, an offensive-security company founded in 2013 in San Francisco. SEWORKS is backed by strategic venture investors and is a member of the NVIDIA Inception program — the same balance sheet and trust footprint stand behind Pentoma.
Strategic investor
Qualcomm Ventures
Strategic investor
Fast Ventures
Program member
NVIDIA Inception
Investor and program affiliations belong to SEWORKS, the parent company. See the SEWORKS company page.
Strategic advisors
SEWORKS' advisory board brings deep experience across national security, mobile threat intelligence, and enterprise venture — and helps Pentoma stay sharp as the threat landscape and AI-era engineering both evolve.
Former Sr. Intelligence Officer, CIA
Former Director of the CIA for K-Mission Center with Presidential Rank Award recognition for exceptional service to national security.
Founder, ZecOps · Founder & Chairman, Zimperium
Serial cybersecurity entrepreneur. Founded ZecOps and previously Zimperium, leading a generation of mobile security and threat-intelligence innovation.
Founder & Managing Director, Draper Athena
Venture-capital leader and technology investor. Serves on the Board of Trustees and Leadership Board at MIT, driving enterprise-technology innovation.
From SEWORKS
The team ships across the offensive-security stack — mobile hardening, credential leak monitoring, and AI-assisted pen testing — under the SEWORKS brand.
The offensive-security company behind Pentoma — mobile, application, and adversarial testing practice since 2013.
se.worksAdvanced APK and AAB obfuscation that protects mobile apps against reverse engineering and tampering.
appsolid.netContinuous monitoring for leaked credentials across the dark web, paste sites, and threat-actor networks.
leakjar.comMilestones
A decade of offensive-security work, the world’s first AI-powered pen testing service, and the unified Pentoma evidence model — in four dates.
The founding team starts running offensive-security engagements together — building the practitioner depth that later becomes SEWORKS and Pentoma.
SEWORKS is established as a US-based offensive-security company, growing the practice across mobile binary protection, application security, and adversarial testing.
SEWORKS ships Pentoma — the first AI-powered penetration testing solution, built on the proprietary GAMAN® AI engine. Agentic discovery and adversarial testing become a real product, not a research demo.
Read the 2018 launch announcementEight years after the original launch, Pentoma brings web pentesting, source-code analysis, and AI red teaming under one evidence model — agentic discovery, deterministic replay, expert validation, and reports that work for engineers and auditors alike.
Work with us