Platform

One evidence model for web, code, and AI security.

Pentoma is an AI-assisted offensive security company. Web, Code, and AI Red Teaming run as separate engagements with one shared evidence model — agentic discovery, deterministic replay, and human validation.

Products

Three products, one professional evidence layer.

Each product has a distinct target and method, but the output is consistent: confirmed findings, replayable proof, remediation guidance, and compliance mappings.

Distinctions

Clear boundaries make the platform easier to buy and easier to trust.

Pentoma Web, Pentoma Code, and Pentoma AI Red Teaming should never blur into a generic assessment. Each product explains what it tests, how it tests, and what evidence the team receives.

Pentoma Web

Target
Running web applications and APIs
Method
AI-assisted exploration, business-logic probing, deterministic replay, and human validation
Output
Confirmed application findings with request/response proof and compliance mappings

Pentoma Code

Target
Source-code repositories, pull requests, and release branches
Method
Offensive static analysis: vulnerability hunting, source-to-sink reasoning, attack-chain reconstruction, validated by reviewers
Output
Validated vulnerabilities, attack-chain evidence, line-level remediation guidance, and 0-day candidates worth coordinated disclosure

Pentoma AI Red Teaming

Target
LLM endpoints, RAG flows, tools, plugins, and agents
Method
Adversarial prompts, agent-boundary tests, behavior replay, and policy checks
Output
AI risk evidence mapped to OWASP LLM Top 10 and governance controls

Evidence that survives engineering and audit review.

Pentoma connects technical reproduction to control mappings so findings do not lose context when they move from engineering to compliance.

SOC 2

Vulnerability detection, response, and change-management proof.

CC7.1 · CC7.2 · CC8.1

ISO 27001

Technical vulnerability management and risk treatment evidence.

A.8.8 · A.5.36

AI Governance

Evidence for AI risk and governance reviews — adversarial replay, agent-boundary checks, and policy mapping.

Prompt replay · Agent boundary · Policy

Validation model

AI discovers. Evidence validates. Humans sign off.

Pentoma uses AI for speed and breadth, but the customer-facing finding standard is proof: replayable evidence, deterministic checks where possible, and expert human validation before delivery.

Find with AI

Agentic discovery hunts web apps, APIs, source code, and AI systems for exploitable vulnerabilities and attack chains faster than a traditional engagement can start.

Prove with replay

Findings are promoted only when reproducible request/response, source path, or prompt evidence supports them under safe conditions.

Validate with humans

An expert reviewer checks scope, exploitability, severity, and remediation quality before a finding leaves the system.

Deliver as evidence

Every assessment ships with executive summary, engineering detail, remediation, retest status, and compliance mapping.

Workflow surface

Minimum launch workflow for teams that already have tools.

Pentoma should not require customers to live in another dashboard. The launch surface needs exports, status, webhooks, and developer workflow touchpoints.

Findings API

List confirmed findings, severity, evidence status, affected asset, remediation state, and compliance mappings.

Report export API

Export executive, engineering, and compliance-ready reports as HTML, PDF, JSON, or CSV.

Assessment status API

Expose queued, running, validating, paused, cancelled, delivered, and retest lifecycle states.

Signed webhooks

Send HMAC-signed events for assessment.started, finding.confirmed, report.ready, assessment.paused, and assessment.cancelled.

Pentoma Code PR comments

Deliver line-level finding context into GitHub pull requests so remediation happens where engineers already work.

Platform fit

Start with the product that matches your risk surface.

Explore solutions