We started Sentaro with one conviction: security tooling had quietly made employees the last line of defense, and that's a design flaw, not a training problem. An immune system doesn't ask cells to spot pathogens. It handles them.
If a person has to catch it, the system already failed. We design so the engine decides first.
Jurisdiction is architecture. Our models, weights and inference live under EU law, full stop.
We ship vectors when they work on live traffic. Roadmaps are commitments, not marketing.
Started from a simple question: why does every breach post-mortem end with “an employee clicked”?
First paying customers in regulated Nordic SMEs. Scoring before interaction, in production.
Every app and OAuth grant in the tenant, revoked via the Workspace and 365 admin SDKs. The engine starts acting, not just flagging.
DORA and NIS2 pull regulated mid-market firms toward sovereign threat defense, and the buying conversation moves from IT to the board.
The full immune system: four vectors, one engine, every signal.
DORA, NIS2 and the AI Act didn't create the problem. They named it. If your threat defense runs on someone else's cloud, under someone else's jurisdiction, it's someone else's call when it matters. Our models are trained, hosted and governed inside the EU. That's not a deployment option. It's the company.
SOC 2 and ISO 27001 are in progress. We'll say so the day they're signed, and not before. The evidence pack is available on request in the meantime.
We hire slowly and deliberately, across the Nordics and remote-EU.