Try Hanzo
Solutions · Industries

Hanzo for cybersecurity

Put agents on the queue — the triage, the investigation, the fix — on a platform whose own controls are written down mechanism by mechanism, with every agent action in the audit trail.

What it does for you

Triage with the evidence attached
An agent reads the alert, pulls the related traces and logs, and writes up what happened with a link to every line it relied on. The analyst decides; the agent gathers.
From advisory to pull request
Hand a bot the CVE and the repository. It finds the affected code, makes the change, runs the tests and opens a pull request for review.
Reproduce it somewhere else
Run a proof of concept or open a suspicious file in a leased sandbox, a separate computer for the organization, and read the exit code, stdout and stderr back.
Guard the model boundary
Guard reads prompts on the way in for injection and pasted secrets, and replies on the way out for leaks — as a proxy, a CLI wrapper or a filter in front of an MCP server.
Identity your review can press on
PKCE with S256 only, argon2id password hashes, single-use refresh tokens that revoke their whole family on replay, and SCIM from your directory.

Security and compliance

Controls you can read
The trust page describes each mechanism as the code implements it: sign-in, token verification, tenancy, the audit trail and key custody — including what is not built yet.
Frameworks
Our controls are built to be compatible with SOC 2 and audited internally, continually. The audit report is available on request.
Or keep it inside
The platform is open source and runs in your cloud, on your own hardware, or air-gapped, with Zen weights served on machines you control. Then nothing reaches us.

Put it to work

Start in the builder today, or talk to us about your organization.