Continuous offensive security without giving up control.

Control what Antigen runs on, the policies it follows, who can access it, how every action is audited, and how long your data is retained.

Book a demo

Meet the governance requirements your organization needs

Antigen connects to your identity provider, logs every action to your SIEM, provides fine-grained control over data retention, and ships with the documents your audit team needs.

A policy lattice illustrates explicit testing boundaries above approved production systems.

Identity and access

Connect Antigen to Okta, Entra ID, or Google Workspace with SAML 2.0 or OIDC. SCIM keeps users in sync, while role-based access controls who can view findings, manage policy, or start a run.

Data retention controls

Only retain the data Antigen needs to run your pentests. Choose how long it is kept, or purge it on demand.

Audit trail

Every run, finding, login, policy change, and data access can be recorded and streamed to Splunk, Datadog, Elastic, Sentinel, or Panther.

Procurement and compliance

Antigen is HIPAA compliant, with a SOC 2 Type II audit underway. Request an MSA, DPA, security questionnaire response, or certificate of insurance for your review.

Choose where Antigen runs.

Use Antigen as a managed service or run the entire stack inside your own infrastructure.

Managed

Use Antigen as a managed SaaS with the same enterprise controls and integrations available in a Dedicated deployment.

  • Isolated infrastructure managed by Antigen
  • SSO, audit logs, API, SDK, and integrations included
  • Customer-defined testing and retention policies
  • Fastest path to production

Dedicated (on-premises)

Run the entire Antigen stack inside infrastructure you control so no testing data leaves your network boundary.

  • Frontend, control plane, and workers run in your environment
  • Delivered as a Helm chart or container image
  • Dashboard, findings, logs, and artifacts stay on your systems
  • Operates entirely within your private network

Build your security program on the Antigen API.

Trigger pentests, automate security workflows, and build internal tools with the API and SDK. Authenticate with an API key or an access token.

CI/CD pipelines

Start a pentest before or after a release from the pipeline you already run.

Software factories

Connect Antigen to your existing software factory so remediation uses its codebase context and produces the PR quality your team already trusts.

Internal observability

Bring run status, findings, and audit events into internal security tools.

API key authentication

Use scoped API keys for machine-to-machine workflows and automation.

Access token authentication

Connect Antigen to your existing identity provider so employee access follows the roles and permissions you already manage.

Custom frontends

Build an Antigen interface in Slack, Retool, or the internal dashboard your team already uses.

Control every run, user, and artifact.

Connect Antigen to the identity, policy, data, and audit systems your organization already uses.

SSO and SCIM

Connect SAML 2.0 or OIDC through Okta, Entra ID, or Google Workspace. SCIM provisions access from your employee directory and removes it when someone leaves.

Audit logs and SIEM

Record every run, finding, access event, and material state change. Stream events into Splunk, Datadog, Elastic, Microsoft Sentinel, or Panther.

Role-based access

Define which employees can view reports, connect repositories, manage findings, or change testing policy.

Data encryption

KMS encryption protects data at rest, encryption protects it in transit, and every customer's data remains isolated.

Data handling and retention

Antigen retains the data needed to run your pentests. You control how long it is kept with a 30-day, 90-day, or custom policy, and can purge it on demand.

Reports your security organization can use.

Certifications and assurance

Antigen is HIPAA compliant, and an independent SOC 2 Type II audit is underway. We will also help your team meet its own compliance requirements with mapped findings, reproducible evidence, and review support.

SOC 2 Type II

Audit underway

GDPR

Data protection requirements

Security architecture

Technical documentation

HIPAA compliance

Compliant

Compliance-mapped reporting

Findings map to the standards security, legal, and compliance teams already use.

PCI DSS

Mapped findings and evidence

NIST 800-171

CUI control mapping

ISO 27001

Audit-ready structure

CWE

Industry-standard identifiers

Procurement readiness

Get the documents and review support your legal, privacy, and security teams require.

DPA and MSA

Standard agreement support

Questionnaire

Current control responses

Architecture session

Deployment and data flow

Security contact

Named enterprise support

Visit the Trust Center

Fits into your existing workflows.

Move confirmed findings into the systems your security and engineering teams already use.

Antigen connects to Jira, AuditBoard, Azure DevOps, Microsoft Teams, Splunk, Tenable, Power BI, Metabase, Slack, ServiceNow, GitHub, and Linear.
  • Jira
  • AuditBoard
  • Azure DevOps
  • Microsoft Teams
  • Splunk
  • Tenable
  • Power BI
  • Metabase
  • Slack
  • ServiceNow
  • GitHub
  • Linear

Built for environments where compromise changes the business.

Continuous offensive security for organizations accountable to customers, regulators, and the public.

Antigen helps public-sector teams and their service providers test approved systems continuously while preserving the evidence needed for authorization and oversight.

  • Validate internet-facing, internal, and cross-vendor attack paths.
  • Support GovRAMP assessment packages with scoped findings and reproducible evidence.
  • Retest significant changes and keep a record of scope, approvals, and execution.
Antigen for Government

Frequently asked questions

Is it safe to run Antigen against production?

Antigen operates within explicit scope, rate, technique, and approval policies established by the customer's security team. Active runs remain observable and can be paused or terminated immediately.

Does Antigen make changes to production?

Testing and remediation permissions are governed separately. Antigen does not merge or deploy a remediation without the review and approval workflow configured by the customer.

What does Dedicated mean?

Dedicated is Antigen's on-premises deployment. Antigen workers run inside the customer's cloud account, Kubernetes cluster, or private network.

Where are credentials and findings stored?

Storage depends on deployment. Dedicated keeps credentials, findings, logs, and artifacts inside the customer's environment. Managed retains the data needed to run your pentests under a customer-controlled retention policy, with on-demand purging.

Do you support SSO, SCIM, and RBAC?

Yes. Antigen supports SAML 2.0 and OIDC single sign-on, SCIM provisioning, and customer-defined roles and permissions.

Can audit logs stream to our SIEM?

Yes. Audit events can stream into Splunk, Datadog, Elastic, Microsoft Sentinel, or Panther so they appear in the systems your security team already monitors.

Can we purge our data on demand?

Yes. Set a 30-day, 90-day, or custom retention policy, or purge testing data on demand. Deletion events remain in the audit trail.

Can we build on the API?

Yes. Use an API key for machine-to-machine automation or an access token for requests tied to a user's identity. You can build a custom frontend behind your own identity provider.

Can we use Antigen reports for compliance reviews?

Findings map to PCI DSS, NIST, ISO, and CWE. Exported reports are structured for security, compliance, legal, and audit review.

What enterprise support is included?

Enterprise customers receive a dedicated security expert, finding review, office hours, and support through implementation, testing, and remediation.

See Antigen test your environment.

Book a 30-minute demo to review your deployment requirements and watch a live pentest.

Get a demo