Identity and access
Connect Antigen to Okta, Entra ID, or Google Workspace with SAML 2.0 or OIDC. SCIM keeps users in sync, while role-based access controls who can view findings, manage policy, or start a run.
Control what Antigen runs on, the policies it follows, who can access it, how every action is audited, and how long your data is retained.
Book a demoAntigen connects to your identity provider, logs every action to your SIEM, provides fine-grained control over data retention, and ships with the documents your audit team needs.
Connect Antigen to Okta, Entra ID, or Google Workspace with SAML 2.0 or OIDC. SCIM keeps users in sync, while role-based access controls who can view findings, manage policy, or start a run.
Only retain the data Antigen needs to run your pentests. Choose how long it is kept, or purge it on demand.
Every run, finding, login, policy change, and data access can be recorded and streamed to Splunk, Datadog, Elastic, Sentinel, or Panther.
Antigen is HIPAA compliant, with a SOC 2 Type II audit underway. Request an MSA, DPA, security questionnaire response, or certificate of insurance for your review.
Use Antigen as a managed service or run the entire stack inside your own infrastructure.
Use Antigen as a managed SaaS with the same enterprise controls and integrations available in a Dedicated deployment.
Run the entire Antigen stack inside infrastructure you control so no testing data leaves your network boundary.
Trigger pentests, automate security workflows, and build internal tools with the API and SDK. Authenticate with an API key or an access token.
Start a pentest before or after a release from the pipeline you already run.
Connect Antigen to your existing software factory so remediation uses its codebase context and produces the PR quality your team already trusts.
Bring run status, findings, and audit events into internal security tools.
Use scoped API keys for machine-to-machine workflows and automation.
Connect Antigen to your existing identity provider so employee access follows the roles and permissions you already manage.
Build an Antigen interface in Slack, Retool, or the internal dashboard your team already uses.
Connect Antigen to the identity, policy, data, and audit systems your organization already uses.
Connect SAML 2.0 or OIDC through Okta, Entra ID, or Google Workspace. SCIM provisions access from your employee directory and removes it when someone leaves.
Record every run, finding, access event, and material state change. Stream events into Splunk, Datadog, Elastic, Microsoft Sentinel, or Panther.
Define which employees can view reports, connect repositories, manage findings, or change testing policy.
KMS encryption protects data at rest, encryption protects it in transit, and every customer's data remains isolated.
Antigen retains the data needed to run your pentests. You control how long it is kept with a 30-day, 90-day, or custom policy, and can purge it on demand.
Antigen is HIPAA compliant, and an independent SOC 2 Type II audit is underway. We will also help your team meet its own compliance requirements with mapped findings, reproducible evidence, and review support.
Audit underway
Data protection requirements
Technical documentation
Compliant
Findings map to the standards security, legal, and compliance teams already use.
Mapped findings and evidence
CUI control mapping
Audit-ready structure
Industry-standard identifiers
Get the documents and review support your legal, privacy, and security teams require.
Standard agreement support
Current control responses
Deployment and data flow
Named enterprise support
Move confirmed findings into the systems your security and engineering teams already use.
Continuous offensive security for organizations accountable to customers, regulators, and the public.
Antigen helps public-sector teams and their service providers test approved systems continuously while preserving the evidence needed for authorization and oversight.
Antigen tests the applications, integrations, devices, and network paths that connect clinical operations to ePHI.
Antigen continuously tests the systems and trust boundaries around customer data and payment environments, giving security teams evidence between point-in-time assessments.
Antigen gives fast-moving product teams continuous evidence that production systems remain secure as applications, APIs, cloud infrastructure, and agents change.
Antigen operates within explicit scope, rate, technique, and approval policies established by the customer's security team. Active runs remain observable and can be paused or terminated immediately.
Testing and remediation permissions are governed separately. Antigen does not merge or deploy a remediation without the review and approval workflow configured by the customer.
Dedicated is Antigen's on-premises deployment. Antigen workers run inside the customer's cloud account, Kubernetes cluster, or private network.
Storage depends on deployment. Dedicated keeps credentials, findings, logs, and artifacts inside the customer's environment. Managed retains the data needed to run your pentests under a customer-controlled retention policy, with on-demand purging.
Yes. Antigen supports SAML 2.0 and OIDC single sign-on, SCIM provisioning, and customer-defined roles and permissions.
Yes. Audit events can stream into Splunk, Datadog, Elastic, Microsoft Sentinel, or Panther so they appear in the systems your security team already monitors.
Yes. Set a 30-day, 90-day, or custom retention policy, or purge testing data on demand. Deletion events remain in the audit trail.
Yes. Use an API key for machine-to-machine automation or an access token for requests tied to a user's identity. You can build a custom frontend behind your own identity provider.
Findings map to PCI DSS, NIST, ISO, and CWE. Exported reports are structured for security, compliance, legal, and audit review.
Enterprise customers receive a dedicated security expert, finding review, office hours, and support through implementation, testing, and remediation.
Book a 30-minute demo to review your deployment requirements and watch a live pentest.