CINQUE by Loom Security · Unified Security Posture ObservabilityCorrelate your visibility.Know your security posture.

Ask your stack what one identity did yesterday across all five control points. Nothing in it can answer.

CINQUE
Risk your stack cannot see Identity Device Network Application Data Risk your stack cannot see Identity Device Network Application Data

Why more tools have not produced more visibility

More tools have not given you
more visibility.

One morning, four things happen. Every console that sees one of them is correct to ignore it.

06:12Device

Unmanaged laptop authenticates on a contractor account

Low · queue noise
06:19Identity

Service account dormant for 60 days wakes, requests new OAuth scopes

Low · queue noise
06:31Network

First-ever path from that host toward the finance subnet

Low · queue noise
06:47Data

Unusual volume staged from a finance share to an external sync tool

Medium · queue noise
CRITICAL

Persona: Contractor, Finance Ops. Four signals, three consoles, one story: staged exfiltration in progress. Not one of the three consoles saw that it was wrong.

Individually, each of these signals sits below every triage threshold.

The story only exists when the five control points are read together.

Illustrative scenario.

And the population behind it is the one growing fastest.

Service accounts, tokens, integrations, and the identities reaching AI tools are the fastest growing population in any environment, and the least likely to have a documented normal.

109:1
Machine identities for every human identity
40%
Of deployed AI agents already reach organizational data

Palo Alto Networks, 2026 Identity Security Landscape Report

Correlation is the only thing that turns four ignorable alerts into one finding you can act on. That is what CINQUE does, above the stack you already own.

Book a Discovery Workshop

The three identity types CINQUE builds behavioral baselines for

Not everything on your network
is a person.

Most posture tools were designed around human users. The population that grew fastest is the one nobody is baselining.

01 — Human

People

Employees, contractors, and third parties. The identity type every tool already covers, and the one that behaves most predictably.

02 — Non-human

Service accounts

Machine identities, tokens, keys, and integrations. They outnumber your people and they rarely have an owner who can tell you what normal looks like.

03 — Agentic

AI agents

Autonomous agents acting with delegated access. CINQUE establishes behavioral baselines for agents the same way it does for human and non-human identities.

Illustrative scenario built on publicly disclosed agent behavior.

What CINQUE is, and where it sits above the stack you already own

Your tools each see a slice.
CINQUE sees the weave.

Posture tools were built one slice at a time. Each is right about its own and blind to every other. CINQUE is Loom Security’s Unified Security Posture Observability platform, the layer above them. Each blind spot between them is attack surface you own and cannot see.

From finding to action

Every finding arrives with the recommended action.

A correlated picture is only worth what your team can do with it. CINQUE writes the recommendation, attaches the evidence, and exposes both so the systems you already run can pick them up.

Recommended actionsEach finding carries a written recommendation and the journey behind it: which control points contributed, what changed against baseline, and why it ranked where it did.
An API you pull fromPersonas, signals, user journeys, entity relationships, and risk trends. CINQUE does not push into your queue. Your systems pull what they need, when they need it.
Into the workflow you already runPull the recommendations into Torq or Tines to kick off an orchestration, or into your SIEM or ticketing system, so the work lands where your team already works.

CINQUE performs no enforcement and replaces no workflow tool. It is the source your remediation path starts from. For Zero Trust programs it is the behavioral evidence that the architecture works the way the diagram says. Zero Trust, evidenced →

What CINQUE looks like in the product

What it actually looks like.

Built for analysts who need to act and leaders who need to explain. Two views your stack cannot produce today. Real product screens, shown with sample data.

CINQUE — Persona Risk
CINQUE persona view: one persona with a single Critical severity, five control-point tiles for Identity, Device, Network, Application, and Data each carrying its own severity and entity count, and four risk cards showing which control points contribute, one expanded to show the explanation and the Recommended Actions link
Persona RiskSignals from all five control points resolve into one severity per persona, with the contributing control points attached. Human, non-human, and agentic identities side by side.
CINQUE — Activity Map
CINQUE Activity Map for one persona, with a single non-human identity traced in yellow from identity through device and network to applications and data stores, against the persona’s baseline journeys; identifying labels redacted
Activity MapThe whole journey on one timeline, from authentication through data access, compared against the established baseline. Identifying labels redacted.

Time to detect is not a SIEM setting. It is how long a persona can drift before anyone is looking. See anomaly detection and all three at full size →

Start Here

See your own environment,
not a canned demo.

Start with an export from your identity provider. Add a data source if you have one, and any others you want in the picture. The Discovery Workshop returns your own personas, the risk hiding between your tools, and a prioritized roadmap mapped to what you already own. No tools displaced, nothing to uninstall afterward.