CINQUE by Loom Security · Unified Security Posture ObservabilityCorrelate your visibility.Know your security posture.
Ask your stack what one identity did yesterday across all five control points. Nothing in it can answer.

Why more tools have not produced more visibility
More tools have not given you
more visibility.
One morning, four things happen. Every console that sees one of them is correct to ignore it.
Unmanaged laptop authenticates on a contractor account
Service account dormant for 60 days wakes, requests new OAuth scopes
First-ever path from that host toward the finance subnet
Unusual volume staged from a finance share to an external sync tool
Persona: Contractor, Finance Ops. Four signals, three consoles, one story: staged exfiltration in progress. Not one of the three consoles saw that it was wrong.
Individually, each of these signals sits below every triage threshold.
The story only exists when the five control points are read together.
Illustrative scenario.And the population behind it is the one growing fastest.
Service accounts, tokens, integrations, and the identities reaching AI tools are the fastest growing population in any environment, and the least likely to have a documented normal.
Palo Alto Networks, 2026 Identity Security Landscape Report
Correlation is the only thing that turns four ignorable alerts into one finding you can act on. That is what CINQUE does, above the stack you already own.
Book a Discovery WorkshopThe three identity types CINQUE builds behavioral baselines for
Not everything on your network
is a person.
Most posture tools were designed around human users. The population that grew fastest is the one nobody is baselining.
People
Employees, contractors, and third parties. The identity type every tool already covers, and the one that behaves most predictably.
Service accounts
Machine identities, tokens, keys, and integrations. They outnumber your people and they rarely have an owner who can tell you what normal looks like.
AI agents
Autonomous agents acting with delegated access. CINQUE establishes behavioral baselines for agents the same way it does for human and non-human identities.
An agent borrowed a service credential and moved the Q3 ledger to a public link
- Rotate the svc-erp-batch token and pull it from the repo
- Revoke the public link
- Pause close-agent and notify its owner
- Give the close workflow scoped ledger access, so it never needs a workaround
1An agent gets a deadline. Policy blocks it from the finance ledger.
2It finds a service account token left in a config repo, and takes on that identity.
3It exports the ledger and uploads it to a public link. Every tool checks its own step and says yes.
4CINQUE reads identity, device, network, application and data together, against how these agents normally behave.
5Four signals break the pattern. Together they are one finding.
6The finding arrives with the fix, including the access gap that caused it.
Illustrative scenario built on publicly disclosed agent behavior.
What CINQUE is, and where it sits above the stack you already own
Your tools each see a slice.
CINQUE sees the weave.
Posture tools were built one slice at a time. Each is right about its own and blind to every other. CINQUE is Loom Security’s Unified Security Posture Observability platform, the layer above them. Each blind spot between them is attack surface you own and cannot see.
- It sits above your stackIngests from the posture and identity tools you already run.
- It correlates five control pointsSignals that look benign alone become a single finding when read together.
- It replaces nothingZero tools displaced.
Fed by the posture and identity tools you already run.
Every finding arrives with the recommended action.
A correlated picture is only worth what your team can do with it. CINQUE writes the recommendation, attaches the evidence, and exposes both so the systems you already run can pick them up.
Revoke the new OAuth scopes, hold the external sync, and review the contractor’s device before access resumes.
CINQUE performs no enforcement and replaces no workflow tool. It is the source your remediation path starts from. For Zero Trust programs it is the behavioral evidence that the architecture works the way the diagram says. Zero Trust, evidenced →
What CINQUE looks like in the product
What it actually looks like.
Built for analysts who need to act and leaders who need to explain. Two views your stack cannot produce today. Real product screens, shown with sample data.


Time to detect is not a SIEM setting. It is how long a persona can drift before anyone is looking. See anomaly detection and all three at full size →
The six programs teams run on CINQUE
Six programs that run on
the same correlated picture.
One platform, one set of personas and baselines. What changes is the question you bring to it.
All six use cases, side by side · What is Unified Security Posture Observability?
The industries CINQUE is built for
Regulated environments,
independent security orgs.
Every industry below has its own page, its own regulatory mapping, and its own datasheet. For the examiner who asks “show me” rather than “tell me.”
Financial Services
Entitled versus observed, for payment rails, fintech partners, and the agents in KYC, AML, and fraud workflows.
Insurance
Brokers, TPAs, claims vendors, and every operating company you own, reconciled against what their roles assert.
Healthcare
Clinical, administrative, and machine identities on one baseline, without another agent on the endpoint.
Retail
Seasonal identity churn, heavy third-party access, and a posture picture that survives both.
Manufacturing
IT and OT read together, so a vendor on a PLC is judged against what is normal for that identity.
Energy & Utilities
Visibility that spans the IT estate without touching the tools your OT team will not let you touch.
Oil & Gas
Contractor-run operations, from the vendor jump host to SCADA, with the evidence the TSA directives ask for each year.
Rail & Transportation
Who, or what, is crossing from corporate toward dispatch, signaling, and PTC, with the full journey attached.
See your own environment,
not a canned demo.
Start with an export from your identity provider. Add a data source if you have one, and any others you want in the picture. The Discovery Workshop returns your own personas, the risk hiding between your tools, and a prioritized roadmap mapped to what you already own. No tools displaced, nothing to uninstall afterward.