CINQUE by Loom Security · Unified Security Posture ObservabilityThe correlation layerabove the stack you already own.
CINQUE reads what your posture and identity tools already produce, then correlates it across Identity, Device, Network, Application and Data.One picture of how your environment actually behaves, with first correlated visibility in about ninety minutes.
- Ingest & normalizeSignals from every control point, from the tools you already run
- Persona baselinesWhat normal looks like for each human, non-human, and agentic identity
- CorrelationSignals read together across Identity, Device, Network, Application, and Data
How CINQUE works, in three moves
Three moves.
One correlated picture.
Persona baselines
CINQUE learns what normal looks like for every business persona: a controller, a cloud engineer, a service account, an AI agent. Built from observed behavior, not stale directory data.
Cross-control-point correlation
An unmanaged device, an odd login, an unusual data touch: three ignorable alerts in three consoles. Read together, they are one urgent, obvious risk.
Anomalous journeys
When any identity's journey deviates from its baseline on any control point, you see it immediately, with the full story attached.





Persona Discovery and Risk
Rapid visibility into user journeys and business personas across all five control points. Behavioral baselines surface the risks that otherwise go unnoticed: Shadow AI, non-human identities, rogue service accounts, and quiet permission creep. Every correlated finding carries a recommended action, and your SOC pulls both through the CINQUE API into Torq, Tines, your SIEM, or your ticketing system. CINQUE does not push; the other system pulls.
One severity per persona
Each severity carries the contributing control points, so the why is always attached to the what.
The three views CINQUE produces: persona risk, activity map, and anomaly detection
Three views your stack
cannot produce today.
Built for analysts who need to act and leaders who need to explain. Click any capture to see it full size.
Risk rolled up to the people who matter
Signals from all five control points resolve into a single severity per persona — Critical, High, Medium, Low. Stop triaging findings in isolation.
- See which control points are driving the severity
- Human, non-human, and agentic identities side by side
- Track how a persona moves between bands over time

The whole journey on one timeline
How an identity moves across your environment, from authentication through data access, on a single axis.
- Cross-control-point activity in one view
- See where behavior concentrates risk
- Compare against the established baseline

The moment a journey goes off-script
When behavior deviates from baseline on any control point, CINQUE flags it with the context that explains why it matters.
- Baselines per identity, including agents
- Correlation across control points cuts false positives
- Full journey attached to every finding

Time to detect is not a SIEM setting. It is how long a persona can drift before anyone is looking.
Behavioral baselines for human, non-human, and agentic identities
Baselines for everything
that holds access.
People
Employees, contractors, and third parties. The identity type every tool already covers, and the one that behaves most predictably.
Service accounts
Machine identities, tokens, keys, and integrations. They outnumber your people and rarely have an owner who can tell you what normal looks like.
AI agents
Autonomous agents acting with delegated access. CINQUE establishes behavioral baselines for agents the same way it does for human and non-human identities.
Loom Lens is how we think, not something we sell. Analyze risk through the user's journey and perspective rather than disconnected alerts and siloed tools. People at the center, context over noise. CINQUE is that methodology, built into software.
Improve Identity Governance
Access decisions checked against actual behavior.
Accelerate Zero Trust
Behavioral evidence that controls work as designed.
Detect Shadow AI
Plus non-human identities and rogue service accounts.
Reduce alert fatigue
A short list of correlated stories, not a queue of raw alerts.
Decide faster
Context that turns findings into decisions.
Thinking “this sounds like UEBA”?
Right instinct, wrong architecture. UEBA lived inside the SIEM: months of tuning, per-user scores with no business context, and one more queue of false positives. CINQUE reads the posture signals you already own, baselines business personas rather than lone users, and shows its first correlated picture in about ninety minutes from deployment, not two quarters. The idea was right. The layer it lived in was not.
Deployment day
Connect CINQUE to your posture tools and see the first correlated picture of your environment the same day, about ninety minutes from deployment.
Week one: personas emerge
CINQUE clusters your population, human, non-human, and agentic, into behavioral personas your team reviews and refines.
Ongoing: correlated risk
Prioritized cross-control-point findings with full journey context, ready for your SOC, IR, and audit workflows.
See your own environment,
not a canned demo.
Start with an export from your identity provider. Add a data source if you have one, and any others you want in the picture. The Discovery Workshop returns your own personas, the risk hiding between your tools, and a prioritized roadmap mapped to what you already own. No tools displaced, nothing to uninstall afterward.