The Platform

CINQUE by Loom Security · Unified Security Posture ObservabilityThe correlation layerabove the stack you already own.

CINQUE reads what your posture and identity tools already produce, then correlates it across Identity, Device, Network, Application and Data.One picture of how your environment actually behaves, with first correlated visibility in about ninety minutes.

Where CINQUE sitsLogical architecture

How CINQUE works, in three moves

Three moves.
One correlated picture.

01

Persona baselines

CINQUE learns what normal looks like for every business persona: a controller, a cloud engineer, a service account, an AI agent. Built from observed behavior, not stale directory data.

02

Cross-control-point correlation

An unmanaged device, an odd login, an unusual data touch: three ignorable alerts in three consoles. Read together, they are one urgent, obvious risk.

03

Anomalous journeys

When any identity's journey deviates from its baseline on any control point, you see it immediately, with the full story attached.

Identity
Who is acting
Device
What they use
Network
How they connect
Application
What they access
Data
What they touch
Every persona has a shape.
Five personas from one tenant. Each fingerprint is the pattern its members’ journeys draw across the five control points: CINQUE derived it from observed behavior, nobody drew a group and assigned people to it.
01Behavioral fingerprint of persona 1: the shape its members' journeys draw across Identity, Device, Network, Application, and Data
02Behavioral fingerprint of persona 2: the shape its members' journeys draw across Identity, Device, Network, Application, and Data
03Behavioral fingerprint of persona 3: the shape its members' journeys draw across Identity, Device, Network, Application, and Data
04Behavioral fingerprint of persona 4: the shape its members' journeys draw across Identity, Device, Network, Application, and Data
05Behavioral fingerprint of persona 5: the shape its members' journeys draw across Identity, Device, Network, Application, and Data
Live platform capture · persona thumbnails as rendered by CINQUE
Flagship Module

Persona Discovery and Risk

Rapid visibility into user journeys and business personas across all five control points. Behavioral baselines surface the risks that otherwise go unnoticed: Shadow AI, non-human identities, rogue service accounts, and quiet permission creep. Every correlated finding carries a recommended action, and your SOC pulls both through the CINQUE API into Torq, Tines, your SIEM, or your ticketing system. CINQUE does not push; the other system pulls.

One severity per persona

CriticalHighMediumLow

Each severity carries the contributing control points, so the why is always attached to the what.

The three views CINQUE produces: persona risk, activity map, and anomaly detection

Three views your stack
cannot produce today.

Built for analysts who need to act and leaders who need to explain. Click any capture to see it full size.

Persona Risk

Risk rolled up to the people who matter

Signals from all five control points resolve into a single severity per persona — Critical, High, Medium, Low. Stop triaging findings in isolation.

  • See which control points are driving the severity
  • Human, non-human, and agentic identities side by side
  • Track how a persona moves between bands over time
CINQUE — Persona Risk
CINQUE persona view: one persona with a single Critical severity, five control-point tiles for Identity, Device, Network, Application, and Data each carrying its own severity and entity count, and four risk cards showing which control points contribute, one expanded to show the explanation and the Recommended Actions link
Live platform capture
Activity Map

The whole journey on one timeline

How an identity moves across your environment, from authentication through data access, on a single axis.

  • Cross-control-point activity in one view
  • See where behavior concentrates risk
  • Compare against the established baseline
CINQUE — Activity Map
CINQUE Activity Map for one persona, with a single non-human identity traced in yellow from identity through device and network to applications and data stores, against the persona's baseline journeys; identifying labels redacted
Live platform capture · identifying labels redacted
Anomaly Detection

The moment a journey goes off-script

When behavior deviates from baseline on any control point, CINQUE flags it with the context that explains why it matters.

  • Baselines per identity, including agents
  • Correlation across control points cuts false positives
  • Full journey attached to every finding
CINQUE — Activity Map · anomalies only, High severity
The same Activity Map as above, anomalies only, Severity High: two identities, one device, four networks, three applications and two data stores, the small subset of the persona that is off-script, with the legend for the five control points and the High, Medium, and Low bands; identifying labels redacted
Live platform capture · anomalies-only filter, High severity · identifying labels redacted

Time to detect is not a SIEM setting. It is how long a persona can drift before anyone is looking.

Behavioral baselines for human, non-human, and agentic identities

Baselines for everything
that holds access.

01 — Human

People

Employees, contractors, and third parties. The identity type every tool already covers, and the one that behaves most predictably.

02 — Non-human

Service accounts

Machine identities, tokens, keys, and integrations. They outnumber your people and rarely have an owner who can tell you what normal looks like.

03 — Agentic

AI agents

Autonomous agents acting with delegated access. CINQUE establishes behavioral baselines for agents the same way it does for human and non-human identities.

The Loom Lens Methodology

Loom Lens is how we think, not something we sell. Analyze risk through the user's journey and perspective rather than disconnected alerts and siloed tools. People at the center, context over noise. CINQUE is that methodology, built into software.

Improve Identity Governance

Access decisions checked against actual behavior.

Accelerate Zero Trust

Behavioral evidence that controls work as designed.

Detect Shadow AI

Plus non-human identities and rogue service accounts.

Reduce alert fatigue

A short list of correlated stories, not a queue of raw alerts.

Decide faster

Context that turns findings into decisions.

Thinking “this sounds like UEBA”?

Right instinct, wrong architecture. UEBA lived inside the SIEM: months of tuning, per-user scores with no business context, and one more queue of false positives. CINQUE reads the posture signals you already own, baselines business personas rather than lone users, and shows its first correlated picture in about ninety minutes from deployment, not two quarters. The idea was right. The layer it lived in was not.

1

Deployment day

Connect CINQUE to your posture tools and see the first correlated picture of your environment the same day, about ninety minutes from deployment.

2

Week one: personas emerge

CINQUE clusters your population, human, non-human, and agentic, into behavioral personas your team reviews and refines.

3

Ongoing: correlated risk

Prioritized cross-control-point findings with full journey context, ready for your SOC, IR, and audit workflows.

Start Here

See your own environment,
not a canned demo.

Start with an export from your identity provider. Add a data source if you have one, and any others you want in the picture. The Discovery Workshop returns your own personas, the risk hiding between your tools, and a prioritized roadmap mapped to what you already own. No tools displaced, nothing to uninstall afterward.