Resources

Datasheets, the blog,
and the proof.

What CINQUE does, by industry. What we think, in writing. And what one customer got out of it.

Datasheets

One platform.
Written for your industry.

Nothing here is gated. Every datasheet is also published as a full page on this site, so you can read it, link it, and quote it without downloading anything.

Every industry datasheet opens with the same question. Which identities touched it last night? Here is the it, for yours.

Financial Services

Payment rails

The reconciliation nobody runs: entitled versus observed, for payment rails, fintech partners, contractors, and the agents in KYC, AML, and fraud workflows.

NYDFS Part 500DORACRI ProfilePCI DSS v4.x
Insurance

Policyholder data

The ledger a carrier never balances: access, across brokers, TPAs, claims vendors, and every operating company you own.

NYDFS Part 500NAIC #668
Healthcare

PHI

One correlated journey per persona, human, non-human, and AI, across a federated health system, mapped to where the HIPAA Security Rule is heading.

HIPAA Security Rule
Manufacturing

The plant floor

IT and OT read together, so a vendor on a PLC or a service account talking to a controller is judged against what is normal for that identity.

IEC 62443CMMC 2.0
Energy & Utilities

Control systems

The adversaries pre-positioning in critical infrastructure log in with valid credentials and wait. Behavior is the only proof.

NERC CIPTSA SD Pipeline-2021-02IEC 62443
Oil & Gas

SCADA

For contractor-run operations: every persona, human, non-human, and AI, measured against its own normal, mapped to the TSA pipeline directives.

TSA SD Pipeline-2021-01/-02API 1164
Rail & Transportation

The railroad

Entitled versus observed across the enterprise, the yard, and the operations network.

TSA SD 1580/82-2022-01
Retail

Your stores

Seasonal churn, store-systems vendors, and the payment path, reconciled across stores, DCs, and digital.

PCI DSS v4.x
Thanks. You are on the list.
Blog

Posture, correlation, identity.
From the people building CINQUE.

AI Security

Nobody Baselines an Agent: Six Weeks of Disclosures, Read in Order

Autonomous attack capability is compounding, rapidly. The identity population has changed — and behavioral baselining has not followed it. Six weeks of daily AI security intelligence briefings, read in order, reveal one story in four stages. The fourth stage is the one begging for attention.

Casey Rash · September 7, 2026
Identity Security

The Third Identity Category: Why AI Agents Break Identity Security Models

For decades, identity programs have operated around two categories: human identities and non-human identities. As autonomous AI agents begin to reason, act, and interact across enterprise environments, a critical question emerges: do existing governance models adequately address a new class of digital actors?

Casey Rash · June 3, 2026
Product & CINQUE

Beyond Mythos and curl: Why AI-Powered Context is Security’s New Superpower

How platforms like Loom Security’s CINQUE use persona-based behavioral analysis to understand the real context behind user activity, much as AI code analysis tools now reason about vulnerabilities with human-like understanding. CINQUE maps authentic user journeys across systems to cut alert noise, surface meaningful anomalies, and deliver business-contextualized security insight in as little as 90 minutes.

David Yarnevich · May 21, 2026
Product & CINQUE

The Illusion of Control

This article explores why traditional security controls like Zero Trust and RBAC fall short without behavioral persona context, and how CINQUE helps organizations detect risk faster by correlating user behavior across identity, devices, networks, applications, and data.

Chris Vermilya · May 12, 2026
Product & CINQUE

Beyond the Blind Spots: Taming the Modern Enterprise Sprawl

Modern enterprises are riddled with hidden risk from unchecked SaaS sprawl and fragmented communication channels, where lack of visibility leads to both data exposure and operational inefficiencies. By applying persona-based, end-to-end visibility, CINQUE transforms security from reactive alert-chasing into proactive, business-aligned intelligence that reduces risk while enabling productivity.

David Yarnevich · March 25, 2026
Product & CINQUE

Technology Sprawl and Inefficient Operations

Security teams struggle with fragmented tools and limited visibility, making it difficult to piece together a complete “story” of user activity and leading to inefficient investigations and potential missteps. By shifting to a persona-driven view of the full user journey—from device to data—organizations can gain unified visibility, improve decision-making, and build more resilient, user-centric security programs.

Bryan Hutchinson · March 18, 2026
Thought Leadership

From Data Hoarding to Identity Intelligence

The security industry has centralized massive amounts of data into SIEM platforms, but still lacks the ability to turn that data into meaningful insight about user behavior and risk. Loom Security built CINQUE to close this gap: an identity intelligence engine that correlates activity across identity, device, network, application, and data into a persona-driven view of security aligned to how the business actually operates.

Steven Ly · February 20, 2026
Thought Leadership

The Silent Persistence Layer: Why OAuth Governance Is Now a Critical Identity Risk

OAuth tokens have become a silent persistence layer in modern identity environments, allowing attackers to maintain access even after passwords are reset and MFA is enforced. This article explores why OAuth governance is now critical to IAM strategy and how organizations can close this growing gap before it’s exploited.

Chris Vermilya · December 1, 2025
Thought Leadership

How Persona-Based Security is Redefining Defense, and why Unified Security Posture Observability is the Future

Persona-based security reframes defense around user behavior and context, replacing fragmented, tool-driven approaches with a unified view of risk that connects identity, device, network, application, and data signals. Unified Security Posture Observability makes that shift real by removing silos, reducing complexity, and turning scattered telemetry into a correlated risk picture, so organizations move from reactive security to proactive, business-aligned decisions.

Chuck Crawford · October 14, 2025