ÿÿ Enterprise Continuous Agentic Pentesting, Self-Hosted | Keygraph Skip to main content

Enterprise

For organizations whose regulatory or data-sovereignty requirements prohibit source code, findings, or AI inference traffic from leaving their environment.

Deploys on
Google Cloud Amazon Web Services Microsoft Azure

Air-gapped deployments
also available.

Keygraph Enterprise deploys entirely within your cloud infrastructure. Source code, scan results, and AI inference stay inside your security perimeter. No Keygraph-managed control plane, no external data plane.

Architecture

Every component runs inside your cloud account.

Your cloud account
01
Shannon Runner

Deployed in your cloud. Scans repos and infrastructure. Calls the LLM via your credentials.

02
Orchestration & UI

Scheduling, workflow, and operator console all run on your compute.

03
Findings Store

Your Postgres. Your encryption. Your retention policy.

04
Identity

Integrates with your IdP via SAML 2.0 or OIDC, with any standards-compliant provider.

Air-gapped deployments

Run the Keygraph platform in a fully network-isolated environment. Designed for FedRAMP, ITAR, defense, classified networks, and financial-services environments where every byte of egress requires legal sign-off.

Mirrored registry

Platform images mirrored to your private registry, Docker Hub, ECR, GCR, Artifactory, or Harbor.

BYO AI inference

Models served from your own Amazon Bedrock, Vertex AI, or Azure OpenAI endpoint, or a fully self-hosted model, using credentials you hold.

Offline license

No phone-home, no expiry-day surprises. Validation runs entirely inside your network.

Signed updates

Update bundles delivered as signed artifacts, applied on your schedule via your change-management process.

Integrations

Plugs into the tools your security and engineering teams already run. Native connectors for source control, identity, ticketing, and AI inference.

Ticketing

AI Inference (BYOK)

SSO via SAML 2.0 or OIDC. Native single sign-on with any standards-compliant identity provider, including Okta, Microsoft Entra ID, Ping, Auth0, OneLogin, or your own SAML / OIDC endpoint. SCIM provisioning, group-to-role mapping, and just-in-time user creation included. Custom webhook outputs and any S3-compatible registry are also supported.

Everything in Enterprise

The complete platform plus the support and services around it, in one license. Vulnerabilities are identified, validated with working exploits, prioritized by proven exploitability, and tracked through remediation in a single findings layer.

Continuous AppSec Coverage
Agentic SAST & Whitebox Pentesting

Source-aware static analysis with exploit validation: findings are confirmed against the running application, not just pattern matched.

Agentic Blackbox Pentesting

Penetration testing of the running application with zero code access. Findings are validated by exploitation, not inferred from signatures.

Business Logic Security Testing

Identifies workflow and authorization flaws traditional tools miss.

SCA · Supply chain

Open-source dependency risk with reachability analysis: only CVEs that are actually reachable from your code are surfaced for triage, covering supply-chain risk requirements.

Secrets Scanning

Committed credentials, tokens, keys.

Code Remediation

Fixes for confirmed findings, opened as reviewable pull requests. Patches are never auto-applied; your team reviews and merges.

Unified Findings & Workflow
Single findings layer

Unified across all scanners. One queue, one triage model.

Severity calibration

Tunable to your risk model and asset criticality.

Ticketing & chat integration

Jira, GitHub, GitLab, Azure DevOps, Slack.

RBAC with role hierarchy

Granular permissions per project, scanner, and finding action. Inherit roles from your IdP groups.

Dedicated audit log tab

Every scan, finding mutation, status change, suppression, role grant, and integration call recorded with actor, timestamp, source IP, and diff. Searchable, filterable, and exportable as JSON or CSV for SIEM ingestion or auditor evidence.

SSO via SAML 2.0 or OIDC

Provisioning, de-provisioning, and group mapping inherit from identity.

License & Service
Unlimited scans

All scanners, all findings, no per-scan quotas.

BYOK across the stack

Bring your own keys for infrastructure and AI providers.

Customer engineer

A single point of contact, embedded with your team.

Quarterly business reviews

Usage, findings, and roadmap alignment, every quarter.

24x7 support

Custom SLAs written directly into your contract.

White-glove onboarding

Typically 4 to 8 weeks, end to end.

Full audit log retention

JSON and CSV export for SIEM ingestion and audit evidence. Scan records and validated findings produce evidence for penetration testing and vulnerability scanning requirements.

No add-ons. All scanners, integrations, and service items are included in the base license. You do not buy modules.

Annual contracts. Net 30 standard. Procurement-friendly paper available: MSA, DPA, and security addendum templates ready for redline.

Ready to talk through an Enterprise deployment?

Schedule time with a solutions engineer. We will walk through your current AppSec architecture, identify coverage gaps, and map how Keygraph deploys into your environment.

ÿÿÿÿ