Skip to content

About

We are building the security leader that 90% of companies cannot hire

A great CISO does not spend their day reading CVEs. They spend it making sure the right person knows about the right problem before it becomes an incident — and that there is a record proving it. That job is repetitive, relational and verifiable, which is exactly the work an agent should do.

Why now

The gap is widening, not closing

Enterprises ask small vendors for SOC 2 reports and security questionnaires. Regulators ask for data protection records. Neither asks whether you have a CISO on payroll — they assume somebody is doing the work.

Companies between 20 and 300 people sit in the worst part of the market. They are too big for security to be a side task and too small to justify a $250k-to-$400k hire plus a four-to-seven-month search. So the work lands on a platform lead, a head of IT, or a technical founder who already has three jobs.

Meanwhile the demands keep arriving: an enterprise prospect sends a 140-question review, a renewal depends on SOC 2, a customer wants a DPA, an insurer wants proof of MFA. Each one is a small project that nobody owns. Multiply by twenty and you have an invisible backlog.

CISO Express closes that gap with an agent that does the operating work — learning the org, assigning owners, setting due dates, collecting evidence, escalating on breach and reporting upward — inside the tools your team already has open.

What we believe

  • Security work fails for organisational reasons, not technical ones. Someone has to know who owns what and keep asking.
  • A program nobody can see is a program nobody funds. Executives need one number and five decisions, not a 60-page report.
  • Evidence should be collected by a system, not remembered by a person. Humans should only be asked what only humans can attest to.
  • Escalation is kind. Silence is what lets a patch sit unshipped for five weeks while an audit date approaches.
Founded, by operators who ran security programs by hand
2026Founded, by operators who ran security programs by hand
Role archetypes Sentinel is trained to recognise
11Role archetypes Sentinel is trained to recognise
Frameworks supported out of the box
6Frameworks supported out of the box
Median time from install to first assigned issue
< 1 dayMedian time from install to first assigned issue
Remote-firstDistributed across Europe and North America
Founder-led salesYou talk to the people who build the product
Self-serveCreate a workspace and connect Slack or Teams in about two minutes

Put an owner on every issue

Start free, connect Slack or Teams, and Sentinel assigns the first issues before you commit to anything.