Private beta · Summer 2026

Seven stones.
One unblinking sight.
Total security.

PalantiriSecurity.com is an AI-driven security platform modeled on the seven palantíri — seven specialist agents that watch your network, endpoints, and data in concert. SOC telemetry, dark-web intelligence, ML threat hunting, immutable forensics, governance. Orchestrated. Always open. Never blinking.

7
Specialist agents
24/7
Unblinking watch
Immutable audit
The Seven Stones

Seven specialists, one watchful mind.

Each agent is named for one of the seven palantíri of Middle-earth. Each sees a different part of your environment — together they form an orchestrated sight that no single pane of glass can match.

[ALERT] auth_fail x42 [NEW] endpoint joined [INFO] scan clean
Anor · The Sun-stone
Real-time SOC
Live telemetry, correlated alerts, triage queues. The always-on daylight watch across every endpoint, firewall, and cloud workload.
Ithil · The Moon-stone
Dark web & insider threat
Covert-channel monitoring, credential leak intel, anomalous access patterns. Sees what moves in the dark your daytime tools miss.
Orthanc · The Wizard's Stone
ML threat hunting
Unsupervised anomaly detection across logs and process trees. Learns your baseline and surfaces behavior that's simply wrong.
NET · 10Gb/s
Amon Sûl · The Watchtower Stone
Network IDS / NDR
Deep packet inspection, flow analytics, lateral-movement detection. The tower on the road — nothing passes without being seen.
Osgiliath · The Central Stone
Orchestration & SOAR
The master console. Coordinates the other six, routes response playbooks, automates containment. One pane of glass — but not fragile.
EVT 0x7a3f e3f9…ab21 verified
PROC /bin/bash d40c…17fe captured
NET tcp 443 out 71a2…9b04 logged
FILE /etc/hosts 8e0d…cc11 hash-chained
USER root auth 4b8a…f7d3 signed
Elostirion · The Tower Stone
Forensics & audit ledger
Immutable, hash-chained event record. Every action signed, every breach reconstructable. Built for the day you have to explain what happened.
Annúminas · The Kingdom Stone
Governance & compliance
SOC 2, ISO 27001, NIST CSF, HIPAA evidence, mapped automatically. Policy drift flagged, audit packs generated on demand.
Live Sight · Osgiliath console

One console. Seven perspectives.

Osgiliath is where the other six stones report. Triage the day, correlate a breach, run a playbook, pull a compliance packet. All of it, without swivel-chair tooling.

Why Palantiri

Because one tool isn't enough. And seven siloed ones are worse.

Legacy stacks bolt SIEM, EDR, SOAR, NDR, DLP, GRC, and threat intel together with duct tape. PalantiriSecurity.com is built as one — seven specialist agents, one shared memory, one console.

Agentic, not alert-ic

Stones don't just raise alerts — they act. Contain a host, rotate a credential, quarantine a process, document every step.

Shared memory

What Amon Sûl sees on the wire, Orthanc correlates in process space, Ithil validates against leaked intel. No stitching.

Immutable by default

Every observation is hash-chained in Elostirion the moment it's made. Ransomware can't rewrite your forensics.

Dark-web aware

Ithil watches paste sites, underground forums, and leak marketplaces. Your credentials show up — we know first.

Compliance as a byproduct

Annúminas maps evidence to SOC 2, ISO 27001, NIST CSF, HIPAA continuously. Audit prep becomes "download packet."

Lightweight to deploy

Agent per endpoint, collector per subnet, API per cloud. Talks to what you already run — SIEM, EDR, IAM. No rip-and-replace.

Free Security Audit

Scan any website. No account needed.

Enter a URL and our stones will check your SSL, security headers, exposed directories, email authentication, and known vulnerabilities — in seconds.

Pricing

Start free. Scale when you outgrow us.

Three stones (Amon Sûl, Annúminas, Ithil) are open-source and MIT licensed — no account, no limits, no throttling. Paid tiers add continuous monitoring, LLM-driven correlation, endpoint response, and compliance evidence packs on top of that foundation.

OPEN SOURCE

Free

$0

Amon Sûl + Annúminas + Ithil. Unlimited external scans. Severity-ranked findings with copy-paste remediation. Runs from your laptop — stdlib Python, zero pip deps. MIT licensed on GitHub.

No credit card. No account. Ever.

STARTUP

Watch

$49/mo

Everything in Free, plus: scheduled daily/weekly scans, scan diffing (alerts on new findings only), email + Slack webhook alerts, REST API access, 90-day scan history, CSV/JSON export, one-click remediation templates pre-filled with your domain.

Save 25% with annual billing → $441/yr

MOST POPULAR

Guard

$199/mo

Everything in Watch, plus: Orthanc (Claude-powered correlation across findings), Anor (SOC rollup), authenticated scanning for logged-in areas, CVE correlation on banner versions, AI risk scoring, endpoint stack (ClamAV · YARA · osquery · Suricata · CrowdSec), SOC2 / PCI / HIPAA PDF evidence packs.

Save 25% with annual billing → $1,791/yr

ENTERPRISE

High Seat

Custom

Everything in Guard, plus: Elostirion (hash-chained forensic audit), Osgiliath (SOAR + remediation planner), cloud posture for AWS/GCP/Azure, SIEM / Jira / PagerDuty / EDR integrations, on-prem deployment option, SLA-backed incident response, dedicated Slack channel with a named engineer.

Typically $2–5k/mo depending on scope.

Founder offer
First 10 annual subscribers get 40% off for life. Lock it in at #waitlist below.
Early access

Join the watch. Before the next breach joins you.

Private beta opens Summer 2026. Request an invite — we're onboarding a small cohort of security teams who want to stop running seven tools to catch one attacker.

No spam. Beta invites only. One email a month, max.
✓ You're on the list. Check your inbox for a confirmation from Palantiri.