Category and positioning
Where AI-SPM sits relative to AI TRiSM, CNAPP, DSPM, ASPM and LLM guardrails. What we test versus what a runtime guardrail proxy enforces, and why the two are complementary.
Penaxtra briefs industry analysts on the AI Security Posture Management market. This page is for analysts at Gartner, Forrester, IDC, GigaOm and independent research firms. Briefings are open, on the record, and grounded in the shipped product - not a roadmap deck.
Every topic below maps to a shipped subsystem you can see in a live demo, with control-mapped output at the end.
Where AI-SPM sits relative to AI TRiSM, CNAPP, DSPM, ASPM and LLM guardrails. What we test versus what a runtime guardrail proxy enforces, and why the two are complementary.
The scan engine, the self-hosted runtime gateway with Ed25519-signed policy distribution, AI asset inventory, cloud AI posture, and the compliance-evidence pipeline. Data residency is a first-class design constraint.
The multi-judge consensus method, framework control-ID mapping across six frameworks, and how a finding becomes audit evidence. We are direct about what is measured versus what is still being calibrated.
Why we build for regulated mid-market teams facing EU AI Act and ISO/IEC 42001 obligations, and the Turkish-market depth (BDDK, KVKK, native Turkish coverage) that sets our regional focus.
Briefings run 30 to 45 minutes: a live product walkthrough, the architecture, and open Q&A. We can follow up with the fact sheet, a scoped demo workspace, and written answers to a research questionnaire.
Reach the team through the contact form and note that you are an industry analyst. We reply from a named technical contact, not a shared alias.
Contact us →Company and product facts on one page: the entity, the market category, the frameworks covered, the deployment model, and the open-source footprint.
Open fact sheet →Product availability, the open-source releases, and the public footprint an analyst can verify independently.
Open newsroom →We would rather you verify than take a slide at face value. Everything below is public.
Every capability, anchored to the subsystem that ships it.
Open →Trust boundary, signed rule distribution, control-plane split.
Open →Encryption, tenant isolation, audit log, coordinated disclosure.
Open →Data residency, subprocessors, certification status.
Open →Six frameworks at control-ID level with cross-framework overlaps.
Open →Apache-2.0 tooling published under our own name.
Open →Analysts covering AI security, AI-SPM, AI TRiSM, LLM security or EU AI Act readiness: reach out for a live walkthrough and a research questionnaire response. No client relationship required.