Skip to main content

🪐 Backed by $16.5M to build the security workforce for the security workforce. Meet the new Cantina.

Agents for every issue

Cantina agents are reasoning systems that work across your whole stack, taking each issue from raw signal through to validated remediation. Start from a prebuilt agent, adapt one to your environment, or build your own.

Replace manual security work with agents

A Cantina agent does the work of a security analyst or engineer, not the scripted steps of a bot or workflow. It reads each issue, reasons across every system you've connected to decide whether it's real, and then acts to resolve it, bringing in a person only when the situation genuinely calls for one.

01 Prebuilt agent
Upper-torso blueprint drawing representing the Cloud posture agent

Monitors

01 / 18

Cloud posture agent

GCP Security Command Center

active · last run 2026-06-30

Catches posture drift such as public buckets and over-permissive IAM, grades it by real data sensitivity and usage, and shuts it down before it's abused.

  • Public bucket exposure
  • IAM right-sizing
  • Key rotation handoff

Consequential changes route through human approval.

Adapt and use our agents

Most teams take the default that's closest to what they need and adjust its logic, thresholds, and workflow until it fits their environment.

Build your own

Fully programmable agents, built from skills, playbooks, and tools.

When you need something specific, build an agent from the ground up: compose its skills, connect each one to only the tools it needs, and orchestrate complete workflows across your systems.

Borrow what already works

Agent proven and shared from the Cantina Customer Community.

Bring in an agent another team has already proven, with its skills and thresholds intact, then connect your own tools and set your own level of autonomy. Because every skill is readable, you can see exactly what it does before it runs.

Built so you can let it act

Cantina agents close issues, contain hosts, and change configurations. You decide what they can do, how much runs on its own, and see exactly what happened.

Manual Assisted Soon Autopilot Soon

Available now. Cantina finds, scores, and drafts the fix. You approve every action. Full control, full visibility, proof on every call.

  1. 01

    Discover

    Agents watch 4 domains

  2. 02

    Score

    Reachability + risk

  3. 03

    You approve

    Contain, fix, rotate

  4. 04

    Verify

    Merged + re-tested

See the full Trust page →

Put an agent on it

Start prebuilt, adapt it, or build your own. Either way, you're directing agents, not chasing alerts.