Quantro Security
Seven specialist agents under a Supervisor that find, test and remediate exploitable vulnerabilities, with human approval for every action.
Quantro Security builds an agentic workforce for vulnerability and exposure management. Seven specialist agents, VM, Exposure, Pen Test, Remediation, Research, Compliance and Report, work under a Supervisor agent: they discover assets and findings, test reachability and exploitability, prove impact, execute fixes with human approval, build exploit checks when new CVEs are disclosed, map evidence to audit frameworks and write executive reporting.
The platform takes inputs from cloud providers (AWS, Azure, GCP), cloud security tools such as Wiz and Orca, and pentest and external attack surface tools, and sends outputs to ServiceNow, Jira, Slack and GitHub. Quantro states that a human stays in the loop for every action and that the company holds SOC 2 Type II and ISO/IEC 27001:2022 certification. Its first product, VM.Analyst, launched from stealth in March 2026. Quantro also publishes its own research on exploitation economics; those figures are the vendor's own. The company is based in New York, was founded by CEO Sasan Padidar and CPO Mehul Revankar with a team from CrowdStrike, Tenable and Qualys, and is backed by Gradient.
Vendor details
Canonical URL
https://quantro.security
Category
Security / SOC agent
Funding status
Seed. Backed by Gradient, Google's early stage AI seed fund. The funding amount was not disclosed. Emerged from stealth in March 2026.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Integrations
Inputs from AWS, Azure, GCP, Wiz, Orca and pentest and external attack surface tools; outputs to ServiceNow, Jira, Slack, GitHub and remediation jobs. No public API, SDK or MCP server is documented.
In practice
The scanners report thousands of critical findings and the team cannot tell which ones matter. Quantro's Exposure Agent checks which are reachable and exploitable in this environment, and the Remediation Agent prepares fixes that run only once a person approves them.
A new CVE is disclosed late on a Friday. The Research Agent builds an exploit check for it right away, and the results reach the team in Jira, ServiceNow or Slack.
An MSSP wants to sell full vulnerability management, not just PCI scans. It runs Quantro's agents multi tenant inside its own service, with its own analysts and its own SLA.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
7.0 / 14 capabilities · 50%
| Integrations & Tool Calling | Full |
|---|---|
|
Inputs come in from AWS, Azure, GCP, Wiz, Orca and pentest and EASM tools, and outputs go to ServiceNow, Jira, Slack, GitHub and remediation jobs. VM.Analyst also ingests from vulnerability management platforms, cloud security suites, CMDBs and firewalls, and a Fortune 100 energy customer brought more than 50 security tools together through Quantro. The platform works with existing telemetry and its own AI sensors rather than replacing the customer's tools. SourceQuantro Security, quantro.security, /case-studies and the launch post on quantro.security/blogread 2026-10-06 |
|
| Workflow Orchestration | Full |
|
A Supervisor agent orchestrates and monitors what Quantro calls an "agentic workforce" of seven specialist agents (VM, Exposure, Pen Test, Remediation, Research, Compliance, Report) and sequences the handoffs between them from start to finish. The work moves through discover, validate, pentest, close, research, comply and report phases, one for each specialist. SourceQuantro Security, quantro.securityread 2026-10-06 |
|
| Knowledge Grounding & RAG | Full |
|
VM.Analyst, launched in March 2026, ingests from vulnerability management platforms, cloud security suites, CMDBs and firewalls. It normalizes and deduplicates the data into one layer the agents reason over, in the context of the customer's environment, compensating controls and security configurations. For a Fortune 100 energy company, that cut 12 million findings to 4 actionable risks. SourceQuantro Security, the launch post on quantro.security/blog and /case-studiesread 2026-10-06 |
|
| Human Oversight & Guardrails | Full |
|
Quantro states "Human-in-the-loop for every action", and the Remediation Agent creates a fix and executes it only on the customer's approval. Security teams can also ask the agents questions or hand them tasks in plain language. SourceQuantro Security, quantro.security and the launch post on quantro.security/blogread 2026-10-06 |
|
| Security, Identity & Governance | Partial |
|
Stated certifications are SOC 2 Type II and ISO/IEC 27001:2022. No SSO, role model or audit log for the console is documented, and the site links no trust center. SourceQuantro Security, quantro.securityread 2026-10-06 |
|
| Observability & Auditability | Partial |
|
The agents explain why a risk is vulnerable, reachable and exploitable, and the Report Agent turns the whole picture into executive reporting and visualization. The Supervisor agent monitors the specialist agents as they work. No run trace or audit log of the agents' own steps is documented. SourceQuantro Security, quantro.securityread 2026-10-06 |
|
| Memory & State Persistence | Not documented |
|
Quantro describes no memory its agents keep from one run to the next, or how long it would last. The normalized vulnerability data the agents draw on is a shared knowledge layer about the customer's risk, not a memory of past runs. SourceQuantro Security, quantro.securityread 2026-10-06 |
|
| Deployment & Data Residency | Not documented |
|
No hosting region, customer environment or data residency option is documented. Quantro deploys its own AI sensors and works with the customer's existing telemetry, and a free outside in exposure assessment needs nothing deployed. MSPs and MSSPs can run the agents inside their own service, multi tenant from the start. SourceQuantro Security, quantro.security and /partnersread 2026-10-06 |
|
| Prebuilt Agents / Templates / Packs | Full |
|
Quantro ships seven named agents with stated jobs under a Supervisor agent. They are VM (continuous discovery across every asset), Exposure (reachability and exploitability), Pen Test (proof of impact), Remediation (fixes with approval), Research (exploit checks on CVE disclosure), Compliance (audit preparation and mapping) and Report (executive reporting and visualization). Customers run them as a continuous workforce, and a free outside in exposure snapshot needs nothing deployed. SourceQuantro Security, quantro.securityread 2026-10-06 |
|
| Triggers & Channel Coverage | Full |
|
The Research Agent builds exploit checks the moment a new vulnerability is disclosed, so a CVE disclosure starts its work without anyone asking. The VM Agent scans the environment continuously across every asset. SourceQuantro Security, quantro.securityread 2026-10-06 |
|
| Model Flexibility & Routing | Not documented |
|
No customer model choice or routing is documented, and Quantro's pages do not name a model provider. SourceQuantro Security, quantro.securityread 2026-10-06 |
|
| APIs / SDKs / MCP Extensibility | Not documented |
|
No public API, SDK or MCP server for building on the platform is documented, and the listed inputs and outputs are Quantro's own connectors. Partners can resell Quantro, refer deals, integrate it as systems integrators or join as technology alliances, and MSPs and MSSPs run the agents multi tenant inside their own service. SourceQuantro Security, quantro.security and /partnersread 2026-10-06 |
|
| Testing, Debugging & Optimization | Not documented |
|
The Pen Test Agent tests the customer's estate for proof of impact, safely showing what an attacker could actually do, but Quantro documents no way to test or score the agents themselves. It reports a 45% cut in critical risk within a week of deployment and ten times the analyst productivity of manual work at a Fortune 100 energy customer. SourceQuantro Security, quantro.security and /case-studiesread 2026-10-06 |
|
| Browser / Computer-use | Not documented |
|
No browser or computer use by the agents is documented. They act through connectors to cloud, ticketing, chat and code systems and through remediation jobs. SourceQuantro Security, quantro.securityread 2026-10-06 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Quantro Security released AI-Recon, an external attack surface scanner, and AI-XI, a vulnerability scoring model. Both tools are powered by the company's Exploit Harness, an autonomous system of AI agents that can generate verified exploits for disclosed vulnerabilities without human intervention.
Bears on: Agent capability
View sourcePricing
Not public. Quantro Security sells through a demo led enterprise motion; no pricing page is published.
Inference, not stated by the vendor: enterprise engagement scaled by environment size.
Included quota
Not public.
Cost watchouts
Inference, not stated by the vendor: cost likely scales with environment size and the volume of findings ingested.
Variable cost rationale
Inference, not stated by the vendor: cost likely scales with environment size and the volume of findings ingested; pricing is not published.
Overage / add-ons
Not public.
Sales call required
Yes, required for paid access
Free / trial
Book a demo.
Lowest paid plan
Not public.
Key ambiguities
No public pricing and no pricing page.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Quantro Security
The closest documented capability profiles to Quantro Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Exaforce8.0 / 14Adds documented Memory & State Persistence
- 7AI8.5 / 14Adds documented Memory & State Persistence and Deployment & Data Residency
- Airrived8.5 / 14Adds documented Model Flexibility & Routing and APIs, SDKs & MCP Extensibility, among others
- Anvilogic8.5 / 14Adds documented Deployment & Data Residency and APIs, SDKs & MCP Extensibility
- Linx Security6.5 / 14Fuller documented coverage on Observability & Auditability
- Token Security6.5 / 14Adds documented APIs, SDKs & MCP Extensibility
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded