| Service model | SaaS multi-tenant · TPCRM specialist · attack-surface scanner + AI questionnaire layer | SaaS multitenant · end-customer tenancy · Enterprise-tier isolated deployment on request |
|---|
| Public API | Not enumerated on public product surface | REST + MCP (Model Context Protocol) tool graph · OpenAPI 3.0 |
|---|
| SSO / SCIM | Not publicly disclosed on product page | SAML 2.0 · OIDC · SCIM 2.0 |
|---|
| Audit-trail model | Platform-internal store · no external anchor / per-event signing / transparency log disclosed | Evidence Graph · hash-chained per-event · Ed25519 signing · RFC 3161 external timestamp anchor · SDK-licensable |
|---|
| Vendor-incident-response product | Incident Response Portal — alert routing + task tracking + comms (generic workflow) | DC-TPIR (Dependency-Centric Third-Party Incident Response) — codified per-incident-type playbooks with MSA contractual mapping and comms templates; methodology from Yolonda’s Someone Else’s Breach |
|---|
| Where the AI actually runs | Inside the Panorays UI · buyer’s Claude / Cursor / partner agents cannot invoke vendor operations directly | Callable from any MCP-speaking client (Claude, Cursor, custom LLMs, partner stacks, autonomous loops) · every invocation Ed25519-signed to Evidence Graph |
|---|
| Autonomous execution layer | Agentic AI drives automated remediation inside the platform; not separately productized with published evaluation harness | Trustworthy Autonomy (public beta 2026-07-07) · Level 1 agent governance proven prod 2026-08-17 · published evaluation harness |
|---|
| External attack-surface scanning | Primary technical asset · continuous scans on the whole vendor tail · Risk DNA composite score | Inside the red-team service, QCD diligence, and DC-TPIR · engagement-driven, not a continuous cyber-rating engine at 200+ vendor scale |
|---|
| ISO/IEC 42001 AI-governance cert | First TPCRM vendor with the cert (management-system cert on how the AI is operated, not on whether the AI’s answers are correct) | Not certified today |
|---|
| Portfolio-concentration risk primitive | Individual-vendor Risk DNA only | QCD Pillar 2 (HHI concentration) codified from Yolonda’s Someone Else’s Debt |
|---|
| Own compliance | ISO/IEC 42001 certified AI-governance management system; broader own-compliance not publicly disclosed | SOC 2 Type II · ISO 27001 (in progress) · runs on itself |
|---|