Company

We built the tool we kept wishing existed.

SanCipher started with a specific frustration: every platform that promised to find sensitive data first insisted on taking a copy of it. That trade seemed backwards then and it seems worse now that agents read everything. So we moved the analysis to the data instead.

Where the name comes from

san · cipher

Sanitise, then cipher — clean the data before it travels, and keep what travels unreadable to anyone it was not meant for. The ring in the mark is a boundary with a deliberate gap: security that is closed enough to hold, open enough that work still gets done.

Founded on one refusal no data copies
Four modules, one queue by design
What we believe

Four positions we are not flexible on

01

Inspection should not create a second copy

The moment your regulated data lands in a vendor tenancy, it has a new breach surface, a new retention clock and a new review to pass. Analysis belongs where the data already lives.

02

Show the gap, not the flattering half

Coverage screens exist to be uncomfortable. If four hundred identities have no protected browser, that number belongs on the dashboard, not in a footnote nobody reads.

03

Nothing blocks work without a rehearsal

Every rule that can stop someone's day replays against real history first. A security team that breaks production twice never gets to enforce anything again.

04

Evidence, never certification

We will produce the artefact behind every control and name the controls with no evidence at all. We will not tell you that you are compliant — that was never ours to say.

How we got here

Built one module at a time, in the order teams asked for them

  • Start
    Privalayer, on the browser

    The first module, built because the browser was the only place where shadow AI was visible at all — and the only place where analysis could plausibly run locally.

  • Then
    Code security

    Added when it became obvious that the credentials being pasted into chat tools were the same ones sitting in commit history. The correlation model came from this pairing.

  • Then
    Cloud security

    Deliberately generic posture management. Not a new category — the complete, boring version of something every team already needed, sharing evidence with the other modules.

  • Now
    Redtrace, for agents and MCP

    Continuous red-teaming with deterministic replay. Agentic and MCP testing are first-class here rather than a filter on a generic scanner, because that is where the wedge is.

  • Next
    Deeper correlation

    More cross-module links, richer automation templates, and evidence packs that assemble themselves from all four modules without anyone opening a spreadsheet.

Get in touch

Book a working session

Thirty minutes. We connect one cloud account or one repository live on the call, and you leave with a real findings list from your own environment rather than a slide deck about someone else's.

We will reply within one business day. No sequence, no drip campaign — one human, one reply.

Still reading? Let's talk properly.

A working session, not a pitch. Bring an environment and a problem you have not solved yet.

No credit card. No agent on the endpoint. Nothing leaves your network.