RedMentis

Validate security continuously. AI-orchestrated.

RedMentis makes security testing more repeatable and reveals attack paths in context, as a complement to classic penetration tests.

·THE PROBLEM

Classic pentests are point-in-time snapshots.

One audit per year, then 11 months of flying blind in between. RedMentis aims to close that gap, without replacing the classic pentest.

Status quo

Classic penetration test

1 ×

annual time window · manual effort

  • Snapshot instead of trend view
  • Hard to reproduce between audits
  • Findings go stale between tests
With RedMentis

AI-orchestrated validation

repeatable · isolated · automated

  • Continuous validation over time
  • Reproducible with the same scope
  • Path analysis instead of isolated findings
·THE PLATFORM IN ACTION

From the daily SOC alert to the board report in one interface.

RedMentis combines operational security, the management view and offensive testing in one platform, with clearly separated roles and a shared data foundation.

1. Login

One login screen for all roles

After successful authentication, the platform automatically routes the user to the right area:

  • SOC Analyst → SOC Dashboard
  • Executive → Executive Dashboard
  • Red Team → Simulations
  • Admin → all areas visible
·HOW IT WORKS

AI-orchestrated validation, step by step.

An AI-assisted decision logic models possible attack paths, evaluates intermediate results and prioritizes risks in context.

ENTRY VULNERABILITIES TARGET

01Scope & environment

Defined scope, isolated test environment, clear rules of engagement.

02Path modeling

AI-assisted modeling of possible attack paths across identities, configurations and interfaces.

03Controlled validation

Tests run repeatably in an isolated environment. Intermediate results are evaluated and prioritized.

04Two-level reporting

Technical findings with remediation, management reports with clear context.

·SECURITY FRAMEWORK

The entire process runs under two non-negotiable rules:

  • Role-based access. Every action is tied to a role, every access is logged.
  • Compliance mapping. Findings are mapped to ISO 27001, NIS-2 and the EU AI Act, so audit requirements are met directly.
USE CASES

Situations where we support you

RedMentis
RedMentis

AI-powered attack path analysis with RedMentis

Problem
Classic pentests are often point-in-time. Vulnerabilities are documented in isolation, but rarely viewed in the context of possible attack paths.
Approach
RedMentis looks at vulnerabilities in the context of possible attack paths, across identities, misconfigurations, Web/API interfaces, and internal network structures. As a complement to the classic pentest, not a replacement.
Benefit
A more realistic view of attack paths, fewer irrelevant findings, and better prioritization.
RedMentis · Research and development initiative
RedMentis
RedMentis

Make security validation repeatable

Problem
Security posture should be reviewed not just once a year, but repeatably. Especially before audits, releases, or migrations.
Approach
RedMentis aims to make security testing more repeatable and continuous. AI-orchestrated, in a controlled, isolated test environment, with traceable results.
Benefit
More visibility into real maturity between audit cycles, with clear reports for engineering and management.
RedMentis · Phase 1: AI-powered Penetration Testing
RedMentis
RedMentis
In concept

Cyber Defense Lab & Security Research

Problem
Research partners or internal teams want to study attack patterns and defenses in a controlled environment, with no risk to production systems.
Approach
Build an isolated lab environment for reproducible tests, detection engineering, and security research. a planned future stage.
Benefit
Structured research on attack paths and detection, with clear security, governance, and compliance requirements.
RedMentis · Phase 2: Cyber Defense Lab

Questions? Answers.

What exactly is RedMentis?

An AI-orchestrated security validation. RedMentis does not just take a snapshot, it looks at weaknesses in the context of possible attack paths and makes that check repeatable. RedMentis is our research and development initiative, not a finished mass-market product.

Does RedMentis replace a classic penetration test?

No. RedMentis complements the classic pentest, it does not replace it. The value lies in repeatable checks between audit cycles and in the view of connected attack paths instead of isolated findings.

Where and how do the tests run?

In a controlled, isolated test environment. Every action is bound to a role, every access is logged. Production systems stay untouched and the results stay traceable.

Which standards does RedMentis map findings to?

Findings are mapped to ISO 27001, NIS 2 and the EU AI Act. A technical result becomes evidence that fits directly into audit and management requirements.

What is the development status of RedMentis?

RedMentis is in active development. We are open about the current status and assess first use cases or a pilot setup together with you, matched to your environment.

Get to know RedMentis.

We're happy to talk about pilot setups, research partnerships or initial use-case assessments, aligned with the current stage of development.