About

A team of security engineers who got tired of ten thousand alerts and built one list instead.

SOC 2 Type II · ISO 27001 · 1,400 security teams

    About

    A team of security engineers who got tired of ten thousand alerts and built one list instead.

    SOC 2 Type II · ISO 27001 · 1,400 security teams

      About

      A team of security engineers who got tired of ten thousand alerts and built one list instead.

      SOC 2 Type II · ISO 27001 · 1,400 security teams

        Our story

        Palisade began in 2019 with one incident. A cloud key sat in a public repository for 212 days before anyone noticed, and three good tools had each seen a piece of it.

        Nobody had the whole picture, so we built the product we needed that week: one list of what is exposed across people, devices, cloud and code, ranked by what an attacker would try first.

        Today 86 of us keep that list honest for 1,400 security teams. We still measure ourselves the same way: how long a finding stays open.

        An open-plan office with people at their desks
        Founded
        2019
        People
        86
        Security teams
        1,400
        Offices
        London, Lisbon

        How we work

        1. Open

          Show the exposure, not a dashboard

          A finding names the asset, the owner and the fix. If it cannot be acted on today it does not belong on the list.

        2. Open

          Read-only until you say otherwise

          We connect with the least access that works. Closing a finding is always a step you approve.

        3. Open

          Prove it afterwards

          Every closed finding keeps its evidence, so the audit is a link and not a week of screenshots.

        The team

        Security engineers, former auditors and designers. Small enough that the person who answers your ticket has read the code.

        • Ines Carvalho

          Co-founder, product

          Since 2019

        • Tom Whitlock

          Co-founder, engineering

          Since 2019

        • Amara Osei

          Head of detection

          Since 2020

        • Jonas Brandt

          Head of customer security

          Since 2021

        • Priya Menon

          Compliance lead

          Since 2022

        • Luc Fontaine

          Design

          Since 2022

        Sample team, demo data

        Where we work

        • 01

          London

          14 Curtain Road, EC2A 3NH

          Engineering and detection

        • 02

          Lisbon

          Rua da Boavista 82, 1200-066

          Customer security and support

        • 03

          Remote

          Nine countries, one on-call rota

          Follow-the-sun response

        Our story

        Palisade began in 2019 with one incident. A cloud key sat in a public repository for 212 days before anyone noticed, and three good tools had each seen a piece of it.

        Nobody had the whole picture, so we built the product we needed that week: one list of what is exposed across people, devices, cloud and code, ranked by what an attacker would try first.

        Today 86 of us keep that list honest for 1,400 security teams. We still measure ourselves the same way: how long a finding stays open.

        An open-plan office with people at their desks
        Founded
        2019
        People
        86
        Security teams
        1,400
        Offices
        London, Lisbon

        How we work

        1. Open

          Show the exposure, not a dashboard

          A finding names the asset, the owner and the fix. If it cannot be acted on today it does not belong on the list.

        2. Open

          Read-only until you say otherwise

          We connect with the least access that works. Closing a finding is always a step you approve.

        3. Open

          Prove it afterwards

          Every closed finding keeps its evidence, so the audit is a link and not a week of screenshots.

        The team

        Security engineers, former auditors and designers. Small enough that the person who answers your ticket has read the code.

        • Ines Carvalho

          Co-founder, product

          Since 2019

        • Tom Whitlock

          Co-founder, engineering

          Since 2019

        • Amara Osei

          Head of detection

          Since 2020

        • Jonas Brandt

          Head of customer security

          Since 2021

        • Priya Menon

          Compliance lead

          Since 2022

        • Luc Fontaine

          Design

          Since 2022

        Sample team, demo data

        Where we work

        • 01

          London

          14 Curtain Road, EC2A 3NH

          Engineering and detection

        • 02

          Lisbon

          Rua da Boavista 82, 1200-066

          Customer security and support

        • 03

          Remote

          Nine countries, one on-call rota

          Follow-the-sun response

        Our story

        Palisade began in 2019 with one incident. A cloud key sat in a public repository for 212 days before anyone noticed, and three good tools had each seen a piece of it.

        Nobody had the whole picture, so we built the product we needed that week: one list of what is exposed across people, devices, cloud and code, ranked by what an attacker would try first.

        Today 86 of us keep that list honest for 1,400 security teams. We still measure ourselves the same way: how long a finding stays open.

        An open-plan office with people at their desks
        Founded
        2019
        People
        86
        Security teams
        1,400
        Offices
        London, Lisbon

        How we work

        1. Open

          Show the exposure, not a dashboard

          A finding names the asset, the owner and the fix. If it cannot be acted on today it does not belong on the list.

        2. Open

          Read-only until you say otherwise

          We connect with the least access that works. Closing a finding is always a step you approve.

        3. Open

          Prove it afterwards

          Every closed finding keeps its evidence, so the audit is a link and not a week of screenshots.

        The team

        Security engineers, former auditors and designers. Small enough that the person who answers your ticket has read the code.

        • Ines Carvalho

          Co-founder, product

          Since 2019

        • Tom Whitlock

          Co-founder, engineering

          Since 2019

        • Amara Osei

          Head of detection

          Since 2020

        • Jonas Brandt

          Head of customer security

          Since 2021

        • Priya Menon

          Compliance lead

          Since 2022

        • Luc Fontaine

          Design

          Since 2022

        Sample team, demo data

        Where we work

        • 01

          London

          14 Curtain Road, EC2A 3NH

          Engineering and detection

        • 02

          Lisbon

          Rua da Boavista 82, 1200-066

          Customer security and support

        • 03

          Remote

          Nine countries, one on-call rota

          Follow-the-sun response

        In numbers

        Averages across every customer over the last twelve months. Your own numbers sit on the first screen of the product.

        Mean time to detect
        From the moment something is exposed to the moment its owner is told.
        Findings closed
        Closed by the person who owns the asset, not parked in a queue.
        Coverage
        Of identities, devices, cloud accounts and repositories under watch.
        Security teams
        From ten-person start-ups to regulated groups in 31 countries.

        Figures are sample data for this template

        In numbers

        Averages across every customer over the last twelve months. Your own numbers sit on the first screen of the product.

        Mean time to detect
        From the moment something is exposed to the moment its owner is told.
        Findings closed
        Closed by the person who owns the asset, not parked in a queue.
        Coverage
        Of identities, devices, cloud accounts and repositories under watch.
        Security teams
        From ten-person start-ups to regulated groups in 31 countries.

        Figures are sample data for this template

        In numbers

        Averages across every customer over the last twelve months. Your own numbers sit on the first screen of the product.

        Mean time to detect
        From the moment something is exposed to the moment its owner is told.
        Findings closed
        Closed by the person who owns the asset, not parked in a queue.
        Coverage
        Of identities, devices, cloud accounts and repositories under watch.
        Security teams
        From ten-person start-ups to regulated groups in 31 countries.

        Figures are sample data for this template

        Start here

        Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.

        Nothing is scanned until you connect a source. No card needed.

        We will sweep

        • Identity providerNot connected
        • Cloud accountsNot connected
        • DevicesNot connected
        • Code repositoriesNot connected

        Start here

        Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.

        Nothing is scanned until you connect a source. No card needed.

        We will sweep

        • Identity providerNot connected
        • Cloud accountsNot connected
        • DevicesNot connected
        • Code repositoriesNot connected

        Start here

        Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.

        Nothing is scanned until you connect a source. No card needed.

        We will sweep

        • Identity providerNot connected
        • Cloud accountsNot connected
        • DevicesNot connected
        • Code repositoriesNot connected
        Palisade

        Palisade watches every identity, device and key your company runs on, finds what is exposed and closes it before it turns into a breach.

        Book a demo
        © 2026 Palisade Security Ltd. All rights reserved. All systems securedPrivacyTermsCookies
        Palisade

        Palisade watches every identity, device and key your company runs on, finds what is exposed and closes it before it turns into a breach.

        Book a demo
        © 2026 Palisade Security Ltd. All rights reserved. All systems securedPrivacyTermsCookies
        Palisade

        Palisade watches every identity, device and key your company runs on, finds what is exposed and closes it before it turns into a breach.

        Book a demo
        © 2026 Palisade Security Ltd. All rights reserved. All systems securedPrivacyTermsCookies

        Create a free website with Framer, the website builder loved by startups, designers and agencies.