SOC 2 Type II · ISO 27001 · 1,400 security teams
SOC 2 Type II · ISO 27001 · 1,400 security teams
Palisade
Palisade
Risk score82/100open
Next page/
Home
About
We find what was left open.
A team of security engineers who got tired of ten thousand alerts and built one list instead.
SOC 2 Type II · ISO 27001 · 1,400 security teams

About
We find what was left open.
A team of security engineers who got tired of ten thousand alerts and built one list instead.
SOC 2 Type II · ISO 27001 · 1,400 security teams

About
We find what was left open.
A team of security engineers who got tired of ten thousand alerts and built one list instead.
SOC 2 Type II · ISO 27001 · 1,400 security teams

Our story
It started with one leaked key.
Palisade began in 2019 with one incident. A cloud key sat in a public repository for 212 days before anyone noticed, and three good tools had each seen a piece of it.
Nobody had the whole picture, so we built the product we needed that week: one list of what is exposed across people, devices, cloud and code, ranked by what an attacker would try first.
Today 86 of us keep that list honest for 1,400 security teams. We still measure ourselves the same way: how long a finding stays open.

- Founded
- 2019
- People
- 86
- Security teams
- 1,400
- Offices
- London, Lisbon
How we work
Three rules we hold ourselves to.
- 1Open
Show the exposure, not a dashboard
A finding names the asset, the owner and the fix. If it cannot be acted on today it does not belong on the list.
- 2Open
Read-only until you say otherwise
We connect with the least access that works. Closing a finding is always a step you approve.
- 3Open
Prove it afterwards
Every closed finding keeps its evidence, so the audit is a link and not a week of screenshots.
The team
The people who keep the list honest.
Security engineers, former auditors and designers. Small enough that the person who answers your ticket has read the code.

Ines Carvalho
Co-founder, product
Since 2019

Tom Whitlock
Co-founder, engineering
Since 2019

Amara Osei
Head of detection
Since 2020

Jonas Brandt
Head of customer security
Since 2021

Priya Menon
Compliance lead
Since 2022

Luc Fontaine
Design
Since 2022
Sample team, demo data
Where we work
Two offices, one rota.
01
London
14 Curtain Road, EC2A 3NH
Engineering and detection
02
Lisbon
Rua da Boavista 82, 1200-066
Customer security and support
03
Remote
Nine countries, one on-call rota
Follow-the-sun response
Our story
It started with one leaked key.
Palisade began in 2019 with one incident. A cloud key sat in a public repository for 212 days before anyone noticed, and three good tools had each seen a piece of it.
Nobody had the whole picture, so we built the product we needed that week: one list of what is exposed across people, devices, cloud and code, ranked by what an attacker would try first.
Today 86 of us keep that list honest for 1,400 security teams. We still measure ourselves the same way: how long a finding stays open.

- Founded
- 2019
- People
- 86
- Security teams
- 1,400
- Offices
- London, Lisbon
How we work
Three rules we hold ourselves to.
- 1Open
Show the exposure, not a dashboard
A finding names the asset, the owner and the fix. If it cannot be acted on today it does not belong on the list.
- 2Open
Read-only until you say otherwise
We connect with the least access that works. Closing a finding is always a step you approve.
- 3Open
Prove it afterwards
Every closed finding keeps its evidence, so the audit is a link and not a week of screenshots.
The team
The people who keep the list honest.
Security engineers, former auditors and designers. Small enough that the person who answers your ticket has read the code.

Ines Carvalho
Co-founder, product
Since 2019

Tom Whitlock
Co-founder, engineering
Since 2019

Amara Osei
Head of detection
Since 2020

Jonas Brandt
Head of customer security
Since 2021

Priya Menon
Compliance lead
Since 2022

Luc Fontaine
Design
Since 2022
Sample team, demo data
Where we work
Two offices, one rota.
01
London
14 Curtain Road, EC2A 3NH
Engineering and detection
02
Lisbon
Rua da Boavista 82, 1200-066
Customer security and support
03
Remote
Nine countries, one on-call rota
Follow-the-sun response
Our story
It started with one leaked key.
Palisade began in 2019 with one incident. A cloud key sat in a public repository for 212 days before anyone noticed, and three good tools had each seen a piece of it.
Nobody had the whole picture, so we built the product we needed that week: one list of what is exposed across people, devices, cloud and code, ranked by what an attacker would try first.
Today 86 of us keep that list honest for 1,400 security teams. We still measure ourselves the same way: how long a finding stays open.

- Founded
- 2019
- People
- 86
- Security teams
- 1,400
- Offices
- London, Lisbon
How we work
Three rules we hold ourselves to.
- 1Open
Show the exposure, not a dashboard
A finding names the asset, the owner and the fix. If it cannot be acted on today it does not belong on the list.
- 2Open
Read-only until you say otherwise
We connect with the least access that works. Closing a finding is always a step you approve.
- 3Open
Prove it afterwards
Every closed finding keeps its evidence, so the audit is a link and not a week of screenshots.
The team
The people who keep the list honest.
Security engineers, former auditors and designers. Small enough that the person who answers your ticket has read the code.

Ines Carvalho
Co-founder, product
Since 2019

Tom Whitlock
Co-founder, engineering
Since 2019

Amara Osei
Head of detection
Since 2020

Jonas Brandt
Head of customer security
Since 2021

Priya Menon
Compliance lead
Since 2022

Luc Fontaine
Design
Since 2022
Sample team, demo data
Where we work
Two offices, one rota.
01
London
14 Curtain Road, EC2A 3NH
Engineering and detection
02
Lisbon
Rua da Boavista 82, 1200-066
Customer security and support
03
Remote
Nine countries, one on-call rota
Follow-the-sun response
In numbers
What gets measured gets closed.
Averages across every customer over the last twelve months. Your own numbers sit on the first screen of the product.
- Mean time to detect
- 4 min
- From the moment something is exposed to the moment its owner is told.
- Measuring
- Findings closed
- 1.28M
- Closed by the person who owns the asset, not parked in a queue.
- Measuring
- Coverage
- 99.2%
- Of identities, devices, cloud accounts and repositories under watch.
- Measuring
- Security teams
- 1,400
- From ten-person start-ups to regulated groups in 31 countries.
- Measuring
Figures are sample data for this template
In numbers
What gets measured gets closed.
Averages across every customer over the last twelve months. Your own numbers sit on the first screen of the product.
- Mean time to detect
- 4 min
- From the moment something is exposed to the moment its owner is told.
- Measuring
- Findings closed
- 1.28M
- Closed by the person who owns the asset, not parked in a queue.
- Measuring
- Coverage
- 99.2%
- Of identities, devices, cloud accounts and repositories under watch.
- Measuring
- Security teams
- 1,400
- From ten-person start-ups to regulated groups in 31 countries.
- Measuring
Figures are sample data for this template
In numbers
What gets measured gets closed.
Averages across every customer over the last twelve months. Your own numbers sit on the first screen of the product.
- Mean time to detect
- 4 min
- From the moment something is exposed to the moment its owner is told.
- Measuring
- Findings closed
- 1.28M
- Closed by the person who owns the asset, not parked in a queue.
- Measuring
- Coverage
- 99.2%
- Of identities, devices, cloud accounts and repositories under watch.
- Measuring
- Security teams
- 1,400
- From ten-person start-ups to regulated groups in 31 countries.
- Measuring
Figures are sample data for this template
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected