Peregrine turned intermittent security tests into a continuous heartbeat. We don't wait for the next audit. The audit is always on.
Always-on pen testing.
No blind spots.
Peregrine is the only platform purpose-built for continuous penetration testing. We watch your attack surface around the clock — detecting, triaging, and remediating vulnerabilities the moment they appear. No annual blind spots. No waiting for the next audit.





Your perimeter changes every hour. Your pen test shouldn't be annual.
A snapshot every twelve months catches a few headlines and misses the long tail. Peregrine treats penetration testing as a continuous control — not a once-a-year compliance event.
Pen testers don't disappear. They run inside Peregrine — augmented, faster, audit-ready.
| Annual pen test | Peregrine | |
|---|---|---|
| Cadence | Once or twice a year | 24 / 7Continuous |
| Time to detect | Weeks → months | Minutes |
| Retest cost | €8k–€25k per round | Included |
| Remediation | Manual ticket queue | One-click AutoFix |
| Coverage | Point-in-time snapshot | Always-on, full estate |
| Audit evidence | PDF, six weeks later | Always audit-ready |
| Agentic detection | — | Built-in |
Three steps. No security team required.
Point Peregrine at your estate. We discover, detect, and remediate — continuously. Your team gets the verdict, not the noise.
Map your attack surface in minutes.
Connect cloud, code, infra and APIs. Peregrine builds a live model of every external-facing asset — including the ones nobody told you about.
Agentic interception, around the clock.
SAST, SCA, IaC scanning and live attack-surface monitoring run continuously. AI triage cuts the noise; only real exploits reach your inbox.
One-click AutoFix. Always audit-ready.
Approve a fix and Peregrine opens the PR, runs the retest and timestamps the evidence. Compliance artefacts ship themselves.
Built for the security team you wish you had.
Every commit. Every cloud. Every change.
SAST, SCA, IaC and DAST run on every push and every infrastructure change — not on a Tuesday in October.
Signal, not noise.
Peregrine ranks findings by real-world exploitability. Critical paths reach the top; theoretical CVEs stay in the log.
One-click remediation.
For supported issues, Peregrine opens the pull request, runs the retest and closes the ticket. You stay in approval, not in YAML.
Agents that hunt, not just scan.
Adversarial agents probe your estate the way a real attacker would — chaining misconfigurations a scanner would never see.
Evidence on demand.
Every scan, every fix, every retest is timestamped and signed. Pull SOC 2 / ISO / PCI / HIPAA evidence in a click.
On-prem, air-gapped, your rules.
Peregrine Enterprise deploys inside your perimeter. Air-gapped environments supported. Your code never leaves your network.
The numbers behind a year of always-on.
SAST runs completed
Every line of code, every push — across customer codebases in the last twelve months.
SCA scans performed
Open-source dependencies graphed, fingerprinted, and continuously rechecked against new CVEs.
IaC security scans
Terraform, CloudFormation and Kubernetes manifests audited before they ever reach production.
We hold ourselves to a higher standard than we hold your code.
Peregrine is built by Marino Software — twenty years delivering regulated software for finance, healthcare and the public sector. ISO 27001 / FSQS-registered. DORA-aware. Audited the way we'd audit you.
Sounds too good to believe? We get it.
A lot of products make bold claims. So don't take our word for it.
Peregrine started life as our own internal tool.
Marino Software is a Dublin engineering studio that has spent twenty years building regulated software for finance, healthcare, transport and the public sector — including ptsb, RTÉ, Iarnród Éireann, Met Éireann and the Rotunda Hospital.
We’ve been building digital products since before smartphones were smart. Today we work with some of Ireland’s most respected organisations, helping them design and ship software that’s technically rigorous and genuinely easy to use.
"We built Peregrine to watch over our own codebases — and we proved it across literally hundreds of them before we shipped a line of it to a customer. Every SAST rule, every triage heuristic, every AutoFix template is forged against real production code under real audit pressure. If it works here, it works in your estate."
Point us at your estate.
We'll find what your last pen test missed.
Connect a repo or a domain. First scan in ten minutes. No credit card. No call required.