Continuous penetration testing · Live

Always-on pen testing.
No blind spots.

Peregrine is the only platform purpose-built for continuous penetration testing. We watch your attack surface around the clock — detecting, triaging, and remediating vulnerabilities the moment they appear. No annual blind spots. No waiting for the next audit.

SOC 2 Type II ISO 27001 / 27017 Zero code storage
Trusted by security-conscious teams across finance, healthcare, transport and infrastructure
ptsb
Veracity
Qpercom
Iarnród Éireann (Irish Rail)
Met Éireann
The annual pen test problem

Your perimeter changes every hour. Your pen test shouldn't be annual.

A snapshot every twelve months catches a few headlines and misses the long tail. Peregrine treats penetration testing as a continuous control — not a once-a-year compliance event.

Pen testers don't disappear. They run inside Peregrine — augmented, faster, audit-ready.

Annual pen test Peregrine
Cadence Once or twice a year 24 / 7Continuous
Time to detect Weeks → months Minutes
Retest cost €8k–€25k per round Included
Remediation Manual ticket queue One-click AutoFix
Coverage Point-in-time snapshot Always-on, full estate
Audit evidence PDF, six weeks later Always audit-ready
Agentic detection Built-in
Typical mid-market team Saves €60k+ / yr vs annual + retests
How it works

Three steps. No security team required.

Point Peregrine at your estate. We discover, detect, and remediate — continuously. Your team gets the verdict, not the noise.

Step 01 · Discover

Map your attack surface in minutes.

Connect cloud, code, infra and APIs. Peregrine builds a live model of every external-facing asset — including the ones nobody told you about.

Step 02 · Detect

Agentic interception, around the clock.

SAST, SCA, IaC scanning and live attack-surface monitoring run continuously. AI triage cuts the noise; only real exploits reach your inbox.

Step 03 · Remediate

One-click AutoFix. Always audit-ready.

Approve a fix and Peregrine opens the PR, runs the retest and timestamps the evidence. Compliance artefacts ship themselves.

Capabilities

Built for the security team you wish you had.

Continuous scanning

Every commit. Every cloud. Every change.

SAST, SCA, IaC and DAST run on every push and every infrastructure change — not on a Tuesday in October.

AI triage

Signal, not noise.

Peregrine ranks findings by real-world exploitability. Critical paths reach the top; theoretical CVEs stay in the log.

AutoFix

One-click remediation.

For supported issues, Peregrine opens the pull request, runs the retest and closes the ticket. You stay in approval, not in YAML.

Agentic detection

Agents that hunt, not just scan.

Adversarial agents probe your estate the way a real attacker would — chaining misconfigurations a scanner would never see.

Always audit-ready

Evidence on demand.

Every scan, every fix, every retest is timestamped and signed. Pull SOC 2 / ISO / PCI / HIPAA evidence in a click.

Enterprise

On-prem, air-gapped, your rules.

Peregrine Enterprise deploys inside your perimeter. Air-gapped environments supported. Your code never leaves your network.

Proven at scale

The numbers behind a year of always-on.

1.4M+

SAST runs completed

Every line of code, every push — across customer codebases in the last twelve months.

482k

SCA scans performed

Open-source dependencies graphed, fingerprinted, and continuously rechecked against new CVEs.

92k

IaC security scans

Terraform, CloudFormation and Kubernetes manifests audited before they ever reach production.

Security & compliance

We hold ourselves to a higher standard than we hold your code.

Peregrine is built by Marino Software — twenty years delivering regulated software for finance, healthcare and the public sector. ISO 27001 / FSQS-registered. DORA-aware. Audited the way we'd audit you.

Attested
SOC 2 Type II
Continuous controls audit. Report available under NDA.
Certified
ISO 27001 & 27017
Information security management. Cloud-specific controls.
In transit
TLS 1.3
Modern ciphers only. Mutual TLS on all internal traffic.
At rest
AES-256
Customer-managed keys via AWS KMS or HSM on request.
Architecture
Zero code storage
We scan your code where it lives. Nothing persists to our infrastructure.
Frameworks
PCI · HIPAA · DORA
Evidence mapping for every common framework, generated on demand.
Customers

Sounds too good to believe? We get it.

A lot of products make bold claims. So don't take our word for it.

Peregrine turned intermittent security tests into a continuous heartbeat. We don't wait for the next audit. The audit is always on.

Simon Crisp
Simon Crisp
CEO · Veracity Trust Network
About Marino Software

Peregrine started life as our own internal tool.

Marino Software is a Dublin engineering studio that has spent twenty years building regulated software for finance, healthcare, transport and the public sector — including ptsb, RTÉ, Iarnród Éireann, Met Éireann and the Rotunda Hospital.

We’ve been building digital products since before smartphones were smart. Today we work with some of Ireland’s most respected organisations, helping them design and ship software that’s technically rigorous and genuinely easy to use.

"We built Peregrine to watch over our own codebases — and we proved it across literally hundreds of them before we shipped a line of it to a customer. Every SAST rule, every triage heuristic, every AutoFix template is forged against real production code under real audit pressure. If it works here, it works in your estate."

Keith Davey
Keith Davey
Co-founder & CTO · Marino Software

Point us at your estate.
We'll find what your last pen test missed.

Connect a repo or a domain. First scan in ten minutes. No credit card. No call required.

SOC 2 Type II · ISO 27001 · Zero code storage · TLS 1.3 · AES-256