Your repository has a shadow.
Penumbra lives there.
The gap between what you've shipped and what a compliance auditor expects to find — Penumbra maps it, scores it, and tells you exactly how to close it.
Scan on demand or run automatically on every push. Penumbra maps your codebase against ISO 27001:2022, SOC 2 Type II, HIPAA, and PCI-DSS v4.0 — catching gaps before they become findings.
Your code ships. Your auditor finds no surprises. Nobody panics.
$ penumbra scan --repository=my-app
→ Mapping your repository shadow...
✓ 847 files indexed across 12 layers
✓ 19 configuration surfaces mapped
ISO 27001:2022 Annex A...
✓ A.5 Policies PASS
⚠ A.9 Access Control 2 gaps
✗ A.10 Cryptography not configured
SOC 2 Trust Services...
✓ CC6 Logical Access PASS
⚠ CC7 System Operations 1 gap
PCI-DSS v4.0 Requirements...
✓ Req 6 Secure Software PASS
⚠ Req 7 Access Control 1 gap
312 dependencies audited...
✗ lodash@4.17.20 HIGH CVE-2021-23337
Penumbra report ready — 6 gaps found.
How it works
Most teams discover their compliance posture the week before an audit.
Penumbra makes that week irrelevant.
Run a scan on demand at any time, or upgrade to Enterprise and Penumbra triggers automatically on every push. Either way, the results surface as a living compliance report — always current, always honest.
No spreadsheets. No consultants. No surprises.
Capabilities
Compliance that lives in the shadows
Purpose-built for engineering teams who need compliance without the noise.
Multi-Framework Coverage
Scans against ISO 27001:2022 Annex A (93 controls), all 13 SOC 2 Trust Service Criteria, HIPAA Security Rule safeguards, and PCI-DSS v4.0 Requirements — simultaneously in a single run.
All plansPrioritised Findings
Critical, high, medium, low, and informational findings are ranked by severity so your team always works on what matters most — backed by a per-control evidence trail.
All plansRepository-Native
Connect any private GitHub repository in seconds. A GitHub access token is required for each repository. Tokens and API keys are stored encrypted with AES-256-GCM and scoped to your organisation.
All plansDependency & Supply Chain Security
Every scan automatically audits your lockfile against the npm Security Advisory database and flags outdated packages by major, minor, and patch lag — delivering a scored dependency health report alongside your compliance findings.
All plansMulti-Model AI Engine
Powered by Claude, OpenAI, and Gemini. Choose your preferred model, add your API KEY per repository — Penumbra analyses your repo structure, dependencies, and configuration files.
All plansAuditable Evidence Trail
Every control result includes a human-readable evidence summary explaining exactly what was checked and what was found — ready to hand to an auditor.
All plansAI Remediation Prompts
Every finding ships with a ready-to-use AI coding prompt. Copy it into GitHub Copilot, Cursor, or Claude to generate a pull request that closes the gap.
Lean+Automated Fix Pull Requests
Turn AI remediation prompts into action with one click — Penumbra opens a real GitHub pull request with a remediation checklist for your team to review and merge.
Lean+Team & Organisation Support
Multi-tenant organisations keep repositories and scan reports private to each team. Invite colleagues, share results, and manage compliance across your whole engineering org.
Scale+CI/CD Ready
Drop the provided GitHub Actions workflow into your repo, configure a Scan token and run on every push to main. Results post directly to the GitHub Security tab as SARIF — no extra tooling required.
EnterpriseCoverage
Four pillars, one report
A single scan surfaces everything — across frameworks, packages, and codebase health — in a single living document.
Compliance Frameworks
ISO 27001 · SOC 2 · HIPAA · PCI-DSS
Four frameworks, one scan. ISO 27001:2022 Annex A, SOC 2 Trust Services Criteria, HIPAA Security Rule safeguards, and PCI-DSS v4.0 Requirements — scored, tracked, and explained in plain language.
Vulnerability Intelligence
Every dependency, every CVE
Every dependency, every version, every known CVE. Penumbra surfaces what your package manager doesn't tell you and tracks it over time so nothing quietly ages into a liability.
Maintainability Audit
The debt auditors now care about
Compliance isn't just about frameworks. Code that can't be maintained can't be secured. Penumbra flags the structural debt that auditors increasingly care about.
AI Remediation
Close the gap, not just find it
Every finding ships with a ready-to-use AI coding prompt. Copy it into GitHub Copilot, Cursor, or Claude to generate a pull request that closes the gap — no manual triage required.
Intelligence & Transparency
Not a checklist.
An AI compliance scanner that reads your repository.
Penumbra understands context — the difference between a hardcoded secret and a test fixture, between a missing log retention policy and a deliberate architectural choice. It reads only the three data layers that map directly to compliance controls. Nothing more.
Layer 1
Repository Structure
The complete file tree is fetched first. No file content is read at this stage — only paths. Structural signals are derived from the presence of well-known filenames.
- All file paths (up to thousands of files)
- Language detection from file extensions
- Presence flags: Dockerfile, GitHub Actions, dependency manifests
- Security and governance docs: SECURITY.md, CONTRIBUTING.md, CHANGELOG
Layer 2
Key Configuration Files
A curated whitelist of high-signal configuration files is fetched verbatim where present. These directly map to compliance controls and unlock findings that structural signals alone cannot surface.
- Dependency manifests (package.json, requirements.txt, go.mod, Cargo.toml…)
- CI/CD workflow definitions (.github/workflows/*.yml)
- Container configs (Dockerfile, docker-compose.yml)
- Environment template (.env.example) and SECURITY.md full text
Layer 3
Project README
The top-level README is read to understand project intent, architecture overview, and self-described security measures. It is truncated to keep token usage predictable.
- Project purpose and architecture description
- Self-documented security controls and setup instructions
- Deployment and infrastructure notes
- Truncated at 2,000 characters
Source code, build artifacts, and test files are never sent to the AI — only the configuration and documentation that directly map to compliance controls (ISO 27001, SOC 2, HIPAA, PCI-DSS). All content is processed in-memory and discarded after the scan completes.
The gap is waiting
The audit was always coming.
Now you're ready.
Penumbra closes the gap between the repository you have and the one your auditor expects — continuously, quietly, and without asking for a sprint.
Connect your first repository in under two minutes.
No agents. No configuration. Just push.
Penumbra by Shadowfill — the invisible audit layer for engineering teams that ship.