Penumbra by Shadowfill

Your repository has a shadow.
Penumbra lives there.

The gap between what you've shipped and what a compliance auditor expects to find — Penumbra maps it, scores it, and tells you exactly how to close it.

Scan on demand or run automatically on every push. Penumbra maps your codebase against ISO 27001:2022, SOC 2 Type II, HIPAA, and PCI-DSS v4.0 — catching gaps before they become findings.

Start your free scan

Your code ships. Your auditor finds no surprises. Nobody panics.

Auto-scan on EnterpriseISO 27001, SOC 2, HIPAA & PCI-DSSResults iin minutes, not weeks

How it works

Most teams discover their compliance posture the week before an audit.

Penumbra makes that week irrelevant.

Run a scan on demand at any time, or upgrade to Enterprise and Penumbra triggers automatically on every push. Either way, the results surface as a living compliance report — always current, always honest.

No spreadsheets. No consultants. No surprises.

Every scan covers:
ISO 27001:2022 Annex A controls
SOC 2 Trust Services Criteria
HIPAA Security Rule safeguards
PCI-DSS v4.0 Requirements
Known package vulnerabilities
Long-term maintainability

Capabilities

Compliance that lives in the shadows

Purpose-built for engineering teams who need compliance without the noise.

Multi-Framework Coverage

Scans against ISO 27001:2022 Annex A (93 controls), all 13 SOC 2 Trust Service Criteria, HIPAA Security Rule safeguards, and PCI-DSS v4.0 Requirements — simultaneously in a single run.

All plans

Prioritised Findings

Critical, high, medium, low, and informational findings are ranked by severity so your team always works on what matters most — backed by a per-control evidence trail.

All plans

Repository-Native

Connect any private GitHub repository in seconds. A GitHub access token is required for each repository. Tokens and API keys are stored encrypted with AES-256-GCM and scoped to your organisation.

All plans

Dependency & Supply Chain Security

Every scan automatically audits your lockfile against the npm Security Advisory database and flags outdated packages by major, minor, and patch lag — delivering a scored dependency health report alongside your compliance findings.

All plans

Multi-Model AI Engine

Powered by Claude, OpenAI, and Gemini. Choose your preferred model, add your API KEY per repository — Penumbra analyses your repo structure, dependencies, and configuration files.

All plans

Auditable Evidence Trail

Every control result includes a human-readable evidence summary explaining exactly what was checked and what was found — ready to hand to an auditor.

All plans

AI Remediation Prompts

Every finding ships with a ready-to-use AI coding prompt. Copy it into GitHub Copilot, Cursor, or Claude to generate a pull request that closes the gap.

Lean+

Automated Fix Pull Requests

Turn AI remediation prompts into action with one click — Penumbra opens a real GitHub pull request with a remediation checklist for your team to review and merge.

Lean+

Team & Organisation Support

Multi-tenant organisations keep repositories and scan reports private to each team. Invite colleagues, share results, and manage compliance across your whole engineering org.

Scale+

CI/CD Ready

Drop the provided GitHub Actions workflow into your repo, configure a Scan token and run on every push to main. Results post directly to the GitHub Security tab as SARIF — no extra tooling required.

Enterprise

Coverage

Four pillars, one report

A single scan surfaces everything — across frameworks, packages, and codebase health — in a single living document.

Compliance Frameworks

ISO 27001 · SOC 2 · HIPAA · PCI-DSS

Four frameworks, one scan. ISO 27001:2022 Annex A, SOC 2 Trust Services Criteria, HIPAA Security Rule safeguards, and PCI-DSS v4.0 Requirements — scored, tracked, and explained in plain language.

Vulnerability Intelligence

Every dependency, every CVE

Every dependency, every version, every known CVE. Penumbra surfaces what your package manager doesn't tell you and tracks it over time so nothing quietly ages into a liability.

Maintainability Audit

The debt auditors now care about

Compliance isn't just about frameworks. Code that can't be maintained can't be secured. Penumbra flags the structural debt that auditors increasingly care about.

AI Remediation

Close the gap, not just find it

Every finding ships with a ready-to-use AI coding prompt. Copy it into GitHub Copilot, Cursor, or Claude to generate a pull request that closes the gap — no manual triage required.

Intelligence & Transparency

Not a checklist.
An AI compliance scanner that reads your repository.

Penumbra understands context — the difference between a hardcoded secret and a test fixture, between a missing log retention policy and a deliberate architectural choice. It reads only the three data layers that map directly to compliance controls. Nothing more.

always collected

Layer 1

Repository Structure

The complete file tree is fetched first. No file content is read at this stage — only paths. Structural signals are derived from the presence of well-known filenames.

  • All file paths (up to thousands of files)
  • Language detection from file extensions
  • Presence flags: Dockerfile, GitHub Actions, dependency manifests
  • Security and governance docs: SECURITY.md, CONTRIBUTING.md, CHANGELOG
up to 10 files, 8 KB each

Layer 2

Key Configuration Files

A curated whitelist of high-signal configuration files is fetched verbatim where present. These directly map to compliance controls and unlock findings that structural signals alone cannot surface.

  • Dependency manifests (package.json, requirements.txt, go.mod, Cargo.toml…)
  • CI/CD workflow definitions (.github/workflows/*.yml)
  • Container configs (Dockerfile, docker-compose.yml)
  • Environment template (.env.example) and SECURITY.md full text
up to 2,000 chars

Layer 3

Project README

The top-level README is read to understand project intent, architecture overview, and self-described security measures. It is truncated to keep token usage predictable.

  • Project purpose and architecture description
  • Self-documented security controls and setup instructions
  • Deployment and infrastructure notes
  • Truncated at 2,000 characters

Source code, build artifacts, and test files are never sent to the AI — only the configuration and documentation that directly map to compliance controls (ISO 27001, SOC 2, HIPAA, PCI-DSS). All content is processed in-memory and discarded after the scan completes.

The gap is waiting

The audit was always coming.
Now you're ready.

Penumbra closes the gap between the repository you have and the one your auditor expects — continuously, quietly, and without asking for a sprint.

Connect your first repository in under two minutes.
No agents. No configuration. Just push.

Start your free scan

Penumbra by Shadowfill — the invisible audit layer for engineering teams that ship.

We use cookies
We use essential cookies to remember your preferences (theme, colour scheme, sidebar state) and analytics cookies via PostHog to understand how you use the product and diagnose errors. Clerk, our authentication provider, sets session cookies required to keep you signed in.

By clicking "Accept", you agree to our use of cookies.

Learn more