All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
North Pole Security sells Workshop, a console that makes software allowlisting workable on enterprise Mac fleets, and maintains Santa, the open-source agent its founders created at Google. Google archived its repository in February 2025 and points users to the company's fork, so the founders now steward the code and community behind Mac allowlisting. The durable assets are positional and personal: the maintainer role, the community's trust, and rare macOS systems depth. A rival cannot buy these, and the company can lose them, since the agent is open source and public sources show no data flywheel. Workshop ships near-monthly on a $4 million seed with one disclosed unnamed customer and no published pricing, so a buyer bets the team holds its position until operational embedding takes over.
| Description | North Pole Security builds Workshop, an enterprise control plane for macOS allowlisting, and maintains Santa, the open-source binary and file access authorization agent its founders created at Google. | [f1] |
|---|---|---|
| Founded | 2024 | [f2] |
| HQ | New York, New York, US | [f3] |
| Latest funding | Seed, $4M (July 2025) | [f3] |
| Product | What it does |
|---|---|
| Workshop | Enterprise management platform for Santa fleets that adds automated approval workflows, package rules, tag-based policy scoping, and centralized telemetry. |
| Santa | Open-source macOS security agent providing binary authorization, file access authorization, removable media blocking, and system event logging. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Workshop and Santa control what software runs on macOS endpoints and what files running code can touch. The company is mapped to the Cyber Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The Mac-fleet buyer and the allowlisting approval burden are clear and Google's migration redirect plus the Mac Admins Podcast corroborate the problem, but the scale figures stay vendor-stated rather than independently quantified, qualitative pain that holds this at 3. [s2, s7, s10, s8] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Public documentation spans deployment, sync configuration, and rule cookbooks, and the enforcement agent is working open-source code with a visible release cadence. Google’s redirect to the company’s fork is external validation of the codebase. [s12, s11, s7, s2] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | Google archiving Santa in 2025 forces existing deployments to pick a maintained fork now, a dated buyer-side driver, and independent press covered the launch. No analyst category notes, RFP language, or budget-line evidence appears in fetched sources. [s7, s9, s4] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | The founders created Santa at Google, and Google’s repository plus the Mac Admins Podcast confirm that history independently. Prior-exit claims such as Capsule8’s sale to Sophos appear only in vendor bios among fetched sources. [s7, s10, s3] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Vendor materials describe an unnamed first customer in May 2025 and Fortune 500 design partners, evidence that on its own supports only a weak-signals score. The indirect-signal adjustment applies for the Andreessen Horowitz lead and the founders’ pedigree, which suggest traction that is real but undisclosed. [s4, s5, s8, s9] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The $4 million seed matches a design-partner stage motion, and year-one output of 12 Santa releases, three Workshop releases, and a six-person team shows visible shipping per dollar. Enterprise go-to-market beyond that stage will need more capital, and no follow-on round is disclosed. [s8, s4, s11] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Allowlisting is a recognized control and the Mac admin community places Santa without coaching, but whether Workshop is a new budget line or part of an existing EDR spend still needs vendor explanation, a contested placement that moves this to 3. [s10, s2, s9] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Maintainer control of the open-source Santa agent and Google’s public redirect to the company’s fork are distribution advantages an incumbent cannot quickly buy. The open public sync protocol, the option to run free community sync servers, and possible absorption by Apple or Mac-management incumbents hold the score at adequate. [s7, s13, s12] |
North Pole Security targets enterprises that want to block unapproved software on Macs before it runs. The company argues that detection-and-response tools act only after code executes, and that AI-assisted attackers widen the gap between execution and detection. CEO Pete Markowsky states the market case in vendor terms, claiming one in five business machines in the US now runs macOS while the industry lacks a security playbook for the platform.
The specific pain is operational rather than conceptual. Allowlisting is a well-understood control that blocks anything not approved, but on large fleets administrators historically could not keep up with approval requests. Workshop’s product page leads with that burden and promises approval paths that resolve requests in minutes through self-service, designated approvers, and peer voting, the model the founders ran across more than 100,000 Macs at Google.
Buyers outside the vendor’s control corroborate the problem space. The Mac Admins Podcast dedicated an episode to Santa’s move to North Pole Security and what it means for the tool’s users, and Google’s archived repository instructs existing Santa deployments to migrate to a maintained fork. Both confirm that an installed base depends on this control, though no fetched source quantifies the pain in incident or dollar terms. [s8, s2, s10, s7]
Santa gives the company a production-hardened enforcement layer. The open-source agent performs binary authorization, file access authorization, removable media blocking, and rich system event logging on macOS, and it has run in enterprise fleets since the founders created it at Google in 2014. The northpolesec repository now carries the active releases, and Google’s archived original directs users there.
Workshop adds the fleet-scale operations that make the agent deployable beyond expert teams. The product page documents automated approval workflows with per-department routing, package rules that approve software above the individual binary, tag-based grouping that scopes rules and approvals to teams, and telemetry that flows back to a central console. The console can also instruct Santa agents to kill running processes during incident response.
The engineering record is public to a degree few seed-stage vendors match. The documentation tree covers deployment profiles, sync configuration, and rule cookbooks, and the one-year retrospective counts 12 Santa releases and more than 470 merged pull requests in the company’s first year, a pace the founders contrast with the project’s decade at Google. Features such as Common Expression Language rules and a standalone self-approval mode shipped in the open during that period.
A split sync protocol separates the open agent from the paid platform. Santa 2025.10 introduced a private protocol whose features ship only to Workshop customers, while the public protocol that community sync servers use remains maintained. The company uses that split to monetize the control plane while keeping the agent open. [s6, s11, s7, s2, s12, s4, s13]
North Pole Security positions against a model rather than a named vendor. Its marketing contrasts prevention-first allowlisting with endpoint products that detect and respond after execution, and the funding coverage repeats that framing. The founders sell the approach Google ran internally on its own Mac fleet rather than a conventional endpoint suite.
The crowded part of the field is the Mac endpoint stack itself. Apple-management platforms such as Jamf and Iru, formerly Kandji, and EDR vendors such as CrowdStrike and Microsoft work the same Mac fleets, and any of them could present allowlisting management as a feature rather than a product. The fetched evidence does not establish the depth of those incumbent relationships on Workshop’s target fleets, so the absorption scenario is a likely competitive pressure rather than a documented one buyers will weigh.
Free alternatives to Workshop exist because Santa’s public sync protocol is open. Organizations can run the agent against community sync servers and never buy the commercial console, which caps what Workshop can charge and forces it to win on workflow depth. The counterweight is maintainer status. Google archived its repository and directed users to the founders’ fork, so the company now holds the project’s codebase, community, and roadmap, and a competitor cannot copy that position by writing software. [s2, s9, s12, s13, s7]
No fetched source names a Workshop customer. The one-year retrospective records an unnamed first customer in May 2025, the funding materials describe Fortune 500 design partners, and both claims appear only in the vendor’s own voice. Workshop officially launched on July 28, 2025, so the commercial motion is less than a year old.
The founders carry the selling in public, which fits the company’s stage. Pete Markowsky and Russell Hancox appeared together on the Mac Admins Podcast, Russell presented Workshop at MacDevOpsYVR, and the contact page lists a demo booking and a sales address with no published pricing. The Santa community is the visible distribution channel, with the #santa Mac Admins Slack channel near a thousand members and existing Santa fleets forming the natural Workshop prospect list.
Andreessen Horowitz’s seed lead is the strongest third-party commercial endorsement on record. Independent outlets covered the round, and the company says the capital goes to go-to-market acceleration. Pricing is unpublished, customers are unnamed, and no marketplace or reseller motion appears in fetched sources, so revenue evidence remains indirect. [s4, s5, s8, s9, s10]
The founders’ claim to this domain is unusually direct. The four of them worked on Santa at Google, and the about page credits Russell Hancox and Tom Burgin as the agent’s two original authors, Pete Markowsky as the leader of Google’s first-party security agent development, and Matt White as the original author and lead of Apple’s Endpoint Security Framework, the interface that all macOS security products must use.
Independent sources verify the core of that story. Google’s archived repository directs users to the company’s fork, the plainest endorsement a former employer can give, and the Mac Admins Podcast hosted Pete and Russell as the people behind Santa’s new home. The richer bio details, such as Pete co-founding Capsule8 before its sale to Sophos, appear only in the company’s own materials among fetched sources.
Hiring during the company’s first year deepened the bench. The retrospective records a director of sales engineering, a principal engineer, and a fractional CFO joining in early 2025, and the team stood at six people as of October 2025. No publicly identified go-to-market executive appears in fetched sources, so the founders run enterprise selling themselves. [s3, s7, s10, s4]
Transparency through open source is the company’s main trust asset. The enforcement agent’s code, release history, and documentation are public, the docs cover deployment, configuration profiles, and troubleshooting in depth, and recent releases added anti-tamper protections. A security reviewer can audit the software that runs on the endpoints, which few endpoint vendors offer.
Formal enterprise trust collateral is present but report-gated. The homepage footer displays an AICPA SOC 2 Type II badge that links to a Vanta trust center at trust.northpole.security, and the Workshop page says security, compliance, and SOC 2 details are available on request and that the product is built to meet enterprise procurement, so a reviewer sees the attestation up front but extracts the audit evidence through sales. No ISO certification or security questionnaire page is published. Pricing and contractual terms are also unpublished. Workshop documentation does cover API keys, audit logging, and event export, the operational controls a procurement reviewer would check first.
Company age will dominate the counterparty review. North Pole Security is a 2024 company with a seed round asking enterprises to put a privileged system-extension agent on every Mac, and reviewers will weigh vendor viability accordingly. The agent predates the company by a decade and its open-source license means it outlives any one vendor, but a young vendor without published compliance attestations should expect longer procurement cycles. [s11, s4, s15, s12, s8, s16]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Jamf | competes with | Apple-focused device management and endpoint security incumbent whose Jamf Protect runs on the same Mac fleets Workshop targets. | |
| Iru | competes with | Apple device management platform, formerly Kandji, that bundles endpoint security and compliance for the same Mac-first buyers. | |
| CrowdStrike | competes with | Endpoint detection incumbent whose macOS Falcon agent embodies the detect-and-respond model North Pole Security positions against. | |
| Microsoft | competes with | Defender for Endpoint covers macOS inside enterprise license bundles many Workshop prospects already own. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
Add analyzed competitors to compare them side by side with North Pole Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
North Pole Security earns what durability it has from people and position rather than accumulated assets. Customers buy software features, the agent carries an Apache license, the risk engine consumes third-party threat intelligence, and no certification regime mandates this product class, so a well-funded rival could rebuild the console. The hard-to-copy parts are the founders’ macOS systems depth, the maintainer role Google handed over, and a community that trusts the team, advantages a competitor cannot purchase but the company could lose. Workshop becomes structurally durable only as customers wire tags, approval workflows, and telemetry into daily operations, so deployment depth rather than feature count is the number to watch.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy Workshop’s software features through a demo-to-sales motion that sells a console license rather than judgment or accountability. No managed service, liability acceptance, or expert-review layer appears in fetched sources. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Tags mapped to IdP groups, SCIM-synced policy, accumulated rules, and telemetry history make leaving Workshop a re-plumbing project, but the public sync protocol and free community servers give a departing customer a documented exit path. No network effects or regulatory residency apply. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | A SOC 2 Type II seal sits in the homepage footer and links to a Vanta trust center, but the report is gated behind a request form and no other attestation appears in the reviewed public sources, so the assurance is table-stakes rather than a barrier. No regulatory regime mandates this product class, so a determined replacement faces procurement friction but no structural moat. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | A reliable macOS system-extension agent that enforces execution decisions in real time without breaking fleets demands years of platform-specific expertise, which this team accumulated building Santa and Apple’s Endpoint Security Framework. Adversary pressure, such as the OpenClaw blocking work, forces continuous evolution. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The company courts Fortune 500 buyers whose strict procurement reviews would slow replacement, but no named enterprise customer confirms that base yet, and the Santa community includes smaller Mac-first teams, which blends the buyer profile. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Workshop is a management platform with REST and gRPC APIs and a plugin architecture around an OS-level enforcement agent, and independent sync servers operate against Santa’s protocol. No third party builds on Workshop itself, so the product is a platform rather than depended-on infrastructure. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The agent is Apache licensed, the risk engine consumes VirusTotal and ReversingLabs verdicts, and no cross-customer telemetry flywheel or proprietary dataset is claimed in public materials. |
North Pole Security sells to organizations that already run Santa or want the allowlisting discipline it enforces, which makes the open-source installed base the company’s beachhead segment. Google archived its Santa repository in February 2025 and encourages remaining users to migrate to an actively maintained fork, naming the company’s repository as an example, so the founders’ agent is the migration target Google itself names. The contact page counts more than 1,000 members in the #santa channel on the Mac Admins Slack, a rough proxy for the practitioner community the product addresses.
Stated targets skew toward large enterprises. Pete Markowsky says the company worked hand in hand with Fortune 500 design partners, the seed announcement describes an enterprise-grade platform, and Workshop ships SCIM directory sync, management zones, and multi-party approval, controls that matter at fleet scale. The about page declares a mission of serving organizations of any size, yet the company offers no self-service signup or published entry tier, so the practical persona is a security or client-platform team managing hundreds to thousands of Macs.
Public proof of demand has not refreshed since mid-2025 and remains in the vendor’s voice. The one-year retrospective records an unnamed first customer in May 2025, the funding posts describe Fortune 500 design partners as of July 2025, and no case study, named customer, or usage milestone has appeared since. The company keeps shipping monthly through June 2026, so the staleness is specific to demand evidence rather than delivery, and fresh named accounts are the signal that would show the seed-funded sales motion converting.
Geographic and vertical focus stay implicit. The company operates from New York, and Pete states that one in five business machines in the US now runs macOS, a market-sizing figure no fetched source corroborates independently. No vertical packaging appears, though the company built package rules for Homebrew, npm, and Cargo, a feature aimed at engineering-heavy organizations whose developers install new software constantly and would swamp a manual approval queue.
The company’s core capabilities are verifiable in public code rather than marketing copy. Santa performs binary authorization, file access authorization, removable media blocking, and system event logging, and the company publishes the agent’s full source, security policy, and release history under an Apache 2.0 license. A buyer can audit the enforcement software before deploying it, and the Mac admin community can validate engineering claims against the repository instead of taking a datasheet on faith.
Workshop adds the operational layer that makes the agent manageable at fleet scale. The documentation describes execution rules across five precedence levels, package rules that allowlist entire developer ecosystems, file access rules that block infostealers from credentials and source code, tag-based policy scoped to identity-provider groups, telemetry queryable with SQL, and remediation commands that kill running processes. The risk engine screens every approval request through VirusTotal, ReversingLabs, customer-written rules, and webhook plugins, disables the approve button when any check fails, and treats timeouts as denials.
The company treats AI as a bring-your-own-model feature rather than a proprietary engine. AI Chat, shipped in March 2026, answers natural-language questions about hosts, rules, and events using customer-supplied Anthropic, OpenAI, or Google keys, runs read-only until an admin enables writes, and logs every tool call to the same audit trail as the UI and API. Public sources identify no proprietary detection model or cross-customer data asset, and the risk engine consumes third-party threat intelligence, so the durable technical asset on the record is macOS systems engineering rather than accumulated data.
Release notes from the past two quarters record category-level additions rather than polish. The company shipped package rules in January 2026, Touch ID gated execution in February, AI Chat and rebuilt telemetry in March, and sandbox profile rules with CEL audit policies in the June 2026 releases. It also publishes adversary-driven content, including a guide to blocking OpenClaw, an autonomous macOS AI agent, with layered CEL rules. That guide positions allowlisting as the control the company expects to hold up against AI-accelerated malware.
North Pole Security runs a community-led funnel with sales-assisted conversion and no self-service tier. The open-source agent is the entry point, the Santa repository lists Workshop as the official sync server in the company’s own wording, and prospects reach the company through a demo form or a sales email rather than a signup flow. The company meets buyers where Santa users already gather, in the Mac Admins community, on the project’s repository, and at Mac-focused conferences.
The founders front the public selling, which fits the company’s stage. Pete Markowsky and Russell Hancox appeared on the Mac Admins Podcast to explain Santa’s move, Russell presented Workshop at MacDevOpsYVR, and the founders announced the company’s formation at a Mac Admins conference in Sweden. The company’s earliest commercial hire was a director of sales engineering and customer success in January 2025, no quota-carrying sales organization appears in fetched sources, and that shape matches founder-led selling before repeatable proof rather than premature scale-out.
Buyers encounter Santa through channels an incumbent could not quickly buy. Google’s archive notice names the company’s repository as an actively maintained fork for remaining users, practitioners presented Santa at BSides Columbus and BSides Canberra, and the #santa Slack channel has more than 1,000 members. No cloud marketplace listing, reseller program, or MSSP motion appears in fetched sources, and because the sync protocol is public, an organization can adopt the agent through those same channels and never meet the sales motion, so the company reaches buyers it cannot bind.
Andreessen Horowitz’s seed explicitly funds go-to-market acceleration. The press release says the capital will speed go-to-market efforts and platform work, the company names Zane Lackey as its partner at the firm, and independent coverage repeats the market-entry framing. Whether the company can convert that capital into a repeatable enterprise motion before a Mac-management incumbent bundles allowlisting management is the commercial question to watch over the next few quarters.
Workshop’s pricing is not published. The site’s machine-readable page index lists no pricing page, the contact page routes pricing questions to a sales email, and every call to action leads to a demo booking, a pattern that in security products usually signals negotiated, larger deals. That posture is coherent for a seed-stage vendor courting Fortune 500 buyers, but it contradicts the stated mission of serving organizations of any size, because a small Mac fleet’s administrator cannot estimate the cost without a sales conversation.
The company also withholds its charging unit, a positioning signal buyers normally get for free. No fetched page states whether Workshop charges per endpoint, per user, or per fleet, so prospects cannot infer from the unit what the company believes they are paying for, and the deal-size signal a published unit would give is absent from the public record.
Organizations that balk at Workshop’s quote can run Santa against open-source sync servers such as Moroz, Airbnb’s Rudolph, or Zentral, so the company must price the console against a free baseline and win on approval workflow depth, the risk engine, and operational polish. The private sync protocol introduced in October 2025 is the pricing advantage, reserving advanced capabilities for paying customers while leaving the free path intact, and the founders must balance each paid-only capability against the community goodwill their distribution depends on.
Workshop deploys as managed cloud or self-hosted, a flexible posture for a company of this size. The product page offers cloud hosting with managed updates and scaling alongside a self-hosted option, integrates with Jamf and Intune for rollout, and authenticates through Okta, Azure AD, Google Workspace, OneLogin, JumpCloud, or any SAML or OIDC provider. SCIM directory sync applies changes incrementally every 60 seconds with full reconciliation hourly, so a new engineering hire’s Mac picks up the right policies within about a minute.
Santa enforces decisions at every program launch, so agent failure would block real work, and the product ships with mitigations for that risk. Multi-party approval keeps a single admin account from damaging the fleet, the risk engine fails closed on timeouts and errors, the founders have extended tamper resistance across recent releases, and a standalone mode lets end users self-approve new software where policy allows. The company also shipped Santa support for macOS 26 Tahoe more than a month before Apple released the operating system, evidence that the team tracks OS changes on Apple’s schedule.
The company ships Santa and Workshop on a near-monthly cadence and documents each release publicly. The blog records paired releases through 2026, with Santa 2026.5 and Workshop 2026.5 both announced on June 8, 2026, and the documentation covers deployment profiles, sync configuration, and migration from the archived Google agent. A buyer can read that cadence as partial reassurance, because no SLA or uptime commitment appears in fetched sources, and a vendor operating a managed control plane for an enforcement agent will eventually have to publish those.
Source transparency is the company’s strongest trust asset. The enforcement agent’s code, release history, and security policy are public under an Apache 2.0 license, the founders have hardened the agent against tampering across recent releases, and a decade of production use at Google precedes the company itself. A reviewer can audit the software that will hold execution authority over every Mac in the fleet, which closed-source endpoint vendors cannot offer.
The company displays a SOC 2 Type II attestation but gates the report. The homepage footer carries an AICPA SOC 2 Type II seal that links to a Vanta trust center at trust.northpole.security, and that portal resolves and is branded as the company’s own, so the badge is the company’s own public display rather than a third-party listing. The portal exposes no downloadable report from its landing page. It gates access behind a request form asking for first name, last name, email, company name, and a reason, so a procurement team sees only the company’s claim of the attestation and must request the report that would verify it through that channel.
A SOC 2 Type II report is table-stakes for a vendor seeking deep system privileges, and beyond it no ISO 27001, ISO 42001, HIPAA, PCI, FedRAMP, or HITRUST attestation appears. Reviewers can inspect audit trails, identity-stamped actions, and multi-party approval as operational controls, but the company is asking enterprises to grant a privileged system extension broad authority while keeping its formal assurance behind a request gate.
The AI feature shipped with a conservative security model. AI Chat runs read-only until an admin enables writes, inherits the caller’s role permissions through the same middleware as the REST and gRPC APIs, stores provider keys in AWS or GCP secret managers rather than its own database, and writes every tool call to the audit log with the user’s identity and conversation ID. A security reviewer meeting an LLM feature in an enforcement console will ask about permissions and audit first, and the company built its answers in before shipping.
Enterprise reviewers will weigh vendor viability hardest. North Pole Security is a 2024 company with one seed round, six people as of October 2025, and no publicly named customers, asking buyers to grant deep system privileges across every Mac. The agent’s open-source license means the code survives any single vendor’s failure, and the founders have operated it in production for a decade, which softens part of that review. A conservative buyer will still weigh the chance that a six-person company is acquired or runs short of capital mid-deployment.
Santa’s sync protocol is the platform surface, and the company inherited an ecosystem it did not have to build. The protocol is documented publicly with machine-readable definitions hosted on buf.build, and independent sync servers already operate against it, including Moroz, Airbnb’s Rudolph, and Zentral. The company’s repository lists Workshop first among those options and calls it the official sync server, a maintainer-granted label no competitor can claim.
Workshop exposes extension points in both directions. Customers can wire their own threat intelligence, procurement allowlists, or EDR lookups into the risk engine through webhook plugins, and they can export audit and telemetry data to Splunk, CrowdStrike, or any SIEM. AI Chat supports Anthropic, OpenAI, and Google models through the provider contract the customer already holds. The company positions Workshop alongside Jamf, Intune, and the customer’s identity provider rather than against them, a cooperative posture that lowers adoption friction for Mac-first IT teams.
With the private sync protocol, the company is testing how far it can monetize the platform without spending the open-source goodwill its distribution depends on. Since October 2025, some capabilities ship only to Workshop customers over a private protocol while the public protocol stays maintained, an explicit open-core boundary the company says funds continued open-source investment. If the founders move too much value behind that boundary, users could fork the agent or retreat to free servers, and the company would lose the maintainer standing it relies on.
Founder-to-problem fit is exact. Russell Hancox and Tom Burgin wrote the original Santa at Google, Matt White created and led Apple’s Endpoint Security Framework, the interface every macOS security product must use, and Pete Markowsky led Google’s first-party security agent development after co-founding Capsule8, with the Capsule8 sale to Sophos appearing only in the company’s own bio among fetched sources. Google’s archive notice, which names the founders’ fork as the migration target, independently corroborates the core of the story.
First-year hiring filled operating gaps rather than scaling headcount. Mark Shiozaki joined from Capsule8, Sysdig, and Red Hat as director of sales engineering and customer success, Ian Langworth came aboard as principal engineer, Lauren Pearl took the fractional CFO seat with prior Trail of Bits experience, and Royal Hansen joined as an advisor. The team stood at six people in October 2025, and no go-to-market executive appears in fetched sources, so the founders still carry enterprise selling themselves.
The execution record is public and fast. The company counts 12 Santa releases, three Workshop releases, and more than 470 merged pull requests in its first year, a pace the founders contrast with the project’s decade at Google, and the paired near-monthly releases have continued into mid-2026. The repository shows more than 2,400 commits and 20 releases, so the velocity claim is checkable rather than rhetorical. The record does not yet show the same systematic output applied to revenue, and an engineering-heavy six-person team running an enterprise motion is the capability gap to watch.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | North Pole Security homepage | official | 2026-06-11 |
| f2 | One Year of North Pole Security (company blog, October 2024 entry) | official | 2026-06-11 |
| f3 | North Pole Security seed announcement (GlobeNewswire, July 30, 2025) | press | 2026-06-11 |
| f4 | Workshop product page | official | 2026-06-11 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | North Pole Security homepage “Santa is the highly-performant, open-source macOS security agent pioneered at Google and now maintained by North Pole Security.” | official | 2026-06-11 |
| s2 | Workshop product page “Workshop makes allowlisting livable for modern Mac fleets. The same approach that protected 100,000+ Macs at Google, now an enterprise platform with automated approvals, risk intelligence, and fleet-wide visibility.” | official | 2026-06-11 |
| s3 | About Us page “Co-founded and scaled Capsule8 (enterprise cloud EDR, sold to Sophos). Led all first-party security agent development at Google, including Santa. Original author and lead of Apple's Endpoint Security Framework that all macOS security products must use.” | official | 2026-07-02 |
| s4 | One Year of North Pole Security (company blog) “We officially launched Workshop on July 28, 2025 and featured it on our site. Also, the company acquired its first customer!” | official | 2026-06-18 |
| s5 | We Raised $4M to Reimagine Endpoint Security (company blog) “We’ve worked hand-in-hand with Fortune 500 design partners to ensure Workshop is not only secure, but usable in the real world.” | official | 2026-06-11 |
| s6 | Santa documentation intro “Santa is a high-performance open-source security agent for macOS that provides binary & file-access authorization and rich system event logging.” | official | 2026-06-11 |
| s7 | Google's archived santa repository “As of 2025, Santa is no longer maintained by Google. We encourage existing users to migrate to an actively maintained fork of Santa, such as https://github.com/northpolesec/santa.” | research | 2026-06-11 |
| s8 | North Pole Security seed announcement (GlobeNewswire, July 30, 2025) “North Pole Security today announced it has raised $4 million in seed funding to deliver the first scalable, enterprise-grade endpoint protection platform for macOS, designed for proactive malware prevention.” | press | 2026-06-11 |
| s9 | Pulse 2.0 coverage of the North Pole Security seed round “Led by Andreessen Horowitz, this funding will enhance the platform and accelerate its market entry.” | press | 2026-06-11 |
| s10 | Mac Admins Podcast episode 389 on North Pole Security and Santa “Join us as we talk with Russell and Pete from North Pole about what Santa’s move means, how it’s developing in the future, and what’s coming next for this powerful Mac Security Tool.” | press | 2026-06-11 |
| s11 | North Pole Security Santa repository on GitHub | official | 2026-06-11 |
| s12 | Santa sync server documentation “Santa can be configured to synchronize with a central server, to control the rules that Santa applies, the settings that apply to the host, and to upload details about executions that have been blocked.” | official | 2026-06-11 |
| s13 | A Private Sync Protocol for Workshop (company blog) “The Santa 2025.10 release introduces a new, private sync protocol alongside the existing public protocol. This private protocol includes a limited set of features available exclusively to Workshop customers.” | official | 2026-06-11 |
| s14 | North Pole Security site documentation index | official | 2026-06-11 |
| s15 | North Pole Security Workshop page (SOC 2 details on request) “Security, compliance, and SOC 2 details available on request. Built to meet enterprise procurement.” | official | 2026-06-16 |
| s16 | North Pole Security homepage footer attestation badge (2026-07-02 fetch, alt-text manifest) “footer image /images/badges/soc2-type2.png, alt 'AICPA SOC 2 Type II, SOC for Service Organizations', linked to the Vanta trust center at trust.northpole.security” | official | 2026-07-02 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | North Pole Security homepage “Santa is the highly-performant, open-source macOS security agent pioneered at Google and now maintained by North Pole Security.” | official | 2026-06-11 |
| s2 | Workshop product page “Single sign-on: Okta, Azure AD, Google Workspace, OneLogin, JumpCloud, or any SAML/OIDC. SCIM directory sync: Incremental updates every 60 seconds and full reconciliation hourly. Cloud-hosted or self-hosted, Workshop adapts to your infrastructure requirements.” | official | 2026-07-02 |
| s3 | About Us page “Original author and lead of Apple's Endpoint Security Framework that all macOS security products must use. Last Santa lead at Google.” | official | 2026-06-11 |
| s4 | One Year of North Pole Security (company blog) “May 2025: Also, the company acquired its first customer! We've shipped 12 releases of Santa, three releases of Workshop, presented at two conferences, been featured on two podcasts, and grown the team to six people.” | official | 2026-06-18 |
| s5 | We Raised $4M to Reimagine Endpoint Security (company blog) “We’ve worked hand-in-hand with Fortune 500 design partners to ensure Workshop is not only secure, but usable in the real world.” | official | 2026-06-11 |
| s6 | A Private Sync Protocol for Workshop (company blog) “The Santa 2025.10 release introduces a new, private sync protocol alongside the existing public protocol. This private protocol includes a limited set of features available exclusively to Workshop customers.” | official | 2026-06-11 |
| s7 | North Pole Security blog index “Santa 2026.5 adds sandbox profile rules, on-demand binary upload, CEL audit policies, and CEL fallback coverage for platform binaries.” | official | 2026-06-11 |
| s8 | AI Chat feature page “Anthropic, OpenAI, and Google are all supported. Use your existing provider contract, your own usage quotas, and route long-context work to whichever model fits the job. Write operations are disabled until an admin explicitly enables read-write mode.” | official | 2026-07-02 |
| s9 | Risk Engine feature page “Every approval request is screened by VirusTotal, ReversingLabs, your custom rules, and any webhook plugins you connect. If any check fails, the approve button is disabled.” | official | 2026-06-11 |
| s10 | Contact page “1,000+ members discussing Santa and Mac security.” | official | 2026-06-11 |
| s11 | Google's archived santa repository “As of 2025, Santa is no longer maintained by Google. We encourage existing users to migrate to an actively maintained fork of Santa, such as https://github.com/northpolesec/santa.” | research | 2026-06-11 |
| s12 | North Pole Security Santa repository on GitHub “There are several commercial and open-source servers available: Workshop is the official sync server offered by North Pole Security. Moroz, a simple golang server. Rudolph (github.com/airbnb/rudolph), an AWS-based serverless sync service. Zentral, a centralized service. Apache-2.0 license” | official | 2026-07-02 |
| s13 | North Pole Security seed announcement (GlobeNewswire, July 30, 2025) “North Pole Security today announced it has raised $4 million in seed funding to deliver the first scalable, enterprise-grade endpoint protection platform for macOS, designed for proactive malware prevention. Led by Andreessen Horowitz” | press | 2026-06-11 |
| s14 | Pulse 2.0 coverage of the North Pole Security seed round “Led by Andreessen Horowitz, this funding will enhance the platform and accelerate its market entry.” | press | 2026-06-11 |
| s15 | Mac Admins Podcast episode 389 on North Pole Security and Santa “Join us as we talk with Russell and Pete from North Pole about what Santa’s move means, how it’s developing in the future, and what’s coming next for this powerful Mac Security Tool.” | press | 2026-06-11 |
| s16 | Santa sync server documentation “Santa can be configured to synchronize with a central server, to control the rules that Santa applies, the settings that apply to the host, and to upload details about executions that have been blocked.” | official | 2026-06-11 |
| s17 | North Pole Security site documentation index “This file is a machine-readable index of every public page on northpole.security, following the llmstxt.org standard.” | official | 2026-06-11 |
| s18 | North Pole Security homepage footer attestation badge (SOC 2 Type II) and trust center link “footer image /images/badges/soc2-type2.png, alt 'AICPA SOC 2 Type II, SOC for Service Organizations', linked to the Vanta trust center at trust.northpole.security” | official | 2026-06-17 |
| s19 | North Pole Security Trust Center (Vanta portal, rendered) “North Pole Security's Trust Center. Request access form with First name, Last name, Email, Company name, and a Reason dropdown, then a Request access button. No report is downloadable from the landing page.” | official | 2026-06-18 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.