Tenchi Security

Governance Risk ComplianceCloud Security also known as Tenchi

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2019
Last updated 2026-08-15

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Tenchi Security sells Zanshin, which tests the cloud, identity and endpoint settings of a large company's suppliers every day, with each supplier's permission. Its homepage leads with three recognitions: a Gartner buyer's guide, a Gartner market guide and a contribution to Verizon's 2026 breach report. Brazilian magazine Exame reported in 2021 that the founders named Cielo, XP, BTG Pactual, Telefônica and B3 as customers, and Accenture said in 2024 it would use the platform inside its managed security services. Zanshin's distinctive asset is the supplier permission its daily inside-out assessments need, and no reviewed source outside the company sizes that network or verifies the recognitions and customer roster.

Sourced Details

Description Tenchi Security sells Zanshin, a platform for reducing third-party cyber risk. With a supplier's permission it tests that supplier's cloud, endpoint, identity and SaaS accounts every day, and returns only security metadata to the customer that depends on them. [f1]
Founded 2019 [f2]
HQ São Paulo, Brazil [f2]
Latest funding Series A, $7M, announced February 2024 [f3]

Products

Product What it does
Zanshin Third-party cyber risk platform pairing external attack surface monitoring with permissioned daily checks inside a supplier's cloud, endpoint, identity and SaaS accounts.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Zanshin runs automated daily tests across a third party's cloud, endpoint, identity and SaaS accounts and reports the security metadata back to the customer that depends on them. These capabilities are mapped to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 26 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Tenchi Security names its buyer and its problem in plain terms, that annual audits and questionnaires produce self-attestation and point-in-time evidence rather than a current picture of a supplier's security. Accenture said in its February 2024 investment announcement that its own research found 51% of chief executives ranking supply chain as their second highest external risk. The reviewed sources carry no measurement of the gap from a party with no commercial tie to the company. [s1, s2, s14]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The release notes read as operating detail rather than positioning, adding scan targets across successive releases in 2025 and 2026, and reporting against CIS Controls 8.1, NIST CSF v2.0, ISO 27001:2022 and PCI DSS v4.0.1. The Center for Internet Security lists Tenchi among its certified security vendor members. The release notes link documentation pages that were not separately reviewed, and no published architecture or outside technical evaluation appears in the reviewed sources, so the mechanism behind the tests and the score stays the company's account of it. [s7, s23, s2, s22]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 Brazil's data-protection law is the dated enabler. Exame reported in October 2021 that the founders described the regulation, in force that August, as moving third-party risk management from desirable to mandatory. Recent buyer-side demand is not established in the reviewed sources, which carry the founder-reported 2021 customer roster and Accenture's 2024 announcement of its plan to use the platform in its managed security services, but do not show whether that plan became a deployment. [s10, s14, s12]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Felipe Bouças and Alexandre Sieira built and sold two security companies together before this one, and Baguete reports the acquirers independently, naming Niddel to Verizon and Cipher to Prosegur. Both then ran product organizations at Verizon by the company's account, Bouças for managed security services and Sieira for detection and response. Two in-domain exits reported outside the company put this above the single verifiable senior role that the peer anchors carry. [s11, s10, s4]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Exame reported in October 2021 that the founders named Cielo, XP, BTG Pactual, B3 and Telefônica as customers, and startups.com.br repeated that company-reported roster in February 2024. Accenture's own newsroom says it will use the platform as a component of its managed security services, which is a distribution commitment from a named party rather than a logo. The newest independently reported named customer traces to 2021, and the reviewed sources carry no case study, revenue figure or customer count, so they do not establish current commercial scale. [s10, s12, s14, s6]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 A R$18 million seed in 2021 and a R$35 million round in February 2024, reported as $7 million, is modest capital for a company selling to banks and market infrastructure. Output against it is visible in the release notes, which ship platform coverage and compliance frameworks through 2026, and Exame reported the business grew threefold in 2021 against 2020. No revenue or margin figure, and no growth figure after 2021, appears in the reviewed sources, so the efficiency itself stays unconfirmed. [s10, s11, s13, s7]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Third-party cyber risk management is a category outside Brazilian pages apply to Tenchi Security, with Baguete placing it there and LatamList echoing the company's own framing. The company markets a second label, third-party security posture management, which the Center for Internet Security listing repeats. Its analyst placements come from its own banners, so the outside confirmation that a higher score needs is not in the reviewed sources. [s11, s13, s23, s1]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 The assessed supplier gets Zanshin at no cost because the customer that depends on it pays, and that arrangement buys the read-only access into the supplier's own consoles that the outside-in view cannot reach. Assembling those permissions is potential friction for a platform vendor that could otherwise reproduce the checks. The reviewed sources do not say how many suppliers have granted them, so the friction is documented rather than sized. [s3, s2, s1]
Business Risks No source outside the company confirms its inclusion in Gartner's buyer's guide for third-party cyber-risk management tools, its listing in the Gartner market guide, or its contribution to Verizon's 2026 breach report, so the three claims that lead its homepage do not establish independent market validation…
  • No source outside the company confirms its inclusion in Gartner's buyer's guide for third-party cyber-risk management tools, its listing in the Gartner market guide, or its contribution to Verizon's 2026 breach report, so the three claims that lead its homepage do not establish independent market validation.
  • The 81% reduction in third-party vulnerabilities that the homepage attributes to customers carries no stated method or sample, so the public record does not let a buyer test the figure.
  • The newest independently reported named customer traces to 2021, and no case study, revenue figure or customer count appears in the reviewed sources, so they do not establish current commercial scale.
  • B3 appears in 2021 reporting as a customer and in 2024 reporting as an investor through the L4 Venture Builder fund, so its testimonial on the site carries an investor's interest as well as a customer's.
  • Zanshin's inside-out assessments need each supplier's consent, and the reviewed sources do not say how many suppliers have granted it, so the size of that network is unverified.
  • No certification, trust portal or audit report of Tenchi Security's own appears on the probed surfaces, so a buyer assessing its read-only access into the cloud, identity and endpoint consoles of its customers' suppliers has only the company's own control descriptions.
Problem & Market Tenchi Security sells against the distance between what a supplier says about its security and what its systems actually show. The company frames self-attestation and point-in-time sampled evidence as the failure it replaces, and it offers daily automated tests in place of annual audits and questionnaires. Brazil's data-protection law gave that pitch its opening. Exame reported in October 2021 that the founders described the regulation, in force that August, as moving third-party risk management from desirable to mandatory. The same reporting quotes the founders describing large companies as having had only limited visibility into supplier security before that shift. Outside measurement of the problem is thin in the reviewed sources. Accenture said in its February 2024 investment announcement that its own research found 51% of chief executives ranking supply chain as their second highest external risk. The homepage points at a Gartner buyer's guide, a Gartner market guide and a contribution to Verizon's 2026 breach report, and each of those is the company's own statement…

Tenchi Security sells against the distance between what a supplier says about its security and what its systems actually show. The company frames self-attestation and point-in-time sampled evidence as the failure it replaces, and it offers daily automated tests in place of annual audits and questionnaires.

Brazil's data-protection law gave that pitch its opening. Exame reported in October 2021 that the founders described the regulation, in force that August, as moving third-party risk management from desirable to mandatory. The same reporting quotes the founders describing large companies as having had only limited visibility into supplier security before that shift.

Outside measurement of the problem is thin in the reviewed sources. Accenture said in its February 2024 investment announcement that its own research found 51% of chief executives ranking supply chain as their second highest external risk. The homepage points at a Gartner buyer's guide, a Gartner market guide and a contribution to Verizon's 2026 breach report, and each of those is the company's own statement. [s1, s2, s10, s14]

Product Capabilities Zanshin connects to a supplier's own consoles and tests them every day…

Zanshin connects to a supplier's own consoles and tests them every day. The company describes automated tests across a third party's cloud, endpoints, identity and SaaS that return security metadata rather than the supplier's data, and it states that the access is read-only and cannot modify the supplier's infrastructure. Release notes through 2025 and 2026 add scan targets across successive releases, including Azure DevOps, JumpCloud, CrowdStrike Falcon and Microsoft Defender for Endpoint.

Zanshin reduces those tests to a single score. Tenchi Security says the score design was a joint project between its own engineering and data science teams and the Cyentia Institute, and that a first assessment produces a score within six hours, refreshed every six hours after that. The company rewrote the score in November 2025, saying its dataset had grown in volume and variety.

Compliance reporting and questionnaires ride alongside the tests. Zanshin reports against CIS Controls 8.1, NIST CSF v2.0, ISO 27001:2022 and PCI DSS v4.0.1, and it carries security questionnaires with a summary feature that reads uploaded evidence such as SOC 2 reports and ISO certifications. A public command-line utility talks to the same API.

The release notes link documentation pages that were not separately reviewed, so the reference material a buyer would read before an evaluation is not among the pages reviewed and the release notes carry the operating detail here. [s2, s3, s7, s8, s22]

Competitive Positioning Tenchi Security positions against a method rather than against named rivals. Its page for third parties contrasts its model with security scoring, with internal vendor security teams and with what it calls traditional third-party cyber risk management. No competitor is named on the reviewed pages. The commercial structure is where the difference gets concrete. The assessed supplier pays nothing, because the customer that depends on it buys its access, and the company says the licensing model lets a supplier opt in to a customer investing in its security. That arrangement needs the supplier's agreement, which the company describes as consent rather than audit. The reviewed sources carry no comparison of what rival products require, so they do not establish that permission-based licensing is unique to Zanshin. One feature cuts against the cooperative framing. The product offers an anonymous mode, in which the third party is unaware of the monitoring, beside a cooperative mode in which it consents to share data…

Tenchi Security positions against a method rather than against named rivals. Its page for third parties contrasts its model with security scoring, with internal vendor security teams and with what it calls traditional third-party cyber risk management. No competitor is named on the reviewed pages.

The commercial structure is where the difference gets concrete. The assessed supplier pays nothing, because the customer that depends on it buys its access, and the company says the licensing model lets a supplier opt in to a customer investing in its security. That arrangement needs the supplier's agreement, which the company describes as consent rather than audit. The reviewed sources carry no comparison of what rival products require, so they do not establish that permission-based licensing is unique to Zanshin.

One feature cuts against the cooperative framing. The product offers an anonymous mode, in which the third party is unaware of the monitoring, beside a cooperative mode in which it consents to share data. [s3, s2, s7, s1]

Go-to-Market & Traction Every customer named in independent reporting was named in 2021…

Every customer named in independent reporting was named in 2021. Exame reported in October of that year that the founders named Cielo, XP, BTG Pactual, B3 and Telefônica as customers, and startups.com.br repeated that company-reported roster in February 2024. The testimonials page attributes a quote to Ricardo Redenschi, head of cyber security and data protection at B3, and the homepage carries another attributed to Finnet.

Accenture is the newest outside signal. Its newsroom said in February 2024 that it had invested through Accenture Ventures and would use the platform as a new component of its managed security services. The company also runs a partner program aimed at cyber insurers, managed security providers and consultancies.

Proof of conversion stops there. No case study, revenue figure or customer count appears in the reviewed sources. The homepage says customers report an 81% reduction in third-party vulnerabilities within their first month, and it shows no method or sample behind that figure. [s10, s12, s14, s6, s1, s20]

Team & Credibility Felipe Bouças and Alexandre Sieira have built and sold two security companies together. Baguete reports that Bouças founded Niddel and Cipher, acquired by Verizon and Prosegur, and Exame reports the two founded both companies together. Exame reported in 2021 that the two had worked together for two decades. Both then ran product organizations at the acquirer. The company's page lists Bouças as global director of product for managed security services at Verizon and Sieira as global head of detection and response products there, which puts their post-exit work in the same market they sell into now. The bench below the founders appears only on the company's page, so the reviewed record does not independently establish its depth. That page lists a head of engineering with Apple and Google in his background, a head of customer success who was cyber chief technology officer at Santander Brasil, a chief financial officer, a sales director and a chief marketing officer. Baguete also names a third founder, Dani Dilkin, whom the leadership page does not list…

Felipe Bouças and Alexandre Sieira have built and sold two security companies together. Baguete reports that Bouças founded Niddel and Cipher, acquired by Verizon and Prosegur, and Exame reports the two founded both companies together. Exame reported in 2021 that the two had worked together for two decades.

Both then ran product organizations at the acquirer. The company's page lists Bouças as global director of product for managed security services at Verizon and Sieira as global head of detection and response products there, which puts their post-exit work in the same market they sell into now.

The bench below the founders appears only on the company's page, so the reviewed record does not independently establish its depth. That page lists a head of engineering with Apple and Google in his background, a head of customer success who was cyber chief technology officer at Santander Brasil, a chief financial officer, a sales director and a chief marketing officer. Baguete also names a third founder, Dani Dilkin, whom the leadership page does not list. [s4, s11, s10]

Trust Readiness No security assurance of Tenchi Security's own appears in the reviewed sources or on the probed surfaces. The trust and security subdomains do not resolve, the trust, security and compliance paths return 404, and the privacy policy names no certification. Stated controls stand in place of published attestations. The company says Zanshin is read-only and cannot modify a supplier's infrastructure, that it returns only the amount and type of security issues along with time-to-fix and severity metrics, and that its AI features run through third-party sub-processors under Brazil's data-protection law. A buyer has the company's description of those controls. One assurance signal comes from outside the company. The Center for Internet Security lists Tenchi among its certified security vendor members. The compliance content the product carries serves the customer, reporting against CIS Controls 8.1, NIST CSF v2.0, ISO 27001:2022 and PCI DSS v4.0.1, and it says nothing about how Tenchi Security runs its own systems…

No security assurance of Tenchi Security's own appears in the reviewed sources or on the probed surfaces. The trust and security subdomains do not resolve, the trust, security and compliance paths return 404, and the privacy policy names no certification.

Stated controls stand in place of published attestations. The company says Zanshin is read-only and cannot modify a supplier's infrastructure, that it returns only the amount and type of security issues along with time-to-fix and severity metrics, and that its AI features run through third-party sub-processors under Brazil's data-protection law. A buyer has the company's description of those controls.

One assurance signal comes from outside the company. The Center for Internet Security lists Tenchi among its certified security vendor members. The compliance content the product carries serves the customer, reporting against CIS Controls 8.1, NIST CSF v2.0, ISO 27001:2022 and PCI DSS v4.0.1, and it says nothing about how Tenchi Security runs its own systems. [s24, s8, s3, s23, s7]

Competitors Lema AI, iCOUNTER, OneTrust, Conveyor…
Company Relationship Note Compare
Lema AI competes with Competes for the third-party risk budget Tenchi Security sells into. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
iCOUNTER adjacent Sells third-party cyber risk intelligence to the same buyer, on a different mechanism than permissioned assessment.
OneTrust adjacent Carries third-party risk inside a wider governance and privacy suite rather than as the whole product. N/AWe scored these companies at different scopes, so the totals measure different things.
Conveyor adjacent Works the security questionnaire exchange that Zanshin also automates. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Tenchi Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Tenchi Security's supplier permissions are harder for a rival to earn than its software is to build. The four compliance formats are public, so they do not distinguish Zanshin, and a rival would still have to earn suppliers' permission to connect to their consoles. No certification of Tenchi Security's own appears on the probed surfaces, so the record shows no compliance credential that would slow a qualified rival. The reviewed record documents the permission mechanism without sizing the supplier network.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 2/3 Tenchi Security staffs a remediation team that meets the suppliers Zanshin flags, walks them through open alerts and gives them expert guidance on fixing the issues. That expert work sits inside the offer rather than beside it as an optional service, so code and expertise blend at the middle level. Accountability for the fix stays with the supplier's own team.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 A customer accumulates monitored scan targets across cloud, identity and endpoint consoles and role-based access control assignments inside the platform, and supplier onboarding is cooperative rather than unilateral. Those are the data history, integrations and learned workflows of the middle level. The reviewed record does not establish whether those artifacts are portable, whether suppliers would need to re-onboard, or what a migration would cost.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 No certification, trust portal or audit report of Tenchi Security's own appears on the probed surfaces, and the privacy policy names none. Reporting a customer's posture against CIS Controls, NIST CSF, ISO 27001 and PCI DSS helps that customer comply and imposes no requirement a replacement would have to satisfy.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 2/3 Reading a supplier's cloud, identity, endpoint and SaaS consoles through read-only access, with least-privilege scopes documented for the Microsoft 365, Azure DevOps and JumpCloud integrations, then reducing their findings to one score that refreshes every six hours, is non-trivial integration with moderate algorithmic depth. Tenchi Security brought in the Cyentia Institute for the score design, which is a description of the work rather than evidence of the years of specialized expertise the top level asks for. The reviewed record contains no patent, published method or technical evaluation.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Exame reported a founder-supplied roster of five named Brazilian enterprises, Accenture's announcement describes Tenchi's clients as leading financial, health, telecommunication and insurance institutions, and the testimonials page attributes a quote to the head of cyber security and data protection at B3. Those are regulated enterprises, the class this rung names. Accenture's decision to carry the platform into its managed security services points at the same buyer.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Zanshin runs its own console and dashboards while also exposing an API that a command-line utility and a software development kit consume, so it carries platform surface alongside application features. The reviewed record shows no application depending on it at runtime and names no consumer of its data.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 2/3 A cross-customer record accumulates from the daily tests, and the company acts on it, rewriting the score in November 2025 on the strength of a dataset it says grew in volume and variety, and benchmarking each customer against the organizations that score an A. That is an accumulated data advantage a funded rival could rebuild by earning the same permissions. The reviewed record does not size the dataset and names no exclusive input behind it.
Strategic Market Segmentation Tenchi Security's reported customers concentrate in Brazilian financial services and telecoms…

Tenchi Security's reported customers concentrate in Brazilian financial services and telecoms. Exame reported in October 2021 that the founders named Cielo, XP, BTG Pactual, Telefônica and B3 as customers, and the testimonials page carries a quote from the head of cyber security and data protection at B3. Its own leadership page describes four years of work with major banks.

The product has two sides, and each side is a different segment. On one side is the large company that buys the licence, and on the other is a supplier that gets access at no cost because that customer pays for it. The company aims material at both, with one page for buyers and another that tells suppliers what the relationship asks of them.

Reach outside Brazil is stated rather than shown. Accenture's 2024 announcement placed the platform inside its managed security services offering, and the privacy policy names Mexican and European data protection law alongside Brazil's. No customer outside Brazil appears in the reviewed sources.

Product Capabilities & AI Advantages Zanshin reads a supplier's own security consoles with that supplier's permission. The company describes automated daily tests across cloud, endpoint, identity and SaaS accounts that return security metadata rather than the supplier's data, and it states the access is read-only and cannot modify the supplier's infrastructure. Release notes through 2025 and 2026 add platforms one at a time, including Azure DevOps, JumpCloud, CrowdStrike Falcon and Microsoft Defender for Endpoint. The score is the part with a data story behind it. Tenchi Security says its engineering and data science teams designed it with the Cyentia Institute, that a first assessment returns a score within six hours, and that scores refresh every six hours after that. In November 2025 the company published a new security score, saying its own dataset had grown in volume and variety. The dashboard compares a customer against the organizations that score an A. AI appears as a feature rather than as the product. A summary tool reads evidence a supplier uploads with a questionnaire, such as SOC 2 reports and ISO certifications, and checks whether it supports the answers given. The privacy policy says those AI features run through third-party sub-processors. The reviewed sources give no way to check the claim the vendor leads with. Its homepage says customers report an 81% reduction in third-party vulnerabilities within their first month, and no method, sample or outside measurement of that figure appears in the reviewed sources…

Zanshin reads a supplier's own security consoles with that supplier's permission. The company describes automated daily tests across cloud, endpoint, identity and SaaS accounts that return security metadata rather than the supplier's data, and it states the access is read-only and cannot modify the supplier's infrastructure. Release notes through 2025 and 2026 add platforms one at a time, including Azure DevOps, JumpCloud, CrowdStrike Falcon and Microsoft Defender for Endpoint.

The score is the part with a data story behind it. Tenchi Security says its engineering and data science teams designed it with the Cyentia Institute, that a first assessment returns a score within six hours, and that scores refresh every six hours after that. In November 2025 the company published a new security score, saying its own dataset had grown in volume and variety. The dashboard compares a customer against the organizations that score an A.

AI appears as a feature rather than as the product. A summary tool reads evidence a supplier uploads with a questionnaire, such as SOC 2 reports and ISO certifications, and checks whether it supports the answers given. The privacy policy says those AI features run through third-party sub-processors.

The reviewed sources give no way to check the claim the vendor leads with. Its homepage says customers report an 81% reduction in third-party vulnerabilities within their first month, and no method, sample or outside measurement of that figure appears in the reviewed sources.

Sales Engagement & Go-to-Market Every customer named in independent reporting was named in 2021, so those sources do not establish current customer traction…

Every customer named in independent reporting was named in 2021, so those sources do not establish current customer traction. Exame reported that October on Cielo, XP, BTG Pactual, Telefônica and B3, and startups.com.br repeated the roster in February 2024. The homepage and testimonials pages add quotes attributed to named people at B3 and at Finnet, a supplier on the other side of the model.

Accenture supplies the newest outside evidence. Its newsroom said in February 2024 that it had invested through Accenture Ventures and would use the platform as a new component of its managed security services, which is a distribution route rather than a logo. The partner program also courts cyber insurers, managed security providers and consultancies.

Demand generation runs through the company's own publishing. Its site carries a newsletter, a podcast and an annual report on third-party risk, plus an analysis of Verizon's 2026 breach findings that says Tenchi Security contributed a dataset to that report. The reviewed sources contain no case study, no revenue figure and no customer count, so current commercial scale remains unestablished.

Pricing Model The buyer pays for its suppliers' access as well as its own…

The buyer pays for its suppliers' access as well as its own. Tenchi Security tells suppliers their access is paid for completely by their customers, and it frames that as aligning both sides on the same outcome. A supplier therefore evaluates a product it will not be billed for.

Exame described the charging model in 2021. It reported an annual fee charged to large companies for monitoring the network of companies in their ecosystem, with smaller companies charged directly, and prices varying with the size of the environment monitored.

No figure sits behind that model in the reviewed sources. No pricing page appears among the reviewed pages, and no tier, list price or worked example appears anywhere in them. A buyer can describe the shape of a bill and not its size.

Product Delivery & Operations Onboarding asks a supplier for read-only access…

Onboarding asks a supplier for read-only access. The company states that Zanshin is read-only and cannot modify a supplier's infrastructure, and that what reaches the customer is the amount and type of security issues along with time-to-fix and severity metrics. A first score arrives within six hours, and scores refresh every six hours after that.

Operational control shows up in the product's own release history. Tenchi Security shipped role-based access control in October 2025 and dates each change it publishes, which gives a buyer a running record of what the platform gained and when.

Zanshin exposes an API used by a public command-line utility and a Python software development kit that Tenchi Security publishes on its own GitHub organization. No hosted documentation site for that API appears in the reviewed sources, so a prospective integrator has the public utility and SDK as its implementation references.

Earning Customers' Trust No security assurance of Tenchi Security's own appears in the reviewed sources or on the probed surfaces. The trust and security subdomains do not resolve, the trust, security and compliance paths return 404, and the privacy policy names no certification. That gap sits under a product that holds read-only access into other companies' cloud, identity and endpoint consoles. Stated controls stand in place of published attestations. The company says Zanshin is read-only and cannot modify a supplier's infrastructure, that it returns only the amount and type of security issues along with time-to-fix and severity metrics, and that its AI features run through third-party sub-processors under Brazil's data protection law. One assurance signal comes from outside the company. The Center for Internet Security lists Tenchi among its certified security vendor members. The compliance content the product carries serves the customer, reporting against CIS Controls 8.1, NIST CSF v2.0, ISO 27001:2022 and PCI DSS v4.0.1, and it says nothing about how Tenchi Security runs its own systems…

No security assurance of Tenchi Security's own appears in the reviewed sources or on the probed surfaces. The trust and security subdomains do not resolve, the trust, security and compliance paths return 404, and the privacy policy names no certification. That gap sits under a product that holds read-only access into other companies' cloud, identity and endpoint consoles.

Stated controls stand in place of published attestations. The company says Zanshin is read-only and cannot modify a supplier's infrastructure, that it returns only the amount and type of security issues along with time-to-fix and severity metrics, and that its AI features run through third-party sub-processors under Brazil's data protection law.

One assurance signal comes from outside the company. The Center for Internet Security lists Tenchi among its certified security vendor members. The compliance content the product carries serves the customer, reporting against CIS Controls 8.1, NIST CSF v2.0, ISO 27001:2022 and PCI DSS v4.0.1, and it says nothing about how Tenchi Security runs its own systems.

Platform Strategy & Ecosystem Positioning Zanshin sits between two organizations rather than inside one…

Zanshin sits between two organizations rather than inside one. The company calls it a two-sided security communication platform and says it gives a supplier cloud, SaaS and attack-surface posture management without exposing that supplier's private information to its customers. The follower and following model in the release notes is that structure made concrete.

Its ecosystem work runs through channels rather than through an app marketplace. The partner program targets cyber insurers, managed security providers, consultancies and technology vendors, and the company's own funding announcement said Accenture clients would get access. No cloud marketplace listing appears in the reviewed sources.

What Zanshin consumes are other vendors' consoles. Scan target types added across 2025 and 2026 include Azure DevOps, JumpCloud, CrowdStrike Falcon and Microsoft Defender for Endpoint, and the release notes date each addition.

Team & Execution Capability Felipe Bouças and Alexandre Sieira built and sold two security companies before this one. Baguete reports that Bouças founded Niddel and Cipher, acquired by Verizon and Prosegur, and the company's page gives Sieira the co-founder title at both. Exame reported in 2021 that the two had worked together for two decades. Both also held product roles at the acquirer, which puts their post-exit work in the market they sell into now. The company lists Bouças as global director of product for managed security services at Verizon and Sieira as global head of detection and response products there. The bench below them appears only on the company's page, so the reviewed record does not independently establish its depth. That page lists a head of engineering with Apple and Google in his background, a head of customer success who was cyber chief technology officer at Santander Brasil, a chief financial officer, a sales director and a chief marketing officer. Baguete also names a third founder, Dani Dilkin, whom the leadership page does not list. The company hires remotely and says its team is spread across the globe. Exame reported a plan in 2021 to grow from 10 people to between 50 and 60, and the reviewed sources record no headcount since, so the current team scale is not established…

Felipe Bouças and Alexandre Sieira built and sold two security companies before this one. Baguete reports that Bouças founded Niddel and Cipher, acquired by Verizon and Prosegur, and the company's page gives Sieira the co-founder title at both. Exame reported in 2021 that the two had worked together for two decades.

Both also held product roles at the acquirer, which puts their post-exit work in the market they sell into now. The company lists Bouças as global director of product for managed security services at Verizon and Sieira as global head of detection and response products there.

The bench below them appears only on the company's page, so the reviewed record does not independently establish its depth. That page lists a head of engineering with Apple and Google in his background, a head of customer success who was cyber chief technology officer at Santander Brasil, a chief financial officer, a sales director and a chief marketing officer. Baguete also names a third founder, Dani Dilkin, whom the leadership page does not list.

The company hires remotely and says its team is spread across the globe. Exame reported a plan in 2021 to grow from 10 people to between 50 and 60, and the reviewed sources record no headcount since, so the current team scale is not established.

Sources

Company Detail Sources (3)
Id Source Tier Accessed
f1 Tenchi Security: Why Zanshin official 2026-08-15
f2 Baguete: Tenchi capta R$ 35 milhões press 2026-08-15
f3 LatamList: Tenchi Security raises $7M Series A to accelerate growth press 2026-08-15
Profile Analysis Sources (20)
Id Source Tier Accessed
s1 Tenchi Security homepage official 2026-08-15
s2 Tenchi Security: Why Zanshin official 2026-08-15
s3 Tenchi Security: Zanshin for third parties official 2026-08-15
s4 Tenchi Security: Meet Tenchi leadership page official 2026-08-15
s5 Tenchi Security: Accelerating the business official 2026-08-15
s6 Tenchi Security: client testimonials official 2026-08-15
s7 Tenchi Security: Zanshin release notes official 2026-08-15
s8 Tenchi Security: privacy policy official 2026-08-15
s10 Exame INSIGHT: Tenchi, startup de segurança em nuvem, capta R$ 18 milhões (Portuguese) press 2026-08-15
s11 Baguete: Tenchi capta R$ 35 milhões (Portuguese) press 2026-08-15
s12 Startups: Bradesco, L4 e Accenture investem R$ 35M na Tenchi (Portuguese) press 2026-08-15
s13 LatamList: Tenchi Security raises $7M Series A to accelerate growth press 2026-08-15
s14 Accenture newsroom: Accenture invests in Tenchi Security (investor announcement) official 2026-08-15
s17 Tenchi Security: Series A announcement, February 2024 official 2026-08-15
s18 Tenchi Security: analysis of the Verizon 2026 breach report official 2026-08-15
s19 Tenchi Security: careers official 2026-08-15
s20 Tenchi Security: partner program official 2026-08-15
s22 GitHub: the tenchi-security organization page official 2026-08-15
s23 Center for Internet Security: Tenchi partner listing research 2026-08-15
s24 Trust probe 2026-08-15: no trust or security subdomain resolves, a control subdomain rules out wildcard DNS, /trust /security /compliance 404, no cert in policy official 2026-08-15
Deep-Dive Sources (20)
Id Source Tier Accessed
s1 Tenchi Security homepage official 2026-08-15
s2 Tenchi Security: Why Zanshin official 2026-08-15
s3 Tenchi Security: Zanshin for third parties official 2026-08-15
s4 Tenchi Security: Meet Tenchi leadership page official 2026-08-15
s5 Tenchi Security: Accelerating the business official 2026-08-15
s6 Tenchi Security: client testimonials official 2026-08-15
s7 Tenchi Security: Zanshin release notes official 2026-08-15
s8 Tenchi Security: privacy policy official 2026-08-15
s10 Exame INSIGHT: Tenchi, startup de segurança em nuvem, capta R$ 18 milhões (Portuguese) press 2026-08-15
s11 Baguete: Tenchi capta R$ 35 milhões (Portuguese) press 2026-08-15
s12 Startups: Bradesco, L4 e Accenture investem R$ 35M na Tenchi (Portuguese) press 2026-08-15
s13 LatamList: Tenchi Security raises $7M Series A to accelerate growth press 2026-08-15
s14 Accenture newsroom: Accenture invests in Tenchi Security (investor announcement) official 2026-08-15
s17 Tenchi Security: Series A announcement, February 2024 official 2026-08-15
s18 Tenchi Security: analysis of the Verizon 2026 breach report official 2026-08-15
s19 Tenchi Security: careers official 2026-08-15
s20 Tenchi Security: partner program official 2026-08-15
s22 GitHub: the tenchi-security organization page official 2026-08-15
s23 Center for Internet Security: Tenchi partner listing research 2026-08-15
s24 Trust probe 2026-08-15: no trust or security subdomain resolves, a control subdomain rules out wildcard DNS, /trust /security /compliance 404, no cert in policy official 2026-08-15

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.