STAR Registry Listing for
Serpentine
Serpentine
Serpentine is a unified Security Operating System consolidating continuous detection, automated hardening, controlled exploit verification, and compliance governance onto a single shared data layer. Operated by SPNT DOOEL Skopje on EU infrastructure , Serpentine serves security teams that have outgrown the integration overhead of point tools.
The service comprises four modules:
- Odbrana — continuous detection across web, API, infrastructure, and cloud assets
- Postava — automated Linux host hardening with continuous drift monitoring
- Napad — bounded, auditable exploit verification
- Regulativa — continuous compliance governance across 35 frameworks and 3,144 obligations (SOC 2, ISO 27001, PCI DSS, GDPR, NIS2, DORA, CMMC, NIST CSF, HIPAA)
…and three intelligence layers: OSINT enrichment from external sources, Operational Telemetry validating cloud-audit and identity controls, and Decision Intelligence producing evidence-grounded analysis where every claim cites the substrate records it derives from.
Serpentine is delivered across four tiers — Free, Commercial, Enterprise, Sovereign. The Sovereign tier enforces EU-only LLM inference and offers a self-hosted LLM option for regulated public-sector and financial-services buyers (DORA, NIS2). Data residency is EU-default.
SOC 2 Type II audit is in progress (target Q4 2026). Annual independent penetration testing is conducted; summaries available under NDA.

Listed Since: 05/14/2026
STAR Level 1
Self-Assessment & Partner-Provided

CAIQ Self-assessment v4.0.3
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Created or renewed about 14 hours ago, on May 14, 2026.