
In the news release, Cantina Unveils The Brain to Give Autonomous Security Agents Persistent Knowledge of An Organization's Environment, issued 29-Sep-2026 by Cantina over PR Newswire, we are advised by the company that changes have been made. The complete, corrected release follows, with additional details at the end:
Cantina Unveils The Brain to Give Autonomous Security Agents Persistent Knowledge of An Organization's Environment
Shared context and memory layer connects identities, infrastructure and prior investigations, helping security agents investigate alerts with less discovery work
NEW YORK, Sept. 29, 2026 /PRNewswire/ -- Cantina today unveiled The Brain, a shared context and memory layer that gives its autonomous security agents persistent knowledge of each customer's environment. The Brain connects people and systems with operating context and prior investigations, helping Cantina's agents understand what an issue means inside a specific organization and carry relevant knowledge from one investigation into the next.
Security investigations depend on information scattered across the technology stack. As an example, an alert might point to an AWS role, GitHub repository, Okta user or production service, while the information needed to understand its significance lives in a SIEM, cloud platform, endpoint console, ticket, document or prior investigation. Security teams have to connect those records, determine who owns the affected system, understand what it supports and establish whether similar activity has appeared before.
The Brain brings that information together so Cantina's agents can begin an investigation with knowledge of the environment around an alert. Its current implementation includes identities, cloud assets such as AWS and Vercel, MDM-managed devices, repositories, vulnerabilities and the relationships between them. Agents can begin with a single entity and discover the people and systems connected to it.
The Brain combines structured records with agentic memory. Structured records connect entities through stable identifiers, such as a repository, service and its cloud resources. Agentic memory retains context that does not fit neatly into a relationship, including why a team considered a pattern benign, which operational constraint shaped a decision or what an earlier investigation established about a suspicious IP address.
"Autonomous security workers need to know far more than what appears in an alert," said Hari Mulackal, CEO and co-founder of Cantina. "Experienced security engineers build up years of knowledge about how their environment works, which systems matter, who owns them and what has happened before. The Brain gives Cantina's workers persistent access to that organizational knowledge, so they can use it every time they investigate and resolve an issue."
How The Brain Works
Knowledge about an organization is distributed across systems that were built for different purposes. SIEMs hold events and investigation data, CNAPPs map cloud resources and security posture, CMDBs record ownership and dependencies, while tickets, documents and conversations can explain why a change happened or how a team reached a decision. The Brain connects relevant records to the same person, service or asset and makes that context available to Cantina's agents.
- Connected environment map. The Brain maps identities, repositories, services, cloud resources, managed devices, vulnerabilities and other assets, along with the relationships between them.
- Structured context and memory. Stable identifiers connect technical records, while agentic memory retains investigation findings, known patterns, operational context and other knowledge that can inform future work.
- Entity reconciliation. The Brain currently uses deterministic matching, including email addresses for users and natural keys for other asset types. When a stable identifier is missing or unclear, a record can remain inferred until it is corrected or merged.
- Knowledge from investigations. Agents can write information to The Brain when configured to do so, and humans and agents can correct or merge records as more information becomes available.
- Workspace controls. Brain data resides within individual workspaces, and knowledge records support topic locks and review of proposed facts. Live source checks provide current evidence during an investigation.
The Brain Reduced Alert Triage Time and Tool Calls in an Observational Comparison
Cantina compared 40 low-severity Okta alerts across two workspaces, with 20 alerts in a Brain-enabled workspace and 20 in a comparison workspace. The Brain-enabled workspace averaged 170.8 seconds from alert creation to closure, compared with 220.4 seconds in the comparison workspace, representing 22.5% less elapsed time. It also averaged 12.15 tool calls per alert, compared with 19 in the comparison workspace, or 36.1% fewer calls.
The median time to closure was 159.5 seconds in the Brain-enabled workspace and 191 seconds in the comparison workspace. All 40 alerts were low-severity Okta alerts that were closed as benign or false positives without human action, with equal counts by alert type across the two workspaces.
To account for differences in the models used, Cantina also compared the 20 Brain-enabled alerts with the 18 comparison alerts that ran on the same model, Claude Opus 4.8. In that view, the Brain-enabled sample averaged 22.5% less elapsed time and 27.8% fewer tool calls. The evaluation was observational rather than a randomized test, and each workspace used its own alerts, history and integrations.
Giving Autonomous Security Workers Persistent Understanding
Cantina launched from stealth in July backed by $8 million in funding led by Framework Ventures, bringing its total funding to $16.5 million. The company built an autonomous security workforce that identifies security issues, drives remediation and verifies fixes before attackers can capitalize.
The Brain sits underneath that workforce as a shared source of context and memory. In one captured application-security investigation, Cantina's autonomous OffSec agent, Apex, began with a GitHub repository and used The Brain to retrieve the surrounding topology, including its load balancer, database, cache, jobs, Datadog service, other repositories and AWS resources. That context gave the agent a map of the systems that belonged in the attack path before it began deeper inve
About Cantina
Cantina is the community-powered agentic security workforce that helps organizations identify, prioritize, remediate, and verify security risks at machine speed. Built by veteran security researchers, Cantina combines autonomous security workers with a continuously evolving understanding of each customer's environment to automate security work from discovery through resolution.
For more information, visit cantina.security.
Correction: The website in the first sentence has been updated.
SOURCE Cantina
Share this article