Puck is a posture and investigation layer for IR and detection engineering teams. One Rust binary on every endpoint - macOS, Linux, Windows. Read-only by design: no kernel driver, no write paths, no fleet-write capability anywhere in the architecture. Install Friday. By Monday, most teams have surfaced plaintext credentials, long-lived AWS keys, OAuth tokens cached in dotfiles, forgotten admin paths - already in the environment, never previously visible. Three modes, one product. Continuous understanding. Puck holds a live model of every host: credentials, processes, configs, what changed since yesterday. Most IR questions are answered without waking an LLM. Calibrated detection. Patterns Puck has confirmed enough times across your fleet compile into deterministic checks tuned to your environment. Not a vendor's detection pack - the patterns your fleet actually produced. Investigations. Ask in natural language, or pipe in a signal (CVE drop, leaked token, threat-intel tip). Puck plans, agents execute, structured findings return.
| Website | https://puck.security |
| Employees | 1 (0 on RocketReach) |
| Founded | 2026 |
| Industry | Information Services |
Looking for a particular puck.security employee's phone or email?