Skip to content

Tenchi Security

Tenchi Security's Zanshin platform automates continuous, evidence-based third-party cyber risk assessment for insurers, MSSPs, and consultancies managing risk across large vendor portfolios.

Visit Website ↗ + Add to Compare
60/100Incremental Innovator

Overview

Tenchi Security is a São Paulo-based third-party cyber risk management (TPCRM) vendor, founded in October 2019 by Felipe Bouças and Alexandre Sieira. Its platform, Zanshin, tackles a problem most vendor-risk programs still handle badly: assessing the actual security posture of vendors and partners rather than trusting self-reported questionnaires. Zanshin combines external attack-surface monitoring with non-intrusive, continuous assessment of a third party’s cloud infrastructure (IaaS/PaaS/SaaS), endpoints, and identity configuration, running more than 1,000 automated checks per vendor rather than relying solely on point-in-time surveys.

The company has built real institutional credibility for a five-year-old startup: it’s a partner organization of the Center for Internet Security (CIS), and its customer base skews toward organizations that need to manage risk across a portfolio of third parties at scale — cyber insurers assessing policyholder risk, MSSPs extending the platform to their own clients, and consulting firms running due-diligence engagements. That distribution model (selling through and to organizations that in turn manage risk for many others) is a more capital-efficient path to portfolio-wide coverage than a typical single-enterprise TPRM tool.

Tenchi has raised a total of roughly $10.3M, including a $3.3M seed round led by MAYA Capital and a $7M Series A in 2024 backed by Bradesco, L4 Venture Builder, and notably Accenture as a strategic investor — a signal that a global consultancy sees enough in the product to put money behind it, not just resell it. For CISOs and risk teams, Tenchi is most relevant where the volume of third parties has outgrown manual questionnaire-based vendor risk management and continuous, evidence-based external monitoring is needed to keep pace with supply-chain risk.

Innovation Matrix Assessment

Innovation Velocity 6/10

Tenchi's Zanshin platform has expanded from external attack-surface scoring into deeper, non-intrusive assessment of a vendor's actual cloud, endpoint, and identity configuration with over 1,000 automated checks — a meaningful technical build-out for a five-year-old company, based on the company's own product documentation.

Operational Value 6/10

Founded in 2019 and still operating with institutional backing (Accenture, Bradesco) and a CIS partnership as of the most recent funding round in 2024, Tenchi shows a reasonably solid operating trajectory for its stage, though it remains a mid-sized regional player rather than a globally scaled vendor.

Market Momentum 7/10

Tenchi progressed from a $3.3M seed to a $7M Series A in under five years, with Accenture investing directly (not just partnering commercially) in the 2024 round — a credible momentum signal, since a global consultancy putting capital behind a vendor implies more conviction than a resale agreement alone.

Category Disruption 5/10

Third-party risk management is a crowded category (SecurityScorecard, BitSight, Panorays, UpGuard), and Tenchi's approach — combining external monitoring with deeper, non-intrusive internal-posture checks — is a meaningful refinement rather than a wholesale reinvention of how vendor risk is assessed.

Real-World Efficacy 5/10

Tenchi's CIS partnership and its traction with cyber insurers and MSSPs (organizations with a direct financial incentive to only use tools that actually reduce measured risk) are reasonable indirect efficacy signals. No independent benchmark study or named case study with quantified breach-reduction outcomes was found publicly.

Enduring Relevance 7/10

Supply-chain and third-party breaches remain one of the most common and costly attack vectors, and questionnaire-based vendor risk programs are widely acknowledged as inadequate on their own. Continuous, evidence-based third-party monitoring addresses a real and growing compliance and risk requirement (e.g., DORA, NIS2 third-party risk provisions in relevant markets).

Why CISOs Should Care

If your organization's risk exposure runs through a large or fast-growing portfolio of vendors and partners, Tenchi replaces slow, self-reported questionnaires with continuous, evidence-based monitoring of what those vendors' security posture actually looks like from the outside and, non-intrusively, from key configuration signals.

What Makes It Different

Tenchi sells primarily through and to organizations that manage risk across many third parties at once — insurers, MSSPs, and consultancies — rather than one-to-one to individual enterprises, and backs its scoring with continuous non-intrusive technical checks rather than questionnaires alone.

The Matrix Verdict

60/100 — INCREMENTAL INNOVATOR

A well-funded, technically credible regional leader in third-party risk management with real institutional validation (Accenture's direct investment, a CIS partnership). Worth evaluating for organizations with large third-party portfolios, though it competes in a crowded field against larger established TPRM platforms.

Editorial Note: Claims vs. Verified Findings

Independently verified: founding date, funding rounds and investor names (Crunchbase, TechCrunch-adjacent trade press, and Tenchi's own funding announcements corroborated by outlets like FinSMEs and The SaaS News), and the CIS partner listing (cisecurity.org). Vendor-sourced and not independently verified: the '1,000+ automated checks' figure and specific customer-composition claims (insurer/MSSP/consultancy mix), both drawn from Tenchi's own product and marketing pages.

Sources