Pragmable is an independent Parisian software house. We're building software that reads the cloud's authorization surface at the source. Two founders. One thesis. No outside capital.
We spent years on security engineering for regulated European operators — banks, telcos, healthcare infrastructure. We kept running into the same shape of problem: a rule-based tool that told us an AWS environment was compliant with a benchmark, while an attacker walked through a permission chain that benchmark hadn't heard of yet.
The gap was measurable. AWS shipped new IAM actions weekly; CIS and Security Hub caught up weeks or months later. The tools we trusted were always looking at a version of AWS that no longer existed.
Pragmable is the software house we wished existed at that job. We ingest the provider's source models directly — not benchmarks, not community wikis — and we evaluate the full six-layer decision chain the way the cloud itself does. That is the entire thesis. Everything else — the products, the research, the partnerships — follows.
Make available the tools you always needed.— how we choose what to build
Innovate solutions before you knew you needed them.
Solve problems you didn't know you had.
We build for the threat in front of us, not the dashboard we'd like to sell. Every tool we ship answers a question a security architect actually asks. No abstractions that don't pay rent. No features added because the deck looked thin. The name is the discipline.
Provenance-signed builds. Reproducible artefacts. Hosting that follows the workload — EU, US, on-prem, or SecNumCloud-ready. We own every fix ourselves: no offshore patch teams, no third-party rotations on our advisories. The product is the security posture.
We surface ugly answers plainly — even when they cost us the deal. Every advisory and every commit is signed by a named engineer. If we are wrong, you know by whom. Performative dashboards are someone else's product.
Most security tooling profiles the headlines — the famous CVEs, the ten condition keys everyone benchmarks. We instrument the full surface: every action, every condition, every chained trust path, every field that could touch a customer's risk. Coverage breadth is the point. Hype is optional.