pivt desktop

The investigation, in one window.

A native workbench for security work. Your agent runs the searches and they open as real tabs you can re-run. The notebook writes itself. Local analysis stays local. And the whole thing lands on the case when you're done.

macOS Windows Paid plans
What it is

A workbench, not a chat window.

Most analysts already work with an agent in a terminal. It's fast, and everything it does disappears the moment the scrollback rolls. pivt desktop keeps the speed and gives the work somewhere to live: tabs you can go back to, a record that writes itself, and a case at the end of it.

01 · Searches

Real tabs, not transcripts.

Every search the agent runs opens as an actual search in your workspace. Re-run it, widen the window, pivot off a field. If you can't check the work yourself, you're taking its word for it.

02 · Record

The notebook writes itself.

Every query, tool call and conclusion is recorded as the investigation happens. Nothing to copy out at the end, nothing lost to a closed terminal.

03 · Local

The messy part stays here.

Static analysis, deobfuscation, a full terminal. Pull apart a sample on your own machine without uploading it anywhere first.

How it works

You bring the agent. nano brings the tools.

nano does not ship a model or an agent. pivt desktop drives the coding agent you already run, pointed at the endpoint you already use, and gives it a set of nano tools over MCP. If your organisation has approved that agent, there is no new inference vendor to review.

01

Your SIEM

you bring
managedself-hosted

Point pivt at your nano deployment. It signs in as you and inherits the permissions you already hold, so it can never reach further than you can.

02

Your AI harness

you bring
claudecodexagy

Whichever agent CLI is already on your PATH, running on your subscription against your own model endpoint. nano ships neither a model nor an agent, so there is no new inference vendor to approve.

03

The nano MCP servers

nano brings
searchalertscasesdetectionsprevalenceenrichment

Wired into your agent automatically. This is the part that turns a general coding agent into something that knows your data, your detections and your case history.

One workspace

Searches open as real tabs. The notebook records itself. The terminal and local file analysis sit in the same window, and the whole thing lands on a case when you're done.

The key the agent holds is minted per session and intersected with your own permissions. Every action it takes is audited the same as any other.

What runs where

Local where it matters.

"Local" gets thrown around a lot, so here is the actual split.

Your machine
  • The client itself
  • Terminal
  • Static analysis and deobfuscation
  • The sample, which never has to leave
Your nano instance
  • Logs and search
  • Notebooks and cases
  • Detections and alerts
  • The investigation record, on purpose
Your model endpoint
  • Whatever your agent already uses
  • Bring your own endpoint
  • Air-gapped deployments supported
  • No new inference vendor

Findings going up to nano is the point rather than a caveat. Notes that die in a terminal buffer are the problem this is meant to solve.

In practice

One alert, start to finish.

1

Ask

Point pivt at an alert and a time window. It runs the searches, looks up entity context, and follows the pivots it finds.

2

Check the work

Each search is sitting in the tab strip as a real query. Open it, change the window, take it somewhere else. Steal the query if it's a good one.

3

Go local when you need to

A file dropped on the endpoint, an obfuscated payload, a document you'd rather not open. Same window, and what you find gets tracked with everything else.

4

Land it on the case

Say the word and the session's notes fold into the case notebook, and the workspace follows you there. No copying, no re-typing findings into a comment box.

pivt everywhere else

The same assistant, already in nano.

pivt isn't only the desktop client. It's woven through nano in the browser too: triaging alerts, building parsers from a sample log, writing detections, running playbook steps, and keeping case notes. The desktop is where it gets a terminal and your local machine to work with.

See pivt across the platform
Getting it

What you need.

A nano instance

Managed or self-hosted. The client points at your deployment and authenticates as you.

A coding agent

Claude Code or Codex installed locally, pointed at whichever model endpoint you already use.

macOS or Windows

Native builds for both. Signed installers, no browser required.