A native workbench for security work. Your agent runs the searches and they open as real tabs you can re-run. The notebook writes itself. Local analysis stays local. And the whole thing lands on the case when you're done.
Most analysts already work with an agent in a terminal. It's fast, and everything it does disappears the moment the scrollback rolls. pivt desktop keeps the speed and gives the work somewhere to live: tabs you can go back to, a record that writes itself, and a case at the end of it.
Every search the agent runs opens as an actual search in your workspace. Re-run it, widen the window, pivot off a field. If you can't check the work yourself, you're taking its word for it.
Every query, tool call and conclusion is recorded as the investigation happens. Nothing to copy out at the end, nothing lost to a closed terminal.
Static analysis, deobfuscation, a full terminal. Pull apart a sample on your own machine without uploading it anywhere first.
nano does not ship a model or an agent. pivt desktop drives the coding agent you already run, pointed at the endpoint you already use, and gives it a set of nano tools over MCP. If your organisation has approved that agent, there is no new inference vendor to review.
Point pivt at your nano deployment. It signs in as you and inherits the permissions you already hold, so it can never reach further than you can.
Whichever agent CLI is already on your PATH, running on your subscription against your own model endpoint. nano ships neither a model nor an agent, so there is no new inference vendor to approve.
Wired into your agent automatically. This is the part that turns a general coding agent into something that knows your data, your detections and your case history.
Searches open as real tabs. The notebook records itself. The terminal and local file analysis sit in the same window, and the whole thing lands on a case when you're done.
The key the agent holds is minted per session and intersected with your own permissions. Every action it takes is audited the same as any other.
"Local" gets thrown around a lot, so here is the actual split.
Findings going up to nano is the point rather than a caveat. Notes that die in a terminal buffer are the problem this is meant to solve.
Point pivt at an alert and a time window. It runs the searches, looks up entity context, and follows the pivots it finds.
Each search is sitting in the tab strip as a real query. Open it, change the window, take it somewhere else. Steal the query if it's a good one.
A file dropped on the endpoint, an obfuscated payload, a document you'd rather not open. Same window, and what you find gets tracked with everything else.
Say the word and the session's notes fold into the case notebook, and the workspace follows you there. No copying, no re-typing findings into a comment box.
pivt isn't only the desktop client. It's woven through nano in the browser too: triaging alerts, building parsers from a sample log, writing detections, running playbook steps, and keeping case notes. The desktop is where it gets a terminal and your local machine to work with.
Managed or self-hosted. The client points at your deployment and authenticates as you.
Claude Code or Codex installed locally, pointed at whichever model endpoint you already use.
Native builds for both. Signed installers, no browser required.