Polestead meets your estate where it is: API sync when you're connected, flat-file when you're not, your own keys for AI and scanning. No dependency you didn't choose.
Ingest the vendor master your ERP or procurement system already owns — API sync for connected estates, flat-file import for air-gapped ones. Deduplicated and identity-resolved on ingestion.
Single sign-on and SAML for managed deployments, role-based access control, and scoped API entitlements so access is granted narrowly.
Connect an external attack-surface-management license you already hold, EU-domiciled providers available — scoped by tier and attached as evidence, never a public grade.
Point Polestead at your own AI provider under your spend caps and model choice — or run zero-AI. Your data never trains our models because inference never touches our infrastructure.
The ingestion layer is format-driven, so most ERP, GRC, and ticketing systems connect via API or export. Tell us your stack and we'll confirm the path.
By API sync for connected estates, or flat-file import for air-gapped ones. Records are deduplicated and identity-resolved on ingestion.
Yes — SSO/SAML and provisioning for managed deployments, with RBAC and scoped API entitlements.
Yes. AI runs on your own provider keys, and external signals come through connectors using a scanning license you bring — EU-domiciled providers available.