The first thing we automated was restraint.
Tamnoon is named as a Sample Vendor for Autonomous Exposure Remediation category in the 2026 Gartner® Emerging Tech Impact Radar: Preemptive Cybersecurity. (Full citation at the foot of this page)
The word in that title we care about is preemptive.
Most of cloud security is retrospective. Something gets found, written down, assigned, and then it waits. Preemptive does not mean finding things sooner. Preemptive means something actually closes. So a category about closing things is the right one to be in, and we think it is going to be a brutal one, because closing things inside somebody else’s production environment is the part of this job where you can do real damage.
Which leads to the question we think the whole category gets judged on. Not how fast. Not how many.
What happens when the right move is to leave it alone?
Our answer, in one artifact
When our engine decides not to act on a finding, it does not skip the row and move on. It writes a verdict. We call it a receipt, and five things are on it.
What it read, in the order it read it. Not a confidence score. The actual facts the decision turned on, so you can check the reasoning instead of trusting it.
The verdict, in one word. SAFE, RISKY, or AWAITING DATA. Three answers. No fourth, no maybe.
The reason, in a sentence you can argue with. If nobody on your team could argue with it, it was never a reason.
The one fact that would change it. Every refusal names the thing that would flip it to yes. Otherwise you have a dead end with good typography.
The steps to do it by hand. A refusal moves the work back to a person, so the refusal ships with the commands, the order, and the check that tells that person it worked.
Handing someone work without handing them the instructions is just handing them the blame.
Why any of this matters
53% of everything we have ever detected is still open. Not the hard half. Half.
The number is not a failure of automation. The number is what automation looks like when the only word it knows is yes.
A system that can only act has two settings. Turn it up and it touches things it should not, and somebody’s production goes down on a Tuesday afternoon. Turn it down and it barely touches anything, which is safe, useless, and where most of that 53% has been sitting for months inside a tool somebody is still paying for.
A third setting exists. Getting to it requires a system that can decide not to act, and can explain itself when it does.
The five moments it stops
Each one is a real reason to refuse, and each one is something the engine reads before it touches anything in your cloud.
Nothing uses it. The finding is valid and the remediation is correct, and the resource has been dead for a year. Enforcing a control on it adds cost, plus one more object in an inventory nobody will claim when it eventually matters.
Nobody owns it. You cannot get consent from nobody. A change no person approved is a change no person will maintain.
Something else is quietly reading it. The remediation is documented. The dependency is not. Some job or service nobody remembers is pulling from that bucket or that key, and the written procedure has no idea it exists.
Somebody already tried this and backed it out. The change history shows a similar change made and then rolled back. Doing it again without knowing why is repeating another team’s incident on purpose.
Your team already said no. When one of your engineers refuses a class of finding, that refusal is kept with the reason behind it and applied the next time the same thing shows up. A system that forgets your veto will make you give it twice.
What it looks like when this works
One customer’s quarterly review went from 6,074 open findings to 2,041, with 93% fewer new alerts arriving each quarter. Four quarters running.
Nothing about that curve is compatible with a system that mostly says no.
Refusing is not the product. Refusing is what makes the rest of it safe to switch on.
How to check anybody in this category, including us
Ask how long their refusal logic has been running in production, and across how many real environments. Ours has been four years.
Ask to see one decline end to end. Not a skipped row in a table. A written verdict.
Ask what that decline hands back to the person who now has to do the work.
Bring us your ugliest finding
The one that has been open eleven months because nobody wants to be the person who touches it.
You get a written verdict in 48 hours. What we read, what we decided, why, what would change it, and how to do it by hand if the answer is no.
Everyone demos the fix. Ask them to demo the decline.
Everyone automates the yes. We mastered the no.
Gartner, Emerging Tech Impact Radar: Preemptive Cybersecurity, Elizabeth Kim, 11 September 2026, ID G00858165.
GARTNER is a trademark of Gartner, Inc. and/or its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose