Stop chasing 250,000 vulnerabilities
Focus on the ones being exploited
Are you in scope for NIS2 / DORA?
Find out if the directives apply to your organisation and how ready you are, with an indicative per-domain gap analysis mapped to NIS2 Article 21 and the DORA pillars.
Cloud or On-Premises, Same Platform
Choose the deployment that fits your security requirements. Same vulnerability intelligence and compliance features in both modes.
Cloud
Managed platform at app.sentrikat.com. We handle infrastructure, updates, and backups.
On-Premises
Deploy on your own infrastructure via Docker Compose. Your data never leaves your network.
Both modes use the same vulnerability intelligence, compliance reports, and agent technology.
Most scanners tell you what's wrong.
SentriKat tells you what's actually fixed.
Traditional vulnerability scanners generate thousands of alerts with no context on which ones are already resolved by vendor patches. SentriKat automatically tracks vendor advisories so you only act on what's real.
Automatic Vendor Advisory Sync
SentriKat queries 4 vendor feeds daily and cross-references them against your inventory. When Red Hat backports a fix or Microsoft pushes a KB, SentriKat knows automatically.
Three-Tier Confidence System
Every vulnerability gets a confidence tier based on automated vendor analysis. Amber items stay visible for legal compliance. Green items are auto-acknowledged.
Distro-Native Version Comparison
SentriKat understands how your OS compares package versions, backport-aware across 8 Linux families. No generic string comparison, just real package manager logic for accurate results.
2.31-13+deb11u7 > 2.31-13+deb11u5 4.18.0-425.19.2.el8_7 > 4.18.0-425.3.1 1.36.1-r15 > 1.36.1-r2 Everything Included. No Add-Ons.
Windows, Linux, macOS, container scanning, NIS2 compliance reports, and executive PDFs, all included in the Professional Edition. No separate modules, no hidden costs.
Integrates with Jira, YouTrack, GitHub, GitLab, Slack, Microsoft Teams, and any SIEM via syslog / CEF / LEEF. Single Sign-On via SAML 2.0 (Keycloak, Azure AD, Okta, Google Workspace). User directory sync via LDAP and Active Directory.
Typical Enterprise Scanner
$10,000+/yr
Per module add-on
SIEM + Compliance
Extra modules
Custom pricing
SentriKat
All Included
From €59/mo (Cloud) or €4,999/yr (On-Prem)
Don't trust us.
Trust the verification.
SentriKat is the only vulnerability management that verifies itself. An independent oracle re-checks every detection with a comparator that doesn't share the engine's code, plus a golden corpus built from your own inventory as a continuous regression proof. You see the result in-app, every week, on your data.
Ground-truth distro cross-check
Every detection is re-tested against independent distribution advisory data, the vendor's own source of truth, not the same feed the engine already used. If the two disagree, it's flagged.
Independent comparator, anti-false-positive
A second comparator that shares none of the detection engine's code re-derives each match. Anything the engine reports but the comparator can't confirm is surfaced as a discrepancy.
Independent comparator, anti-false-negative
The same independent comparator works the other direction: anything it finds that the engine missed is caught, so a silent gap in recall can't slip through unnoticed.
Golden floor on your top apps
A golden corpus generated from your real inventory becomes a continuous regression floor, the detections that must never break. Every run re-proves them, so an upgrade can't quietly regress coverage.
One line your auditor understands
No dashboards to interpret, no analyst required. The self-check runs on your instance, including fully air-gapped, and reports a single verdict you can act on and defend.
Detection agrees with the independent references. False-positive gate, recall floor and ground-truth cross-check all passed.
"You're new. Is the engine reliable?"
Fair question, and the honest answer is facts, not adjectives. Detection is deterministic (no AI at match time, so results are reproducible and auditable), gate-tested every release, and self-monitored on every deployment.
A release gate ships nothing red. Every release is green across the full suite.
Deterministic CPE and per-distro goldens (8 families). A new false-positive class turns the gate red before it ships.
On a differential benchmark against Grype, 96.8% recall with zero false positives from the engine.
Every deployed instance measures its real recall on your own data and alarms if it drops. Quality is watched in production, not just in CI.
Behind it: 364,763 CVEs, 1,637 on CISA KEV, 70,132 CPE entries, and 887,833 back-port-aware distro advisories across 8 Linux families. How we validate the engine.
From deployment to protection in minutes
SentriKat is designed to be simple. No complex setup, no steep learning curve.
Deploy SentriKat
Self-host with Docker in minutes. Single command to get started. Your data, your infrastructure.
docker compose up -d
Import Your Inventory
Deploy agents on Windows, Linux, or macOS. Integrate with Lansweeper, SCCM, Intune, or import a CSV.
# Windows Agent .\sentrikat-agent.ps1 -Install
Automatic Matching
SentriKat syncs CISA KEV + ENISA EUVD daily and enriches CVSS scores from NVD, CVE.org, and EUVD with automatic fallback. No single point of failure.
# Daily sync at 2 AM UTC [KEV] 3 exploited vulns matched [EUVD] 1 EU-flagged vulnerability [CVSS] NVD -> CVE.org -> EUVD fallback
Multi-Platform Scanning
Native agents for Windows, Linux, and macOS collect installed software. On endpoints running Docker, container images are automatically scanned too.
# Windows: 142 products detected # Linux: 87 packages (dpkg) # macOS: 63 applications # Containers: 12 images scanned [OK] 3 HIGH, 1 CRITICAL found
Act on Real Threats
Get alerted via email, Slack, Microsoft Teams, or any SIEM via syslog/CEF/LEEF. Open tickets automatically in Jira, YouTrack, GitHub, or GitLab. Prioritize by severity, due dates, and ransomware indicators.
# Critical: CVE-2024-3400 # Due: 7 days | Ransomware: Yes # -> Jira SK-142 created, SIEM notified
A specialist, not a suite
SentriKat does one job properly: it answers "which of my exposures are actually exploited and still unpatched, right now?" with certainty. It sits alongside the tools you already run, it doesn't pretend to be all of them.
What SentriKat does
- Adjudicated vulnerability visibilityKEV, EPSS and the vendor's back-port status, so you act on the exploited handful, not thousands of raw findings.
- Full asset coverageOS packages, container images and code dependencies, back-port aware across 8 Linux families.
- Compliance evidence, on demandNIS2 and DORA gap analysis and SBOMs (CycloneDX / SPDX / STIX), exported when you need them.
- Yours to keepRuns on-premises or fully air-gapped, so vulnerability data never leaves the box. Built in Europe.
What it isn't
- Not a SIEM or EDR/XDRIt finds exposures. It doesn't watch endpoints or correlate logs.
- Not IAM, PAM or backupThose stay in your stack. SentriKat sits alongside them, it doesn't replace them.
- Not a sandbox or a patcherIt tells you exactly what's exposed. Applying the fix and isolating the runtime is still your call.
The rest of your defences answer the other questions. This one answers its own, and shows you the working.
Free scanners like Trivy and Grype answer "do I have it?" once, for one image, and they do it well. SentriKat runs that as a continuous, de-noised process across your whole fleet: back-port aware, KEV and EPSS first, with the NIS2 and DORA evidence attached.
Industrial equipment, checked by us
NIS2 covers energy, water, transport, manufacturing and health, and in those sectors the equipment that matters is not a laptop. It is a controller on a production line that has run untouched for nine years.
Makes, models and firmware versions. A spreadsheet is fine. Nothing is installed on any of your equipment.
Against the same European vulnerability database the product runs on, including the exploited-in-the-wild list and exploitation probability.
What is exploitable today, what can wait, and what has no fix. Written for the person who has to schedule the downtime.
What this is not
We do not put software on your industrial equipment and we do not connect anything to your control network. Nobody should, and the vendors who offer it charge for an appliance you do not need. This is a person reading your equipment list against a database that is already current, and telling you what to do about it.
Tell us the sector and roughly how many devices. We will say what we can answer before you send anything.
Simple, transparent pricing
SentriKat is live. Founding customers lock in launch pricing and get hands-on onboarding from our team. Every plan below ships with its full agent and user limits. All prices are in EUR and exclude VAT.
Starter
- Email alerts
- EPSS + KEV prioritization
- CSV/Excel export
- Community support (email & portal)
Pro
- SBOM export (CycloneDX / SPDX / STIX)
- NIS2, DORA & BOD 22-01 reports
- SIEM integration
- Jira / GitHub / GitLab / YouTrack
- SSO login (SAML 2.0 / OIDC)
- Remediation assignments + SLA
- Priority support (1 business day)*
Business
- Everything in Pro
- LDAP / AD directory-sync
- Multi-tenant + white-label
- Executive PDF reports
- Phone + scheduled calls*
Enterprise
- Custom SLA
- On-premises deployment
- Onboarding & training*
- Custom support agreement*
Unlocks PCI-DSS v4.0, ISO/IEC 27001:2022 and SOC 2 gap-analysis reports (HMAC-signed, JSON or PDF) on top of any Pro, Business or Enterprise plan.
Launch pricing for founding customers, locked in for the life of your
subscription. Agent and user limits vary by plan. All prices in EUR,
excl. VAT.
*Support is provided via email and tickets through the
Customer Portal,
with priority SLA, phone and scheduled calls on higher tiers as listed above.
Community Edition
Try the platform with limited capacity
- 10 Agents (Windows, Linux, macOS)
- 3 Users
- 1 Organization
- 100 Products
- Daily KEV Sync
- Basic Dashboard
- Container Scanning
- Multi-tenant
- Email Alerts + Webhooks
- LDAP/AD/SAML SSO
- Compliance Reports
- SIEM Integration
Professional
Full-featured on-premises, all features unlocked
- 10 Agents included (scale with packs)
- 3 Users included
- Unlimited Organizations
- Unlimited Products
- All vulnerability intelligence sources
- NIS2, DORA, BOD 22-01 reports
- SIEM/Syslog integration
- Jira, GitHub, GitLab integration
- Multi-tenant + White-Label
- LDAP/AD/SAML SSO + TOTP 2FA
- Air-gapped deployment
- Backup/Restore + Docker deploy
Agent Packs (add-on capacity)
Need more agents? Add capacity to your Professional license.
Compare Cloud Plans
Everything you need to choose the right plan.
| Feature | Starter | Pro | Business | Enterprise |
|---|---|---|---|---|
| Agents included | 25 | 100 | 500 | Unlimited |
| Users included | 3 | 10 | 50 | Custom |
| Agent Discovery (OS, browser, IDE, containers) | ||||
| Code Dependency Scanning | ||||
| Version-Verified CVE Dashboard | ||||
| Remediation Actions Widget | ||||
| Email Alerts | ||||
| SBOM Export (CycloneDX / SPDX / STIX) | Not included | |||
| NIS2, DORA & BOD 22-01 Reports | Not included | |||
| Compliance Pack, PCI / ISO 27001 / SOC 2 | Not included | Add-on | Add-on | Add-on |
| Remediation Assignments + SLA | Not included | |||
| SIEM Integration | Not included | |||
| Jira / GitHub / GitLab / YouTrack | Not included | |||
| SSO login (SAML 2.0 / OIDC) | Not included | |||
| LDAP / AD directory-sync | Not included | Not included | ||
| Multi-Tenant | Not included | Not included | ||
| White-Label | Not included | Not included | ||
| On-Premises Deployment | Not included | Not included | Not included | |
| Custom SLA | Not included | Not included | Not included | |
| Support* | Email (1 bd) | Email + Calls | Custom SLA |
What changes with SentriKat
Stop spending hours on manual triage. Here's what your team gets on day one.
| Without SentriKat | With SentriKat | |
|---|---|---|
| CVEs to triage | Every CVE ever published | Only confirmed exploited vulnerabilities |
| CVE triage time | 40+ hours/month manual work | Automated daily, minutes, not hours |
| False positive rate | High noise from generic scanners | Vendor patch detection filters resolved CVEs |
| Starting price | $10,000 – $50,000+/yr | From €59/mo |
Questions about pricing, custom needs, or partnership?
Contact usFrequently asked questions
Everything you need to know about SentriKat and the platform.
Request an On-Premises Evaluation
Deploy SentriKat on your own infrastructure with a guided evaluation. We'll send you a license key and setup guide within 24 hours.
Become a founding customer
Start on SentriKat with launch pricing locked in and hands-on onboarding from our team. No credit card to get started. Personal onboarding is limited to 30 Cloud customers.
No credit card to get started. Founding customers lock in launch pricing for the life of their subscription and get hands-on onboarding from our team.