SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started

For organizations in scope for NIS2 & DORA, without a dedicated security team

Stop chasing 250,000 vulnerabilities
Focus on the ones being exploited

SentriKat surfaces only the vulnerabilities that are actively exploited and still unpatched, then writes your NIS2 and DORA reports for you. No security team needed. Available in the cloud or on premises.

1,300+
Actively exploited vulnerabilities
8
Code Ecosystems
3-Tier
Vendor-patch verification
Limited
Founding-customer spots
2 Modes
Cloud + On-Prem

Be a founding customer. Lock in today's launch price for the life of your subscription and get hands-on onboarding from our team. Limited spots, no credit card to start.

Just want to check a domain? Try the free public security scan

In scope for NIS2 / DORA? Take the free 5-minute readiness check

European privacy standards
NIS2 reporting built-in
Your data stays yours
Auditable source code
OWASP ASVS L1
SentriKat Dashboard
SentriKat dashboard, overview with KEV monitoring, priority breakdown and top vendors SentriKat dashboard, detailed vulnerability list and remediation view
Free · ~5 minutes · No signup to see results

Are you in scope for NIS2 / DORA?

Find out if the directives apply to your organisation and how ready you are, with an indicative per-domain gap analysis mapped to NIS2 Article 21 and the DORA pillars.

Your Choice

Cloud or On-Premises, Same Platform

Choose the deployment that fits your security requirements. Same vulnerability intelligence and compliance features in both modes.

Recommended

Cloud

Managed platform at app.sentrikat.com. We handle infrastructure, updates, and backups.

Every plan's full limits (up to 500 agents on Business)
Zero infrastructure to manage
Automatic updates and security patches
4 plans: Starter → Pro → Business → Enterprise
EU data residency
From €59 /mo
Get started

On-Premises

Deploy on your own infrastructure via Docker Compose. Your data never leaves your network.

100% data sovereignty, zero cloud dependency
Air-gapped deployment supported
Auditable agents (plain bash/PowerShell)
Free Community Edition, or Professional with full features
Ideal for defense, government, healthcare
From €4,999 /yr (Community Edition free)
Request Access

Both modes use the same vulnerability intelligence, compliance reports, and agent technology.

Why SentriKat

Most scanners tell you what's wrong.
SentriKat tells you what's actually fixed.

Traditional vulnerability scanners generate thousands of alerts with no context on which ones are already resolved by vendor patches. SentriKat automatically tracks vendor advisories so you only act on what's real.

4
Vendor feeds synced daily
70K+
CPE entries indexed
3
Confidence tiers
NIS2
Article 21 reports built-in

Automatic Vendor Advisory Sync

SentriKat queries 4 vendor feeds daily and cross-references them against your inventory. When Red Hat backports a fix or Microsoft pushes a KB, SentriKat knows automatically.

OSV.dev (open-source advisories)
Red Hat Security API
Microsoft MSRC
Debian Security Tracker
How it works
RH MS OS DB
SentriKat
12
Affected
28
Likely Resolved
156
Resolved

Three-Tier Confidence System

Every vulnerability gets a confidence tier based on automated vendor analysis. Amber items stay visible for legal compliance. Green items are auto-acknowledged.

AFFECTED No vendor fix detected
LIKELY RESOLVED Vendor fix detected, not verified
RESOLVED Fix confirmed via version check

Distro-Native Version Comparison

SentriKat understands how your OS compares package versions, backport-aware across 8 Linux families. No generic string comparison, just real package manager logic for accurate results.

Debian / Ubuntu (dpkg)
2.31-13+deb11u7 > 2.31-13+deb11u5
RHEL / CentOS (RPM)
4.18.0-425.19.2.el8_7 > 4.18.0-425.3.1
Alpine (APK)
1.36.1-r15 > 1.36.1-r2

Everything Included. No Add-Ons.

Windows, Linux, macOS, container scanning, NIS2 compliance reports, and executive PDFs, all included in the Professional Edition. No separate modules, no hidden costs.

Integrates with Jira, YouTrack, GitHub, GitLab, Slack, Microsoft Teams, and any SIEM via syslog / CEF / LEEF. Single Sign-On via SAML 2.0 (Keycloak, Azure AD, Okta, Google Workspace). User directory sync via LDAP and Active Directory.

Typical Enterprise Scanner

$10,000+/yr

Per module add-on

SIEM + Compliance

Extra modules

Custom pricing

SentriKat

All Included

From €59/mo (Cloud) or €4,999/yr (On-Prem)

Detection Self-Check

Don't trust us.
Trust the verification.

SentriKat is the only vulnerability management that verifies itself. An independent oracle re-checks every detection with a comparator that doesn't share the engine's code, plus a golden corpus built from your own inventory as a continuous regression proof. You see the result in-app, every week, on your data.

Ground-truth distro cross-check

Every detection is re-tested against independent distribution advisory data, the vendor's own source of truth, not the same feed the engine already used. If the two disagree, it's flagged.

Independent comparator, anti-false-positive

A second comparator that shares none of the detection engine's code re-derives each match. Anything the engine reports but the comparator can't confirm is surfaced as a discrepancy.

Independent comparator, anti-false-negative

The same independent comparator works the other direction: anything it finds that the engine missed is caught, so a silent gap in recall can't slip through unnoticed.

Golden floor on your top apps

A golden corpus generated from your real inventory becomes a continuous regression floor, the detections that must never break. Every run re-proves them, so an upgrade can't quietly regress coverage.

Admin Health Detection Self-Check

One line your auditor understands

No dashboards to interpret, no analyst required. The self-check runs on your instance, including fully air-gapped, and reports a single verdict you can act on and defend.

0 discrepancies
last run · weekly

Detection agrees with the independent references. False-positive gate, recall floor and ground-truth cross-check all passed.

Deterministic · Zero AI at runtime · Runs air-gapped · Every week, on your data
Engine validation

"You're new. Is the engine reliable?"

Fair question, and the honest answer is facts, not adjectives. Detection is deterministic (no AI at match time, so results are reproducible and auditable), gate-tested every release, and self-monitored on every deployment.

~2,900 automated checks, 0 failing

A release gate ships nothing red. Every release is green across the full suite.

64/64 · 16/16 golden floors held

Deterministic CPE and per-distro goldens (8 families). A new false-positive class turns the gate red before it ships.

0 engine false positives

On a differential benchmark against Grype, 96.8% recall with zero false positives from the engine.

Weekly recall self-check in production

Every deployed instance measures its real recall on your own data and alarms if it drops. Quality is watched in production, not just in CI.

Behind it: 364,763 CVEs, 1,637 on CISA KEV, 70,132 CPE entries, and 887,833 back-port-aware distro advisories across 8 Linux families. How we validate the engine.

How It Works

From deployment to protection in minutes

SentriKat is designed to be simple. No complex setup, no steep learning curve.

01

Deploy SentriKat

Self-host with Docker in minutes. Single command to get started. Your data, your infrastructure.

bash
docker compose up -d
02

Import Your Inventory

Deploy agents on Windows, Linux, or macOS. Integrate with Lansweeper, SCCM, Intune, or import a CSV.

powershell
# Windows Agent
.\sentrikat-agent.ps1 -Install
03

Automatic Matching

SentriKat syncs CISA KEV + ENISA EUVD daily and enriches CVSS scores from NVD, CVE.org, and EUVD with automatic fallback. No single point of failure.

sync.log
# Daily sync at 2 AM UTC
[KEV] 3 exploited vulns matched
[EUVD] 1 EU-flagged vulnerability
[CVSS] NVD -> CVE.org -> EUVD fallback
04

Multi-Platform Scanning

Native agents for Windows, Linux, and macOS collect installed software. On endpoints running Docker, container images are automatically scanned too.

scan.log
# Windows: 142 products detected
# Linux: 87 packages (dpkg)
# macOS: 63 applications
# Containers: 12 images scanned
[OK] 3 HIGH, 1 CRITICAL found
05

Act on Real Threats

Get alerted via email, Slack, Microsoft Teams, or any SIEM via syslog/CEF/LEEF. Open tickets automatically in Jira, YouTrack, GitHub, or GitLab. Prioritize by severity, due dates, and ransomware indicators.

actions.log
# Critical: CVE-2024-3400
# Due: 7 days | Ransomware: Yes
# -> Jira SK-142 created, SIEM notified
Where it fits

A specialist, not a suite

SentriKat does one job properly: it answers "which of my exposures are actually exploited and still unpatched, right now?" with certainty. It sits alongside the tools you already run, it doesn't pretend to be all of them.

What SentriKat does

  • Adjudicated vulnerability visibility
    KEV, EPSS and the vendor's back-port status, so you act on the exploited handful, not thousands of raw findings.
  • Full asset coverage
    OS packages, container images and code dependencies, back-port aware across 8 Linux families.
  • Compliance evidence, on demand
    NIS2 and DORA gap analysis and SBOMs (CycloneDX / SPDX / STIX), exported when you need them.
  • Yours to keep
    Runs on-premises or fully air-gapped, so vulnerability data never leaves the box. Built in Europe.

What it isn't

  • Not a SIEM or EDR/XDR
    It finds exposures. It doesn't watch endpoints or correlate logs.
  • Not IAM, PAM or backup
    Those stay in your stack. SentriKat sits alongside them, it doesn't replace them.
  • Not a sandbox or a patcher
    It tells you exactly what's exposed. Applying the fix and isolating the runtime is still your call.

The rest of your defences answer the other questions. This one answers its own, and shows you the working.

Free scanners like Trivy and Grype answer "do I have it?" once, for one image, and they do it well. SentriKat runs that as a continuous, de-noised process across your whole fleet: back-port aware, KEV and EPSS first, with the NIS2 and DORA evidence attached.

Machines, not just servers

Industrial equipment, checked by us

NIS2 covers energy, water, transport, manufacturing and health, and in those sectors the equipment that matters is not a laptop. It is a controller on a production line that has run untouched for nine years.

1
You send the list

Makes, models and firmware versions. A spreadsheet is fine. Nothing is installed on any of your equipment.

2
We match it

Against the same European vulnerability database the product runs on, including the exploited-in-the-wild list and exploitation probability.

3
You get a report

What is exploitable today, what can wait, and what has no fix. Written for the person who has to schedule the downtime.

What this is not

We do not put software on your industrial equipment and we do not connect anything to your control network. Nobody should, and the vendors who offer it charge for an appliance you do not need. This is a person reading your equipment list against a database that is already current, and telling you what to do about it.

Send us your equipment list

Tell us the sector and roughly how many devices. We will say what we can answer before you send anything.

Launch pricing

Simple, transparent pricing

SentriKat is live. Founding customers lock in launch pricing and get hands-on onboarding from our team. Every plan below ships with its full agent and user limits. All prices are in EUR and exclude VAT.

Founding-customer onboarding open, limited time

Starter

€59 /mo
Launch pricing
10 agents · 3 users
  • Email alerts
  • EPSS + KEV prioritization
  • CSV/Excel export
  • Community support (email & portal)
Get started
Most Popular

Pro

€249 /mo
Launch pricing
25 agents · 5 users
  • SBOM export (CycloneDX / SPDX / STIX)
  • NIS2, DORA & BOD 22-01 reports
  • SIEM integration
  • Jira / GitHub / GitLab / YouTrack
  • SSO login (SAML 2.0 / OIDC)
  • Remediation assignments + SLA
  • Priority support (1 business day)*
Get started

Business

€649 /mo
Launch pricing
50 agents · 10 users
  • Everything in Pro
  • LDAP / AD directory-sync
  • Multi-tenant + white-label
  • Executive PDF reports
  • Phone + scheduled calls*
Get started

Enterprise

Custom
Launch pricing
Custom · Custom
  • Custom SLA
  • On-premises deployment
  • Onboarding & training*
  • Custom support agreement*
Contact Us
Compliance Pack Add-on €199/mo

Unlocks PCI-DSS v4.0, ISO/IEC 27001:2022 and SOC 2 gap-analysis reports (HMAC-signed, JSON or PDF) on top of any Pro, Business or Enterprise plan.

Launch pricing for founding customers, locked in for the life of your subscription. Agent and user limits vary by plan. All prices in EUR, excl. VAT.
*Support is provided via email and tickets through the Customer Portal, with priority SLA, phone and scheduled calls on higher tiers as listed above.

Compare Cloud Plans

Everything you need to choose the right plan.

Feature Starter Pro Business Enterprise
Agents included 25 100 500 Unlimited
Users included 3 10 50 Custom
Agent Discovery (OS, browser, IDE, containers)
Code Dependency Scanning
Version-Verified CVE Dashboard
Remediation Actions Widget
Email Alerts
SBOM Export (CycloneDX / SPDX / STIX) Not included
NIS2, DORA & BOD 22-01 Reports Not included
Compliance Pack, PCI / ISO 27001 / SOC 2 Not included Add-on Add-on Add-on
Remediation Assignments + SLA Not included
SIEM Integration Not included
Jira / GitHub / GitLab / YouTrack Not included
SSO login (SAML 2.0 / OIDC) Not included
LDAP / AD directory-sync Not included Not included
Multi-Tenant Not included Not included
White-Label Not included Not included
On-Premises Deployment Not included Not included Not included
Custom SLA Not included Not included Not included
Support* Email Email (1 bd) Email + Calls Custom SLA

What changes with SentriKat

Stop spending hours on manual triage. Here's what your team gets on day one.

Without SentriKat With SentriKat
CVEs to triage Every CVE ever published Only confirmed exploited vulnerabilities
CVE triage time 40+ hours/month manual work Automated daily, minutes, not hours
False positive rate High noise from generic scanners Vendor patch detection filters resolved CVEs
Starting price $10,000 – $50,000+/yr From €59/mo

Questions about pricing, custom needs, or partnership?

Contact us
FAQ

Frequently asked questions

Everything you need to know about SentriKat and the platform.

Request an On-Premises Evaluation

Deploy SentriKat on your own infrastructure with a guided evaluation. We'll send you a license key and setup guide within 24 hours.

Become a founding customer

Start on SentriKat with launch pricing locked in and hands-on onboarding from our team. No credit card to get started. Personal onboarding is limited to 30 Cloud customers.

Launch pricing on every plan. Agent and user limits vary by plan (25–500 agents).

This is the plan you'd like to start on. Helps us tailor your onboarding and pre-fills your upgrade path later. All features are available during EA regardless of choice.

256-bit encryption
GDPR Compliant
No credit card

No credit card to get started. Founding customers lock in launch pricing for the life of their subscription and get hands-on onboarding from our team.