SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started
Platform

Everything you need to manage vulnerabilities

Install once, scan everything. One platform, no modules, no per-asset pricing.

Vulnerability View, Prioritized by real-world risk
SentriKat vulnerability dashboard showing CVEs prioritized by severity with version-verified matching and vendor patch status

Version-verified CVEs, color-coded by severity, enriched with exploit probability and vendor patch data.

Zero Configuration

Install once, discover everything

One command to install. Automatic scan every 4 hours. Heartbeat every 5 minutes. The agent handles the rest.

What it scans How Configuration
OS Packages dpkg, RPM, pacman, Homebrew, WMI, Registry Automatic
Browser Extensions Chrome, Firefox, Edge, reads manifests directly Automatic
IDE Plugins VS Code, JetBrains (IntelliJ, PyCharm, etc.) Automatic
Containers Docker images (via integrated Trivy) Automatic if Docker present
Code Dependencies 13+ lockfile formats, 8 ecosystems (npm, pip, cargo, go, gem, composer, .NET, maven) Automatic, finds lockfiles
Dependency Vulnerabilities Version-verified matching for every dependency found Automatic, integrated
Features

Everything you need to manage vulnerabilities

Built for security teams who need to cut through the noise and focus on real threats.

Core Feature

Exploited Vulnerability Focus

Stop chasing every CVE. SentriKat verifies each vulnerability against the exact version of your installed software. Only confirmed matches, prioritized by real-world exploitation.

CVE-2024-3400
CRITICAL
CVE-2024-21887
HIGH
248,500+ other CVEs
FILTERED

Only actively exploited vulnerabilities. No noise.

New

Zero-Day Intelligence

Instant alerts when a zero-day vulnerability affects software in your inventory. Aggregates emergency directives, vendor security advisories, and threat intelligence. A dedicated dashboard separates unpatched zero-day threats from the vulnerabilities already known to be exploited.

CVE-2024-3400 PAN-OS Command Injection
0-DAY
CVE-2024-21887 Ivanti Connect Secure RCE
0-DAY
CVE-2024-1709 ScreenConnect Auth Bypass
PATCH AVAIL
3
Active 0-Days
7
Patch Available
24
Endpoints Hit
Unique

Vendor Advisory Sync

Reads package and vendor advisories daily, across Linux distributions and Microsoft. Automatically detects when a vendor has patched a vulnerability. Zero manual work.

Package advisories synced 2m ago
Red Hat Security API synced 2m ago
Microsoft MSRC synced 15m ago
Debian Security Tracker synced 15m ago
Unique

Three-Tier Confidence

AFFECTED (red), LIKELY RESOLVED (amber), RESOLVED (green). Never silently hides a potential vulnerability. Vendor patch detection eliminates the most common source of false positives.

AFFECTED No vendor fix detected
LIKELY RESOLVED Vendor fix detected
RESOLVED Fix confirmed via version check
Flexible

Software Inventory

Native agents for Windows, Linux, and macOS with distro-native version comparison (dpkg, RPM, APK). Integrates with Lansweeper, PDQ Deploy, SCCM, Intune, REST API, and CSV import.

Windows
Agent
Linux
Agent
macOS
Agent
Lansweeper
Sync
SCCM
Intune
REST
API
New

Endpoint & Container Scanning

Native agents for Windows, Linux, and macOS scan endpoints and container images in one pass. Detect OS packages, installed applications, and container vulnerabilities across your entire infrastructure.

$ sentrikat-agent status
Windows, 142 products collected
Linux, 87 packages (dpkg)
macOS, 63 applications
Containers, 12 images scanned
nginx:1.25, 0 vulnerabilities
app:latest, 1 CRITICAL, 3 HIGH

Windows, Linux, macOS, Docker, one agent

New

Code Dependency Scanning

Find known vulnerabilities in your open-source dependencies before they reach production. 13+ lockfile formats across 8 ecosystems with exact version matching, verified matches only, not CPE guessing. CI/CD native with GitHub Actions, GitLab CI, and Jenkins gate support.

8 Ecosystems · 13 Lockfile Formats
Node.js package-lock.json · yarn.lock · pnpm-lock.yaml
Python Pipfile.lock · poetry.lock
Rust Cargo.lock
Go go.sum · go.mod
Ruby Gemfile.lock
PHP composer.lock
.NET packages.lock.json
Packages
Powered
CI/CD
Native
Exploited
Prioritized

Version-verified matches · exact lockfile resolution

Smart

Intelligent Matching

Multi-method CVE matching using CPE identifiers, vendor+product combinations, and keyword analysis with confidence scoring.

CPE Match 98%
Vendor + Product 85%
Keyword Analysis 72%
Pro

Notifications & Alerting

Email alerts with daily/weekly digests, Slack/Teams/Discord webhooks with HMAC-SHA256 signing, and custom alert rules by priority, organization, or product criticality. 3-tier escalation policies for unacknowledged critical vulnerabilities.

Email AlertsDaily & weekly digests
🔌
WebhooksSlack / Teams / Discord
🎯
Issue TrackersJira / GitHub / GitLab / YouTrack
⚠️
Escalation Policies24h / 72h auto-escalation

Exploited in the wild, due date, ransomware, agent offline & more

Pro

Multi-Tenant & White-Label

Isolated organizations with role-based access control and white-label branding. Customize your app name, logo, and colors in Admin Panel, branding applies to both the web UI and exported compliance documents. Perfect for MSPs or enterprises with multiple business units.

Org: Acme Corp
3 admins · 12 viewers · 847 products
Org: Beta Industries
1 admin · 5 viewers · 231 products
Org: Gamma GmbH
2 admins · 8 viewers · 502 products
Privacy

Self-Hosted & Air-Gapped

Your data stays with you. Deploy on your own infrastructure with Docker, including fully air-gapped environments. Built-in backup/restore and TOTP two-factor authentication.

# Your infrastructure, your data
$ docker compose up -d
Creating sentrikat-db   ... done
Creating sentrikat-app ... done
Creating sentrikat-web ... done
✓ SentriKat running on https://localhost
✓ Air-gapped & TOTP 2FA ready
New

SBOM Export

Generate a Software Bill of Materials for every host in one click. Native exports in CycloneDX 1.5, SPDX 2.3, and STIX 2.1 bundles, plus VEX (CycloneDX), SARIF 2.1, CSAF 2.0 and ServiceNow VR exports for your existing security pipeline. CRA-ready out of the box, the EU Cyber Resilience Act mandates SBOMs for software sold in Europe starting 11 September 2026. Tenable, Qualys, and Rapid7 charge extra for this; SentriKat includes it on every paid plan.

JSON
CycloneDX 1.5 OWASP standard · CRA & EO 14028
JSON
SPDX 2.3 Linux Foundation · ISO/IEC 5962
STIX
STIX 2.1 bundle Threat-intel handoff to SOC/ISAC
Cyber Resilience Act, ready Deadline: 11 September 2026
New

Compliance Reports (6 frameworks)

Signed gap-analysis reports with PASS / PARTIAL / FAIL verdict on every control. NIS2 Article 21, exploited-vulnerability compliance, DORA, PCI-DSS v4.0 (Req 6.3, 11.3), ISO/IEC 27001:2022 (A.8.8, A.8.16, A.5.24), and SOC 2 (CC6.6, CC7.1, CC7.2, CC7.4). Every export carries an HMAC-SHA256 integrity block, auditors can verify the report hasn't been tampered with after generation. JSON, PDF or DOCX, white-label branding included.

EU NIS2 Art. 21
US BOD 22-01
FIN DORA
PCI PCI-DSS v4.0
ISO 27001:2022
SOC SOC 2
HMAC-SHA256 integrity block Tamper-evident · audit-ready

JSON, PDF or DOCX · PASS / PARTIAL / FAIL per control

New

SIEM Integration

Stream vulnerability events to your SIEM via syslog in CEF, JSON, or RFC 5424 format. Native support for Splunk, Elastic/ELK, ArcSight, and QRadar.

CEF:0|SentriKat|VulnMgmt|1.0|KEV_MATCH|
severity=Critical cve=CVE-2024-3400
product=PAN-OS status=AFFECTED
dst=siem.company.local:514
Splunk
ELK
ArcSight
QRadar
New

Multi-Source Intelligence

Severity scores from three independent public databases, with automatic fallback when one is silent or disagrees. Exploited-vulnerability data from two of them, one European. Every score carries a provenance tag saying which one it came from.

CVSS Fallback Chain
Primary database PRIMARY
miss?
Enriched CVE records SECONDARY
miss?
EU European database TERTIARY
Every score tagged: cvss_source: "nvd" | "cve_org" | "euvd"
Intelligence

Exploit Probability

Every vulnerability carries the probability that somebody actually exploits it, so you fix first what is most likely to be used against you.

CVE-2024-3400
97.2%
CVE-2024-1709
82.1%
CVE-2024-0012
44.8%

Exploit probability in next 30 days

Automatic

Background Sync

Scheduled tasks keep your data current without manual intervention. Exploited-vulnerability feeds and vendor advisories sync daily, exploit probabilities update regularly, and the software identity catalogue refreshes weekly. Configurable cron schedules.

Exploited vulnerabilities
Daily at 2 AM
European database
Daily (EU)
Vendor Advisories
Daily (8 distro feeds)
Exploit probability
Daily
Software identities
Weekly (~50K entries)
License Check
Every 6 hours

All tasks start on boot. Custom cron schedules supported.

New

Agent Management

Server-side agent configuration, minimum version enforcement, and heartbeat monitoring. Agents check in regularly and receive configuration updates automatically. MDM-compatible deployment for macOS (Jamf, Kandji, Mosyle).

win-srv-01
v1.0.2, online
ubuntu-app-03
v1.0.2, online
macbook-dev-07
v1.0.2, online
rhel-db-02
v1.0.1, update available

Heartbeat monitoring, config push & version enforcement

Pro

Authentication & SSO

Enterprise authentication with Active Directory, LDAP, SAML 2.0, and TOTP two-factor authentication. Centralized user management.

AD Active Directory / LDAP
SA SAML 2.0 SSO
2F TOTP Two-Factor Auth
New

System Health Checks

10 automated health checks run every 30 minutes, database, disk space, workers, CVE sync freshness, agent heartbeats, and more. Email notifications and in-app alerts surface critical issues before they escalate.

Database
Healthy
CVE Sync
Fresh (2h ago)
Background Workers
Running
Disk Space
Warning (82%)

10 checks · every 30 min · email & in-app alerts

New

Enterprise Scale

Concurrent worker pool, configurable database tuning, exponential backoff retry, and built-in load testing. Tune deployment size via environment variables, no code changes needed. We do not publish an agent ceiling: the sizing guidance in the docs is what we can show, and a number we have not measured is not one we will put on a page.

# Enterprise sizing (.env)
GUNICORN_WORKERS=16
WORKER_POOL_SIZE=16
DB_POOL_SIZE=20
PG_MAX_CONNECTIONS=800
✓ Tuned by environment variable, no code change
16
Workers
5x
Auto-Retry
800
DB Conns

Tune via env vars · no code changes

New

Built-in Admin Tools

GUI log viewer with 7 log types, full-text search, and download. Interactive API documentation via Swagger UI. Built-in troubleshooting guide with Docker commands and common scenarios. No SSH required.

LOG
System Log Viewer 7 log types · search & download
API
Interactive API Docs OpenAPI / Swagger UI
OPS
Admin Guide Troubleshooting & Docker cheat sheet
AUD
Audit Logs Full user activity trail

Swipe tabs or tap to explore

Why SentriKat

Most scanners tell you what's wrong.
SentriKat tells you what's actually fixed.

Traditional scanners generate thousands of alerts with no context on which ones a vendor patch has already resolved. SentriKat tracks vendor advisories automatically, so you only act on what is still real.

4
Vendor feeds synced daily
70K+
CPE entries indexed
3
Confidence tiers
NIS2
Article 21 reports built-in

Automatic vendor advisory sync

SentriKat queries 6 vendor feeds daily and cross-references them against your inventory. When Red Hat backports a fix or Microsoft pushes a KB, SentriKat knows automatically.

Open-source package advisories
Red Hat Security API
Microsoft MSRC
Debian Security Tracker
How it works
RH MS OS DB
SentriKat
12
Affected
28
Likely Resolved, Verify
156
Resolved

Three-tier confidence system

Every vulnerability gets a confidence tier based on automated vendor analysis. Amber items stay visible for legal compliance. Green items are auto-acknowledged.

AFFECTED No vendor fix detected
LIKELY RESOLVED Vendor fix detected, not verified
RESOLVED Fix confirmed via version check

Distro-native version comparison

SentriKat understands how your OS compares package versions, backport-aware across 8 Linux families. No generic string comparison, just real package manager logic for accurate results.

Debian / Ubuntu (dpkg)
2.31-13+deb11u7 > 2.31-13+deb11u5
RHEL / CentOS (RPM)
4.18.0-425.19.2.el8_7 > 4.18.0-425.3.1
Alpine (APK)
1.36.1-r15 > 1.36.1-r2

Everything included. No add-ons.

Windows, Linux, macOS, container scanning, NIS2 compliance reports, and executive PDFs, all included in the Professional Edition. No separate modules, no hidden costs.

Integrates with Jira, YouTrack, GitHub, GitLab, Slack, Microsoft Teams, and any SIEM via syslog / CEF / LEEF. Single Sign-On via SAML 2.0 (Keycloak, Azure AD, Okta, Google Workspace). User directory sync via LDAP and Active Directory.

Typical Enterprise Scanner

$10,000+/yr

Per module add-on

SIEM + Compliance

Extra modules

Custom pricing

SentriKat

All Included

From €59/mo (Cloud) or €4,999/yr (On-Prem)

Vulnerability Intelligence

European vulnerability intelligence, first

We start from the European Union vulnerability database, the one established under NIS2 Article 12, and enrich it with the exploited-vulnerability feeds, exploit probabilities, package advisories and the security advisories of Ubuntu, Debian and Red Hat.

Not a flag on a page: the largest American database has left a large share of recent CVEs without the version data a scanner needs to act on them. The European one carries it, so starting there finds things a US-only pipeline misses.

The European database as the primary source

The EU's own vulnerability database, read first and in full, not as an afterthought. It carries the affected products and versions that the larger American database increasingly leaves out, which is what makes a match actionable.

Active Threat Detection

Continuously monitors confirmed exploited vulnerabilities across more than one authoritative catalog

Version-Verified Matching

Every CVE matched against the software versions in your environment, with an explicit confidence level per match, so you can cut the noise.

Predictive Prioritization

Exploit-probability scoring, prioritize by real-world exploitation likelihood, not just severity

Dependency Scanning

Built-in SCA across 8 ecosystems and 13+ lockfile formats with version-verified matching

Vendor Patch Intelligence

Daily patch status from major vendors, know when fixes are available, not just vulnerabilities

Deterministic & Verified Detection

No AI at runtime. A deterministic engine, anti-false-positive gate, CPE matching, orchestration, suppression, that is mutation-tested, validated against real public CVEs, and self-checks its recall on every instance. Reproducible results you can defend to an auditor.

Built-in resilience: automatic failover between sources ensures uninterrupted coverage even when upstream feeds go down
How It Works

From deployment to protection in minutes

SentriKat is designed to be simple. No complex setup, no steep learning curve.

01

Deploy SentriKat

Self-host with Docker in minutes. One command to get started. Your data, your infrastructure.

bash
docker compose up -d
02

Import your inventory

Deploy agents on Windows, Linux or macOS. Integrate with Lansweeper, SCCM or Intune, or import a CSV.

powershell
# Windows Agent
.\sentrikat-agent.ps1 -Install
03

Automatic matching

SentriKat syncs the exploited-vulnerability feeds daily, one of them European, and enriches severity scores from three independent databases with automatic fallback. No single point of failure.

sync.log
# Daily sync at 2 AM UTC
[EXPLOITED] 3 exploited vulns matched
[EU] 1 EU-flagged vulnerability
[CVSS] primary -> enriched -> EU fallback
04

Multi-platform scanning

Native agents on Windows, Linux and macOS collect installed software. Where Docker is running, container images are scanned too.

scan.log
# Windows: 142 products detected
# Linux: 87 packages (dpkg)
# macOS: 63 applications
# Containers: 12 images scanned
[OK] 3 HIGH, 1 CRITICAL found
05

Act on real threats

Alerts by email, Slack, Microsoft Teams, or any SIEM over syslog. Tickets opened automatically in Jira, YouTrack, GitHub or GitLab. Prioritised by severity, due date and ransomware indicators.

actions.log
# Critical: CVE-2024-3400
# Due: 7 days | Ransomware: Yes
# -> Jira SK-142 created, SIEM notified
Detection Self-Check

Don't trust us.
Trust the verification.

SentriKat checks its own answers and shows you the result. An independent oracle re-checks every detection with a comparator that does not share the engine's code, plus a golden corpus built from your own inventory as a continuous regression proof. You see the outcome in-app, every week, on your data.

Ground-truth distro cross-check

Every detection is re-tested against independent distribution advisory data, the vendor's own source of truth, not the same feed the engine already used. If the two disagree, it's flagged.

Independent comparator, anti-false-positive

A second comparator that shares none of the detection engine's code re-derives each match. Anything the engine reports but the comparator can't confirm is surfaced as a discrepancy.

Independent comparator, anti-false-negative

The same independent comparator works the other direction: anything it finds that the engine missed is caught, so a silent gap in recall can't slip through unnoticed.

Golden floor on your top apps

A golden corpus generated from your real inventory becomes a continuous regression floor, the detections that must never break. Every run re-proves them, so an upgrade can't quietly regress coverage.

Admin Health Detection Self-Check

One line your auditor understands

No dashboards to interpret, no analyst required. The self-check runs on your instance, including fully air-gapped, and reports a single verdict you can act on and defend.

0 discrepancies
last run · weekly

Detection agrees with the independent references. False-positive gate, recall floor and ground-truth cross-check all passed.

Deterministic · Zero AI at runtime · Runs air-gapped · Every week, on your data

Mapped to the rules you are audited against

The rules you are audited against

NIS2 Ready

Article 21: risk management, incident reporting, supply chain.

GDPR Compliant

Data minimisation, and where the data physically sits.

DORA Ready

ICT risk for financial entities, and their providers.

And what we hold ourselves to: OWASP ASVS Level 1, OWASP Top 10, CWE Top 25, security headers, 12-Factor.

SentriKat Dependency Transparency
We scan our own supply chain, and publish the results
Checking...
Python
FastAPI, SQLAlchemy, cryptography
Node.js
Astro, Tailwind, React
Cross-referenced
Package, exploited and identity data
Last scan: loading...
View full report
Engine validation

"You're new. Is the engine reliable?"

Fair question, and the honest answer is facts, not adjectives. Detection is deterministic (no AI at match time, so results are reproducible and auditable), gate-tested every release, and self-monitored on every deployment.

~2,900 automated checks, 0 failing

A release gate ships nothing red. Every release is green across the full suite.

64/64 · 16/16 golden floors held

Deterministic CPE and per-distro goldens (8 families). A new false-positive class turns the gate red before it ships.

0 engine false positives

On a differential benchmark against Grype, 96.8% recall with zero false positives from the engine.

Weekly recall self-check in production

Every deployed instance measures its real recall on your own data and alarms if it drops. Quality is watched in production, not just in CI.

Behind it: 364,763 CVEs, 1,637 confirmed as exploited, 70,132 software identities, and 887,833 back-port-aware distro advisories across 8 Linux families. How we validate the engine.

Quick Start

Deploy in Minutes, Not Days

One command to install. Zero configuration needed.

sentrikat, agent install
< 5 MB

Lightweight agent, minimal footprint

3 Platforms

Windows, Linux, macOS

Auto-Update

Agents update themselves securely

Built-in Scanning

Container & Dependency Scanning

Automatically scan Docker images and open-source dependencies. Powered by Trivy, zero extra cost.

Container Image Scanning

  • Auto-detects Docker on endpoints
  • Scans all local images for HIGH and CRITICAL CVEs
  • Reports fix availability for every vulnerability
  • Included in all plans, no extra cost

Dependency Scanning (SCA)

  • 8 ecosystems: Node.js, Python, Go, Rust, Ruby, PHP, .NET, Java (Maven)
  • 13 lockfile formats supported
  • Automatic vulnerability lookups for every dependency
  • Version-verified matches with exact lockfile resolution

Powered by Trivy (Apache-2.0) and public package advisories, industry-standard open-source scanners

Where it fits

A specialist, not a suite

SentriKat does one job properly: it answers "which of my exposures are actually exploited and still unpatched, right now?" with certainty. It sits alongside the tools you already run, it doesn't pretend to be all of them.

What SentriKat does

  • Adjudicated vulnerability visibility
    What is exploited, how likely it is to be, and the vendor's back-port status, so you act on the handful that matters, not thousands of raw findings.
  • Full asset coverage
    OS packages, container images and code dependencies, back-port aware across 8 Linux families.
  • Compliance evidence, on demand
    NIS2 and DORA gap analysis and SBOMs (CycloneDX / SPDX / STIX), exported when you need them.
  • Yours to keep
    Runs on-premises or fully air-gapped, so vulnerability data never leaves the box. Built in Europe.

What it isn't

  • Not a SIEM or EDR/XDR
    It finds exposures. It doesn't watch endpoints or correlate logs.
  • Not IAM, PAM or backup
    Those stay in your stack. SentriKat sits alongside them, it doesn't replace them.
  • Not a sandbox or a patcher
    It tells you exactly what's exposed. Applying the fix and isolating the runtime is still your call.

The rest of your defences answer the other questions. This one answers its own, and shows you the working.

Free scanners like Trivy and Grype answer "do I have it?" once, for one image, and they do it well. SentriKat runs that as a continuous, de-noised process across your whole fleet: back-port aware, the exploited ones first, with the NIS2 and DORA evidence attached.

Machines, not just servers

Industrial equipment, checked by us

NIS2 covers energy, water, transport, manufacturing and health, and in those sectors the equipment that matters is not a laptop. It is a controller on a production line that has run untouched for nine years.

1
You send the list

Makes, models and firmware versions. A spreadsheet is fine. Nothing is installed on any of your equipment.

2
We match it

Against the same European vulnerability database the product runs on, including the exploited-in-the-wild list and exploitation probability.

3
You get a report

What is exploitable today, what can wait, and what has no fix. Written for the person who has to schedule the downtime.

What this is not

We do not put software on your industrial equipment and we do not connect anything to your control network. Nobody should, and the vendors who offer it charge for an appliance you do not need. This is a person reading your equipment list against a database that is already current, and telling you what to do about it.

Send us your equipment list

Tell us the sector and roughly how many devices. We will say what we can answer before you send anything.

Request an on-premises evaluation

Deploy SentriKat on your own infrastructure with a guided evaluation. We'll send you a licence key and setup guide within 24 hours.