SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started
Platform

Everything you need to manage vulnerabilities

Install once, scan everything. One platform, no modules, no per-asset pricing.

Vulnerability View, Prioritized by real-world risk
SentriKat vulnerability dashboard showing CVEs prioritized by severity with version-verified matching and vendor patch status

Version-verified CVEs, color-coded by severity, enriched with exploit probability and vendor patch data.

Zero Configuration

Install once, discover everything

One command to install. Automatic scan every 4 hours. Heartbeat every 5 minutes. The agent handles the rest.

What it scans How Configuration
OS Packages dpkg, RPM, pacman, Homebrew, WMI, Registry Automatic
Browser Extensions Chrome, Firefox, Edge, reads manifests directly Automatic
IDE Plugins VS Code, JetBrains (IntelliJ, PyCharm, etc.) Automatic
Containers Docker images (via integrated Trivy) Automatic if Docker present
Code Dependencies 13+ lockfile formats, 8 ecosystems (npm, pip, cargo, go, gem, composer, .NET, maven) Automatic, finds lockfiles
Dependency Vulnerabilities Version-verified matching per ogni dipendenza rilevata Automatic, integrated
Features

Everything you need to manage vulnerabilities

Built for security teams who need to cut through the noise and focus on real threats.

Core Feature

Exploited Vulnerability Focus

Stop chasing every CVE. SentriKat verifies each vulnerability against the exact version of your installed software. Only confirmed matches, prioritized by real-world exploitation.

CVE-2024-3400
CRITICAL
CVE-2024-21887
HIGH
248,500+ other CVEs
FILTERED

Only actively exploited vulnerabilities. No noise.

New

Zero-Day Intelligence

Instant alerts when a zero-day vulnerability affects software in your inventory. Aggregates disclosures from CISA emergency directives, vendor security advisories, and threat intelligence feeds. Dedicated tracking dashboard separates unpatched zero-day threats from regular KEV entries.

CVE-2024-3400 PAN-OS Command Injection
0-DAY
CVE-2024-21887 Ivanti Connect Secure RCE
0-DAY
CVE-2024-1709 ScreenConnect Auth Bypass
PATCH AVAIL
3
Active 0-Days
7
Patch Available
24
Endpoints Hit
Unique

Vendor Advisory Sync

Queries OSV.dev, Red Hat, Microsoft MSRC, and Debian feeds daily. Automatically detects when vendors have patched vulnerabilities. Zero manual work.

OSV.dev synced 2m ago
Red Hat Security API synced 2m ago
Microsoft MSRC synced 15m ago
Debian Security Tracker synced 15m ago
Unique

Three-Tier Confidence

AFFECTED (red), LIKELY RESOLVED (amber), RESOLVED (green). Never silently hides a potential vulnerability. Vendor patch detection eliminates the most common source of false positives.

AFFECTED No vendor fix detected
LIKELY RESOLVED Vendor fix detected
RESOLVED Fix confirmed via version check
Flexible

Software Inventory

Native agents for Windows, Linux, and macOS with distro-native version comparison (dpkg, RPM, APK). Integrates with Lansweeper, PDQ Deploy, SCCM, Intune, REST API, and CSV import.

Windows
Agent
Linux
Agent
macOS
Agent
Lansweeper
Sync
SCCM
Intune
REST
API
New

Endpoint & Container Scanning

Native agents for Windows, Linux, and macOS scan endpoints and container images in one pass. Detect OS packages, installed applications, and container vulnerabilities across your entire infrastructure.

$ sentrikat-agent status
Windows, 142 products collected
Linux, 87 packages (dpkg)
macOS, 63 applications
Containers, 12 images scanned
nginx:1.25, 0 vulnerabilities
app:latest, 1 CRITICAL, 3 HIGH

Windows, Linux, macOS, Docker, one agent

New

Code Dependency Scanning

Find known vulnerabilities in your open-source dependencies before they reach production. 13+ lockfile formats across 8 ecosystems with exact version matching, verified matches only, not CPE guessing. CI/CD native with GitHub Actions, GitLab CI, and Jenkins gate support.

8 Ecosystems · 13 Lockfile Formats
Node.js package-lock.json · yarn.lock · pnpm-lock.yaml
Python Pipfile.lock · poetry.lock
Rust Cargo.lock
Go go.sum · go.mod
Ruby Gemfile.lock
PHP composer.lock
.NET packages.lock.json
OSV.dev
Powered
CI/CD
Native
EPSS+KEV
Prioritized

Version-verified matches · exact lockfile resolution

Smart

Intelligent Matching

Multi-method CVE matching using CPE identifiers, vendor+product combinations, and keyword analysis with confidence scoring.

CPE Match 98%
Vendor + Product 85%
Keyword Analysis 72%
Pro

Notifications & Alerting

Email alerts with daily/weekly digests, Slack/Teams/Discord webhooks with HMAC-SHA256 signing, and custom alert rules by priority, organization, or product criticality. 3-tier escalation policies for unacknowledged critical vulnerabilities.

Email AlertsDaily & weekly digests
🔌
WebhooksSlack / Teams / Discord
🎯
Issue TrackersJira / GitHub / GitLab / YouTrack
⚠️
Escalation Policies24h / 72h auto-escalation

KEV match, due date, ransomware, agent offline & more

Pro

Multi-Tenant & White-Label

Isolated organizations with role-based access control and white-label branding. Customize your app name, logo, and colors in Admin Panel, branding applies to both the web UI and exported compliance documents. Perfect for MSPs or enterprises with multiple business units.

Org: Acme Corp
3 admins · 12 viewers · 847 products
Org: Beta Industries
1 admin · 5 viewers · 231 products
Org: Gamma GmbH
2 admins · 8 viewers · 502 products
Privacy

Self-Hosted & Air-Gapped

Your data stays with you. Deploy on your own infrastructure with Docker, including fully air-gapped environments. Built-in backup/restore and TOTP two-factor authentication.

# Your infrastructure, your data
$ docker compose up -d
Creating sentrikat-db   ... done
Creating sentrikat-app ... done
Creating sentrikat-web ... done
✓ SentriKat running on https://localhost
✓ Air-gapped & TOTP 2FA ready
New

SBOM Export

Generate a Software Bill of Materials for every host in one click. Native exports in <strong>CycloneDX 1.5</strong>, <strong>SPDX 2.3</strong>, and <strong>STIX 2.1</strong> bundles, plus <strong>VEX</strong> (CycloneDX), <strong>SARIF 2.1</strong>, <strong>CSAF 2.0</strong> and <strong>ServiceNow VR</strong> exports for your existing security pipeline. CRA-ready out of the box, the EU Cyber Resilience Act mandates SBOMs for software sold in Europe starting 11 September 2026. Tenable, Qualys, and Rapid7 charge extra for this; SentriKat includes it on every paid plan.

JSON
CycloneDX 1.5 OWASP standard · CRA & EO 14028
JSON
SPDX 2.3 Linux Foundation · ISO/IEC 5962
STIX
STIX 2.1 bundle Threat-intel handoff to SOC/ISAC
Cyber Resilience Act, ready Deadline: 11 September 2026
New

Compliance Reports (6 frameworks)

Signed gap-analysis reports with PASS / PARTIAL / FAIL verdict on every control. <strong>NIS2 Article 21</strong>, <strong>CISA BOD 22-01</strong>, <strong>DORA</strong>, <strong>PCI-DSS v4.0</strong> (Req 6.3, 11.3), <strong>ISO/IEC 27001:2022</strong> (A.8.8, A.8.16, A.5.24), and <strong>SOC 2</strong> (CC6.6, CC7.1, CC7.2, CC7.4). Every export carries an <strong>HMAC-SHA256 integrity block</strong>, auditors can verify the report hasn't been tampered with after generation. JSON, PDF or DOCX, white-label branding included.

EU NIS2 Art. 21
US BOD 22-01
FIN DORA
PCI PCI-DSS v4.0
ISO 27001:2022
SOC SOC 2
HMAC-SHA256 integrity block Tamper-evident · audit-ready

JSON, PDF or DOCX · PASS / PARTIAL / FAIL per control

New

SIEM Integration

Stream vulnerability events to your SIEM via syslog in CEF, JSON, or RFC 5424 format. Native support for Splunk, Elastic/ELK, ArcSight, and QRadar.

CEF:0|SentriKat|VulnMgmt|1.0|KEV_MATCH|
severity=Critical cve=CVE-2024-3400
product=PAN-OS status=AFFECTED
dst=siem.company.local:514
Splunk
ELK
ArcSight
QRadar
New

Multi-Source Intelligence

CVSS scores from 3 independent sources (NVD, CVE.org/Vulnrichment, ENISA EUVD) with automatic fallback. Exploited vulnerability data from both CISA KEV and EUVD. Every score carries a provenance tag.

CVSS Fallback Chain
NIST NVD PRIMARY
miss?
CVE.org + Vulnrichment SECONDARY
miss?
EU ENISA EUVD TERTIARY
Every score tagged: cvss_source: "nvd" | "cve_org" | "euvd"
Intelligence

EPSS Scoring

Integrates FIRST's Exploit Prediction Scoring System to prioritize vulnerabilities most likely to be exploited.

CVE-2024-3400
97.2%
CVE-2024-1709
82.1%
CVE-2024-0012
44.8%

Exploit probability in next 30 days

Automatic

Background Sync

Automatic scheduled tasks keep your data current without manual intervention. CISA KEV, EUVD, and vendor advisories sync daily, EPSS scores update regularly, and NVD CPE dictionary refreshes weekly. Configurable cron schedules.

CISA KEV Sync
Daily at 2 AM
ENISA EUVD Sync
Daily (EU)
Vendor Advisories
Daily (8 distro feeds)
EPSS Scores
Daily
NVD CPE Dictionary
Weekly (~50K entries)
License Check
Every 6 hours

All tasks start on boot. Custom cron schedules supported.

New

Agent Management

Server-side agent configuration, minimum version enforcement, and heartbeat monitoring. Agents check in regularly and receive configuration updates automatically. MDM-compatible deployment for macOS (Jamf, Kandji, Mosyle).

win-srv-01
v1.0.2, online
ubuntu-app-03
v1.0.2, online
macbook-dev-07
v1.0.2, online
rhel-db-02
v1.0.1, update available

Heartbeat monitoring, config push & version enforcement

Pro

Authentication & SSO

Enterprise authentication with Active Directory, LDAP, SAML 2.0, and TOTP two-factor authentication. Centralized user management.

AD Active Directory / LDAP
SA SAML 2.0 SSO
2F TOTP Two-Factor Auth
New

System Health Checks

10 automated health checks run every 30 minutes, database, disk space, workers, CVE sync freshness, agent heartbeats, and more. Email notifications and in-app alerts surface critical issues before they escalate.

Database
Healthy
CVE Sync
Fresh (2h ago)
Background Workers
Running
Disk Space
Warning (82%)

10 checks · every 30 min · email & in-app alerts

New

Enterprise Scale

Tested to 10,000+ agents. Concurrent worker pool, configurable database tuning, exponential backoff retry, and built-in load testing. Tune deployment size via environment variables, no code changes needed.

# Enterprise sizing (.env)
GUNICORN_WORKERS=16
WORKER_POOL_SIZE=16
DB_POOL_SIZE=20
PG_MAX_CONNECTIONS=800
✓ 10,000+ agents supported
16
Workers
5x
Auto-Retry
800
DB Conns

Tune via env vars · no code changes

New

Built-in Admin Tools

GUI log viewer with 7 log types, full-text search, and download. Interactive API documentation via Swagger UI. Built-in troubleshooting guide with Docker commands and common scenarios. No SSH required.

LOG
System Log Viewer 7 log types · search & download
API
Interactive API Docs OpenAPI / Swagger UI
OPS
Admin Guide Troubleshooting & Docker cheat sheet
AUD
Audit Logs Full user activity trail

Swipe tabs or tap to explore

Vulnerability Intelligence

Intelligence from 6+ Authoritative Sources

SentriKat continuously aggregates, correlates, and enriches vulnerability data from government, industry, and open-source intelligence feeds.

Active Threat Detection

Continuously monitors confirmed exploited vulnerabilities across US and EU threat catalogs

Version-Verified Matching

Every CVE matched against the software versions in your environment, with an explicit confidence level per match, so you can cut the noise.

Predictive Prioritization

EPSS exploit-prediction scoring (FIRST.org), prioritize by real-world exploitation likelihood, not just severity

Dependency Scanning

Built-in SCA across 8 ecosystems and 13+ lockfile formats with version-verified matching

EU Compliance Ready

Native European vulnerability database integration for NIS2 and DORA compliance

Vendor Patch Intelligence

Daily patch status from major vendors, know when fixes are available, not just vulnerabilities

Deterministic & Verified Detection

No AI at runtime. A deterministic engine, anti-false-positive gate, CPE matching, orchestration, suppression, that is mutation-tested, validated against real public CVEs, and self-checks its recall on every instance. Reproducible results you can defend to an auditor.

Built-in resilience: automatic failover between sources ensures uninterrupted coverage even when upstream feeds go down
Detection Self-Check

Don't trust us.
Trust the verification.

SentriKat is the only vulnerability management that verifies itself. An independent oracle re-checks every detection with a comparator that doesn't share the engine's code, plus a golden corpus built from your own inventory as a continuous regression proof. You see the result in-app, every week, on your data.

Ground-truth distro cross-check

Every detection is re-tested against independent distribution advisory data, the vendor's own source of truth, not the same feed the engine already used. If the two disagree, it's flagged.

Independent comparator, anti-false-positive

A second comparator that shares none of the detection engine's code re-derives each match. Anything the engine reports but the comparator can't confirm is surfaced as a discrepancy.

Independent comparator, anti-false-negative

The same independent comparator works the other direction: anything it finds that the engine missed is caught, so a silent gap in recall can't slip through unnoticed.

Golden floor on your top apps

A golden corpus generated from your real inventory becomes a continuous regression floor, the detections that must never break. Every run re-proves them, so an upgrade can't quietly regress coverage.

Admin Health Detection Self-Check

One line your auditor understands

No dashboards to interpret, no analyst required. The self-check runs on your instance, including fully air-gapped, and reports a single verdict you can act on and defend.

0 discrepancies
last run · weekly

Detection agrees with the independent references. False-positive gate, recall floor and ground-truth cross-check all passed.

Deterministic · Zero AI at runtime · Runs air-gapped · Every week, on your data
Quick Start

Deploy in Minutes, Not Days

One command to install. Zero configuration needed.

sentrikat, agent install
< 5 MB

Lightweight agent, minimal footprint

3 Platforms

Windows, Linux, macOS

Auto-Update

Agents update themselves securely

Built-in Scanning

Container & Dependency Scanning

Automatically scan Docker images and open-source dependencies. Powered by Trivy, zero extra cost.

Container Image Scanning

  • Auto-detects Docker on endpoints
  • Scans all local images for HIGH and CRITICAL CVEs
  • Reports fix availability for every vulnerability
  • Included in all plans, no extra cost

Dependency Scanning (SCA)

  • 8 ecosystems: Node.js, Python, Go, Rust, Ruby, PHP, .NET, Java (Maven)
  • 13 lockfile formats supported
  • Automatic vulnerability lookups for every dependency
  • Version-verified matches with exact lockfile resolution

Powered by Trivy (Apache-2.0) and OSV.dev, industry-standard open-source scanners

Ready to try it?

Every plan ships with its full feature set. Launch pricing for founding customers.

Get started