Everything you need to manage vulnerabilities
Install once, scan everything. One platform, no modules, no per-asset pricing.
Version-verified CVEs, color-coded by severity, enriched with exploit probability and vendor patch data.
Install once, discover everything
One command to install. Automatic scan every 4 hours. Heartbeat every 5 minutes. The agent handles the rest.
| What it scans | How | Configuration |
|---|---|---|
| OS Packages | dpkg, RPM, pacman, Homebrew, WMI, Registry | Automatic |
| Browser Extensions | Chrome, Firefox, Edge, reads manifests directly | Automatic |
| IDE Plugins | VS Code, JetBrains (IntelliJ, PyCharm, etc.) | Automatic |
| Containers | Docker images (via integrated Trivy) | Automatic if Docker present |
| Code Dependencies | 13+ lockfile formats, 8 ecosystems (npm, pip, cargo, go, gem, composer, .NET, maven) | Automatic, finds lockfiles |
| Dependency Vulnerabilities | Version-verified matching per ogni dipendenza rilevata | Automatic, integrated |
Everything you need to manage vulnerabilities
Built for security teams who need to cut through the noise and focus on real threats.
Exploited Vulnerability Focus
Stop chasing every CVE. SentriKat verifies each vulnerability against the exact version of your installed software. Only confirmed matches, prioritized by real-world exploitation.
Only actively exploited vulnerabilities. No noise.
Zero-Day Intelligence
Instant alerts when a zero-day vulnerability affects software in your inventory. Aggregates disclosures from CISA emergency directives, vendor security advisories, and threat intelligence feeds. Dedicated tracking dashboard separates unpatched zero-day threats from regular KEV entries.
Vendor Advisory Sync
Queries OSV.dev, Red Hat, Microsoft MSRC, and Debian feeds daily. Automatically detects when vendors have patched vulnerabilities. Zero manual work.
Three-Tier Confidence
AFFECTED (red), LIKELY RESOLVED (amber), RESOLVED (green). Never silently hides a potential vulnerability. Vendor patch detection eliminates the most common source of false positives.
Software Inventory
Native agents for Windows, Linux, and macOS with distro-native version comparison (dpkg, RPM, APK). Integrates with Lansweeper, PDQ Deploy, SCCM, Intune, REST API, and CSV import.
Endpoint & Container Scanning
Native agents for Windows, Linux, and macOS scan endpoints and container images in one pass. Detect OS packages, installed applications, and container vulnerabilities across your entire infrastructure.
Windows, Linux, macOS, Docker, one agent
Code Dependency Scanning
Find known vulnerabilities in your open-source dependencies before they reach production. 13+ lockfile formats across 8 ecosystems with exact version matching, verified matches only, not CPE guessing. CI/CD native with GitHub Actions, GitLab CI, and Jenkins gate support.
Version-verified matches · exact lockfile resolution
Intelligent Matching
Multi-method CVE matching using CPE identifiers, vendor+product combinations, and keyword analysis with confidence scoring.
Notifications & Alerting
Email alerts with daily/weekly digests, Slack/Teams/Discord webhooks with HMAC-SHA256 signing, and custom alert rules by priority, organization, or product criticality. 3-tier escalation policies for unacknowledged critical vulnerabilities.
KEV match, due date, ransomware, agent offline & more
Multi-Tenant & White-Label
Isolated organizations with role-based access control and white-label branding. Customize your app name, logo, and colors in Admin Panel, branding applies to both the web UI and exported compliance documents. Perfect for MSPs or enterprises with multiple business units.
Self-Hosted & Air-Gapped
Your data stays with you. Deploy on your own infrastructure with Docker, including fully air-gapped environments. Built-in backup/restore and TOTP two-factor authentication.
SBOM Export
Generate a Software Bill of Materials for every host in one click. Native exports in <strong>CycloneDX 1.5</strong>, <strong>SPDX 2.3</strong>, and <strong>STIX 2.1</strong> bundles, plus <strong>VEX</strong> (CycloneDX), <strong>SARIF 2.1</strong>, <strong>CSAF 2.0</strong> and <strong>ServiceNow VR</strong> exports for your existing security pipeline. CRA-ready out of the box, the EU Cyber Resilience Act mandates SBOMs for software sold in Europe starting 11 September 2026. Tenable, Qualys, and Rapid7 charge extra for this; SentriKat includes it on every paid plan.
Compliance Reports (6 frameworks)
Signed gap-analysis reports with PASS / PARTIAL / FAIL verdict on every control. <strong>NIS2 Article 21</strong>, <strong>CISA BOD 22-01</strong>, <strong>DORA</strong>, <strong>PCI-DSS v4.0</strong> (Req 6.3, 11.3), <strong>ISO/IEC 27001:2022</strong> (A.8.8, A.8.16, A.5.24), and <strong>SOC 2</strong> (CC6.6, CC7.1, CC7.2, CC7.4). Every export carries an <strong>HMAC-SHA256 integrity block</strong>, auditors can verify the report hasn't been tampered with after generation. JSON, PDF or DOCX, white-label branding included.
JSON, PDF or DOCX · PASS / PARTIAL / FAIL per control
SIEM Integration
Stream vulnerability events to your SIEM via syslog in CEF, JSON, or RFC 5424 format. Native support for Splunk, Elastic/ELK, ArcSight, and QRadar.
Multi-Source Intelligence
CVSS scores from 3 independent sources (NVD, CVE.org/Vulnrichment, ENISA EUVD) with automatic fallback. Exploited vulnerability data from both CISA KEV and EUVD. Every score carries a provenance tag.
EPSS Scoring
Integrates FIRST's Exploit Prediction Scoring System to prioritize vulnerabilities most likely to be exploited.
Exploit probability in next 30 days
Background Sync
Automatic scheduled tasks keep your data current without manual intervention. CISA KEV, EUVD, and vendor advisories sync daily, EPSS scores update regularly, and NVD CPE dictionary refreshes weekly. Configurable cron schedules.
All tasks start on boot. Custom cron schedules supported.
Agent Management
Server-side agent configuration, minimum version enforcement, and heartbeat monitoring. Agents check in regularly and receive configuration updates automatically. MDM-compatible deployment for macOS (Jamf, Kandji, Mosyle).
Heartbeat monitoring, config push & version enforcement
Authentication & SSO
Enterprise authentication with Active Directory, LDAP, SAML 2.0, and TOTP two-factor authentication. Centralized user management.
System Health Checks
10 automated health checks run every 30 minutes, database, disk space, workers, CVE sync freshness, agent heartbeats, and more. Email notifications and in-app alerts surface critical issues before they escalate.
10 checks · every 30 min · email & in-app alerts
Enterprise Scale
Tested to 10,000+ agents. Concurrent worker pool, configurable database tuning, exponential backoff retry, and built-in load testing. Tune deployment size via environment variables, no code changes needed.
Tune via env vars · no code changes
Built-in Admin Tools
GUI log viewer with 7 log types, full-text search, and download. Interactive API documentation via Swagger UI. Built-in troubleshooting guide with Docker commands and common scenarios. No SSH required.
Swipe tabs or tap to explore
Intelligence from 6+ Authoritative Sources
Active Threat Detection
Continuously monitors confirmed exploited vulnerabilities across US and EU threat catalogs
Version-Verified Matching
Every CVE matched against the software versions in your environment, with an explicit confidence level per match, so you can cut the noise.
Predictive Prioritization
EPSS exploit-prediction scoring (FIRST.org), prioritize by real-world exploitation likelihood, not just severity
Dependency Scanning
Built-in SCA across 8 ecosystems and 13+ lockfile formats with version-verified matching
EU Compliance Ready
Native European vulnerability database integration for NIS2 and DORA compliance
Vendor Patch Intelligence
Daily patch status from major vendors, know when fixes are available, not just vulnerabilities
Deterministic & Verified Detection
No AI at runtime. A deterministic engine, anti-false-positive gate, CPE matching, orchestration, suppression, that is mutation-tested, validated against real public CVEs, and self-checks its recall on every instance. Reproducible results you can defend to an auditor.
Don't trust us.
Trust the verification.
SentriKat is the only vulnerability management that verifies itself. An independent oracle re-checks every detection with a comparator that doesn't share the engine's code, plus a golden corpus built from your own inventory as a continuous regression proof. You see the result in-app, every week, on your data.
Ground-truth distro cross-check
Every detection is re-tested against independent distribution advisory data, the vendor's own source of truth, not the same feed the engine already used. If the two disagree, it's flagged.
Independent comparator, anti-false-positive
A second comparator that shares none of the detection engine's code re-derives each match. Anything the engine reports but the comparator can't confirm is surfaced as a discrepancy.
Independent comparator, anti-false-negative
The same independent comparator works the other direction: anything it finds that the engine missed is caught, so a silent gap in recall can't slip through unnoticed.
Golden floor on your top apps
A golden corpus generated from your real inventory becomes a continuous regression floor, the detections that must never break. Every run re-proves them, so an upgrade can't quietly regress coverage.
One line your auditor understands
No dashboards to interpret, no analyst required. The self-check runs on your instance, including fully air-gapped, and reports a single verdict you can act on and defend.
Detection agrees with the independent references. False-positive gate, recall floor and ground-truth cross-check all passed.
Deploy in Minutes, Not Days
Lightweight agent, minimal footprint
Windows, Linux, macOS
Agents update themselves securely
Container & Dependency Scanning
Automatically scan Docker images and open-source dependencies. Powered by Trivy, zero extra cost.
Container Image Scanning
- Auto-detects Docker on endpoints
- Scans all local images for HIGH and CRITICAL CVEs
- Reports fix availability for every vulnerability
- Included in all plans, no extra cost
Dependency Scanning (SCA)
- 8 ecosystems: Node.js, Python, Go, Rust, Ruby, PHP, .NET, Java (Maven)
- 13 lockfile formats supported
- Automatic vulnerability lookups for every dependency
- Version-verified matches with exact lockfile resolution
Powered by Trivy (Apache-2.0) and OSV.dev, industry-standard open-source scanners
Ready to try it?
Every plan ships with its full feature set. Launch pricing for founding customers.
Get started