Everything you need to manage vulnerabilities
Install once, scan everything. One platform, no modules, no per-asset pricing.
Version-verified CVEs, color-coded by severity, enriched with exploit probability and vendor patch data.
Install once, discover everything
One command to install. Automatic scan every 4 hours. Heartbeat every 5 minutes. The agent handles the rest.
| What it scans | How | Configuration |
|---|---|---|
| OS Packages | dpkg, RPM, pacman, Homebrew, WMI, Registry | Automatic |
| Browser Extensions | Chrome, Firefox, Edge, reads manifests directly | Automatic |
| IDE Plugins | VS Code, JetBrains (IntelliJ, PyCharm, etc.) | Automatic |
| Containers | Docker images (via integrated Trivy) | Automatic if Docker present |
| Code Dependencies | 13+ lockfile formats, 8 ecosystems (npm, pip, cargo, go, gem, composer, .NET, maven) | Automatic, finds lockfiles |
| Dependency Vulnerabilities | Version-verified matching for every dependency found | Automatic, integrated |
Everything you need to manage vulnerabilities
Built for security teams who need to cut through the noise and focus on real threats.
Exploited Vulnerability Focus
Stop chasing every CVE. SentriKat verifies each vulnerability against the exact version of your installed software. Only confirmed matches, prioritized by real-world exploitation.
Only actively exploited vulnerabilities. No noise.
Zero-Day Intelligence
Instant alerts when a zero-day vulnerability affects software in your inventory. Aggregates emergency directives, vendor security advisories, and threat intelligence. A dedicated dashboard separates unpatched zero-day threats from the vulnerabilities already known to be exploited.
Vendor Advisory Sync
Reads package and vendor advisories daily, across Linux distributions and Microsoft. Automatically detects when a vendor has patched a vulnerability. Zero manual work.
Three-Tier Confidence
AFFECTED (red), LIKELY RESOLVED (amber), RESOLVED (green). Never silently hides a potential vulnerability. Vendor patch detection eliminates the most common source of false positives.
Software Inventory
Native agents for Windows, Linux, and macOS with distro-native version comparison (dpkg, RPM, APK). Integrates with Lansweeper, PDQ Deploy, SCCM, Intune, REST API, and CSV import.
Endpoint & Container Scanning
Native agents for Windows, Linux, and macOS scan endpoints and container images in one pass. Detect OS packages, installed applications, and container vulnerabilities across your entire infrastructure.
Windows, Linux, macOS, Docker, one agent
Code Dependency Scanning
Find known vulnerabilities in your open-source dependencies before they reach production. 13+ lockfile formats across 8 ecosystems with exact version matching, verified matches only, not CPE guessing. CI/CD native with GitHub Actions, GitLab CI, and Jenkins gate support.
Version-verified matches · exact lockfile resolution
Intelligent Matching
Multi-method CVE matching using CPE identifiers, vendor+product combinations, and keyword analysis with confidence scoring.
Notifications & Alerting
Email alerts with daily/weekly digests, Slack/Teams/Discord webhooks with HMAC-SHA256 signing, and custom alert rules by priority, organization, or product criticality. 3-tier escalation policies for unacknowledged critical vulnerabilities.
Exploited in the wild, due date, ransomware, agent offline & more
Multi-Tenant & White-Label
Isolated organizations with role-based access control and white-label branding. Customize your app name, logo, and colors in Admin Panel, branding applies to both the web UI and exported compliance documents. Perfect for MSPs or enterprises with multiple business units.
Self-Hosted & Air-Gapped
Your data stays with you. Deploy on your own infrastructure with Docker, including fully air-gapped environments. Built-in backup/restore and TOTP two-factor authentication.
SBOM Export
Generate a Software Bill of Materials for every host in one click. Native exports in CycloneDX 1.5, SPDX 2.3, and STIX 2.1 bundles, plus VEX (CycloneDX), SARIF 2.1, CSAF 2.0 and ServiceNow VR exports for your existing security pipeline. CRA-ready out of the box, the EU Cyber Resilience Act mandates SBOMs for software sold in Europe starting 11 September 2026. Tenable, Qualys, and Rapid7 charge extra for this; SentriKat includes it on every paid plan.
Compliance Reports (6 frameworks)
Signed gap-analysis reports with PASS / PARTIAL / FAIL verdict on every control. NIS2 Article 21, exploited-vulnerability compliance, DORA, PCI-DSS v4.0 (Req 6.3, 11.3), ISO/IEC 27001:2022 (A.8.8, A.8.16, A.5.24), and SOC 2 (CC6.6, CC7.1, CC7.2, CC7.4). Every export carries an HMAC-SHA256 integrity block, auditors can verify the report hasn't been tampered with after generation. JSON, PDF or DOCX, white-label branding included.
JSON, PDF or DOCX · PASS / PARTIAL / FAIL per control
SIEM Integration
Stream vulnerability events to your SIEM via syslog in CEF, JSON, or RFC 5424 format. Native support for Splunk, Elastic/ELK, ArcSight, and QRadar.
Multi-Source Intelligence
Severity scores from three independent public databases, with automatic fallback when one is silent or disagrees. Exploited-vulnerability data from two of them, one European. Every score carries a provenance tag saying which one it came from.
Exploit Probability
Every vulnerability carries the probability that somebody actually exploits it, so you fix first what is most likely to be used against you.
Exploit probability in next 30 days
Background Sync
Scheduled tasks keep your data current without manual intervention. Exploited-vulnerability feeds and vendor advisories sync daily, exploit probabilities update regularly, and the software identity catalogue refreshes weekly. Configurable cron schedules.
All tasks start on boot. Custom cron schedules supported.
Agent Management
Server-side agent configuration, minimum version enforcement, and heartbeat monitoring. Agents check in regularly and receive configuration updates automatically. MDM-compatible deployment for macOS (Jamf, Kandji, Mosyle).
Heartbeat monitoring, config push & version enforcement
Authentication & SSO
Enterprise authentication with Active Directory, LDAP, SAML 2.0, and TOTP two-factor authentication. Centralized user management.
System Health Checks
10 automated health checks run every 30 minutes, database, disk space, workers, CVE sync freshness, agent heartbeats, and more. Email notifications and in-app alerts surface critical issues before they escalate.
10 checks · every 30 min · email & in-app alerts
Enterprise Scale
Concurrent worker pool, configurable database tuning, exponential backoff retry, and built-in load testing. Tune deployment size via environment variables, no code changes needed. We do not publish an agent ceiling: the sizing guidance in the docs is what we can show, and a number we have not measured is not one we will put on a page.
Tune via env vars · no code changes
Built-in Admin Tools
GUI log viewer with 7 log types, full-text search, and download. Interactive API documentation via Swagger UI. Built-in troubleshooting guide with Docker commands and common scenarios. No SSH required.
Swipe tabs or tap to explore
Most scanners tell you what's wrong.
SentriKat tells you what's actually fixed.
Traditional scanners generate thousands of alerts with no context on which ones a vendor patch has already resolved. SentriKat tracks vendor advisories automatically, so you only act on what is still real.
Automatic vendor advisory sync
SentriKat queries 6 vendor feeds daily and cross-references them against your inventory. When Red Hat backports a fix or Microsoft pushes a KB, SentriKat knows automatically.
Three-tier confidence system
Every vulnerability gets a confidence tier based on automated vendor analysis. Amber items stay visible for legal compliance. Green items are auto-acknowledged.
Distro-native version comparison
SentriKat understands how your OS compares package versions, backport-aware across 8 Linux families. No generic string comparison, just real package manager logic for accurate results.
2.31-13+deb11u7 > 2.31-13+deb11u5
4.18.0-425.19.2.el8_7 > 4.18.0-425.3.1
1.36.1-r15 > 1.36.1-r2
Everything included. No add-ons.
Windows, Linux, macOS, container scanning, NIS2 compliance reports, and executive PDFs, all included in the Professional Edition. No separate modules, no hidden costs.
Integrates with Jira, YouTrack, GitHub, GitLab, Slack, Microsoft Teams, and any SIEM via syslog / CEF / LEEF. Single Sign-On via SAML 2.0 (Keycloak, Azure AD, Okta, Google Workspace). User directory sync via LDAP and Active Directory.
Typical Enterprise Scanner
$10,000+/yr
Per module add-on
SIEM + Compliance
Extra modules
Custom pricing
SentriKat
All Included
From €59/mo (Cloud) or €4,999/yr (On-Prem)
European vulnerability intelligence, first
The European database as the primary source
The EU's own vulnerability database, read first and in full, not as an afterthought. It carries the affected products and versions that the larger American database increasingly leaves out, which is what makes a match actionable.
Active Threat Detection
Continuously monitors confirmed exploited vulnerabilities across more than one authoritative catalog
Version-Verified Matching
Every CVE matched against the software versions in your environment, with an explicit confidence level per match, so you can cut the noise.
Predictive Prioritization
Exploit-probability scoring, prioritize by real-world exploitation likelihood, not just severity
Dependency Scanning
Built-in SCA across 8 ecosystems and 13+ lockfile formats with version-verified matching
Vendor Patch Intelligence
Daily patch status from major vendors, know when fixes are available, not just vulnerabilities
Deterministic & Verified Detection
No AI at runtime. A deterministic engine, anti-false-positive gate, CPE matching, orchestration, suppression, that is mutation-tested, validated against real public CVEs, and self-checks its recall on every instance. Reproducible results you can defend to an auditor.
From deployment to protection in minutes
SentriKat is designed to be simple. No complex setup, no steep learning curve.
Deploy SentriKat
Self-host with Docker in minutes. One command to get started. Your data, your infrastructure.
docker compose up -d
Import your inventory
Deploy agents on Windows, Linux or macOS. Integrate with Lansweeper, SCCM or Intune, or import a CSV.
# Windows Agent .\sentrikat-agent.ps1 -Install
Automatic matching
SentriKat syncs the exploited-vulnerability feeds daily, one of them European, and enriches severity scores from three independent databases with automatic fallback. No single point of failure.
# Daily sync at 2 AM UTC [EXPLOITED] 3 exploited vulns matched [EU] 1 EU-flagged vulnerability [CVSS] primary -> enriched -> EU fallback
Multi-platform scanning
Native agents on Windows, Linux and macOS collect installed software. Where Docker is running, container images are scanned too.
# Windows: 142 products detected # Linux: 87 packages (dpkg) # macOS: 63 applications # Containers: 12 images scanned [OK] 3 HIGH, 1 CRITICAL found
Act on real threats
Alerts by email, Slack, Microsoft Teams, or any SIEM over syslog. Tickets opened automatically in Jira, YouTrack, GitHub or GitLab. Prioritised by severity, due date and ransomware indicators.
# Critical: CVE-2024-3400 # Due: 7 days | Ransomware: Yes # -> Jira SK-142 created, SIEM notified
Don't trust us.
Trust the verification.
SentriKat checks its own answers and shows you the result. An independent oracle re-checks every detection with a comparator that does not share the engine's code, plus a golden corpus built from your own inventory as a continuous regression proof. You see the outcome in-app, every week, on your data.
Ground-truth distro cross-check
Every detection is re-tested against independent distribution advisory data, the vendor's own source of truth, not the same feed the engine already used. If the two disagree, it's flagged.
Independent comparator, anti-false-positive
A second comparator that shares none of the detection engine's code re-derives each match. Anything the engine reports but the comparator can't confirm is surfaced as a discrepancy.
Independent comparator, anti-false-negative
The same independent comparator works the other direction: anything it finds that the engine missed is caught, so a silent gap in recall can't slip through unnoticed.
Golden floor on your top apps
A golden corpus generated from your real inventory becomes a continuous regression floor, the detections that must never break. Every run re-proves them, so an upgrade can't quietly regress coverage.
One line your auditor understands
No dashboards to interpret, no analyst required. The self-check runs on your instance, including fully air-gapped, and reports a single verdict you can act on and defend.
Detection agrees with the independent references. False-positive gate, recall floor and ground-truth cross-check all passed.
The rules you are audited against
"You're new. Is the engine reliable?"
Fair question, and the honest answer is facts, not adjectives. Detection is deterministic (no AI at match time, so results are reproducible and auditable), gate-tested every release, and self-monitored on every deployment.
A release gate ships nothing red. Every release is green across the full suite.
Deterministic CPE and per-distro goldens (8 families). A new false-positive class turns the gate red before it ships.
On a differential benchmark against Grype, 96.8% recall with zero false positives from the engine.
Every deployed instance measures its real recall on your own data and alarms if it drops. Quality is watched in production, not just in CI.
Behind it: 364,763 CVEs, 1,637 confirmed as exploited, 70,132 software identities, and 887,833 back-port-aware distro advisories across 8 Linux families. How we validate the engine.
Deploy in Minutes, Not Days
Lightweight agent, minimal footprint
Windows, Linux, macOS
Agents update themselves securely
Container & Dependency Scanning
Automatically scan Docker images and open-source dependencies. Powered by Trivy, zero extra cost.
Container Image Scanning
- Auto-detects Docker on endpoints
- Scans all local images for HIGH and CRITICAL CVEs
- Reports fix availability for every vulnerability
- Included in all plans, no extra cost
Dependency Scanning (SCA)
- 8 ecosystems: Node.js, Python, Go, Rust, Ruby, PHP, .NET, Java (Maven)
- 13 lockfile formats supported
- Automatic vulnerability lookups for every dependency
- Version-verified matches with exact lockfile resolution
Powered by Trivy (Apache-2.0) and public package advisories, industry-standard open-source scanners
A specialist, not a suite
SentriKat does one job properly: it answers "which of my exposures are actually exploited and still unpatched, right now?" with certainty. It sits alongside the tools you already run, it doesn't pretend to be all of them.
What SentriKat does
-
Adjudicated vulnerability visibilityWhat is exploited, how likely it is to be, and the vendor's back-port status, so you act on the handful that matters, not thousands of raw findings.
-
Full asset coverageOS packages, container images and code dependencies, back-port aware across 8 Linux families.
-
Compliance evidence, on demandNIS2 and DORA gap analysis and SBOMs (CycloneDX / SPDX / STIX), exported when you need them.
-
Yours to keepRuns on-premises or fully air-gapped, so vulnerability data never leaves the box. Built in Europe.
What it isn't
-
Not a SIEM or EDR/XDRIt finds exposures. It doesn't watch endpoints or correlate logs.
-
Not IAM, PAM or backupThose stay in your stack. SentriKat sits alongside them, it doesn't replace them.
-
Not a sandbox or a patcherIt tells you exactly what's exposed. Applying the fix and isolating the runtime is still your call.
The rest of your defences answer the other questions. This one answers its own, and shows you the working.
Free scanners like Trivy and Grype answer "do I have it?" once, for one image, and they do it well. SentriKat runs that as a continuous, de-noised process across your whole fleet: back-port aware, the exploited ones first, with the NIS2 and DORA evidence attached.
Industrial equipment, checked by us
NIS2 covers energy, water, transport, manufacturing and health, and in those sectors the equipment that matters is not a laptop. It is a controller on a production line that has run untouched for nine years.
Makes, models and firmware versions. A spreadsheet is fine. Nothing is installed on any of your equipment.
Against the same European vulnerability database the product runs on, including the exploited-in-the-wild list and exploitation probability.
What is exploitable today, what can wait, and what has no fix. Written for the person who has to schedule the downtime.
What this is not
We do not put software on your industrial equipment and we do not connect anything to your control network. Nobody should, and the vendors who offer it charge for an appliance you do not need. This is a person reading your equipment list against a database that is already current, and telling you what to do about it.
Tell us the sector and roughly how many devices. We will say what we can answer before you send anything.
Request an on-premises evaluation
Deploy SentriKat on your own infrastructure with a guided evaluation. We'll send you a licence key and setup guide within 24 hours.