Skip to content

Welcome to SentriKat

  • SaaS, Start in 2 Minutes SaaS


    No installation needed. Sign up, deploy agents, see results. Free during Early Access.

    SaaS Quick Guides

  • Self-Hosted, Full Control On-Prem


    Deploy on your own infrastructure with Docker. Air-gapped and TOTP 2FA supported.

    Installation Guide

  • Focus on Real Threats Both


    Stop drowning in 200,000+ CVEs. SentriKat focuses on the vulnerabilities that are publicly confirmed as being actively exploited in the wild: a small, actionable fraction of the total.

    User Guide

  • Powerful API Both


    RESTful API for all operations. Integrate with your existing tools and workflows.

    API Reference

What is SentriKat?

SentriKat is an enterprise-grade vulnerability management platform that focuses on what matters most: vulnerabilities that are actively being exploited. Available as a fully managed SaaS or on-premises deployment.

Instead of overwhelming you with hundreds of thousands of CVEs, SentriKat tracks the published catalogue of exploited vulnerabilities and matches them against your software inventory.

Key Features

  • Multi-Source Intelligence - CVSS scores cross-checked across three independent public databases with automatic fallback. Learn more
  • Exploited-first - Track actively exploited vulnerabilities from both US (the exploited-vulnerability catalogue) and European (European vulnerability database) databases
  • Data Provenance - Every score carries a cvss_source tag so you know exactly where it came from
  • Multi-Platform Scanning - Native agents for Windows, Linux, macOS, and container images (Docker/Podman)
  • Vendor Advisory Sync - Auto-detect patches from Red Hat, Microsoft, Debian, and package advisories
  • Three-Tier Confidence - Affected / Likely Resolved / Resolved status for every vulnerability
  • NIS2 Compliance Reports - Article 21 mapping, exploited-vulnerability compliance tracking, executive summary PDFs
  • SIEM Integration - Forward events to Splunk, ELK, ArcSight, QRadar via syslog (CEF/JSON/RFC 5424)
  • Issue Tracker Integration - Auto-create issues in Jira, GitHub, GitLab, YouTrack
  • Community Knowledge Base - PRO installations share CPE mappings; complete software identity catalogue included
  • Intelligent Matching - CPE-based matching with distro-native version comparison (dpkg, RPM, APK)
  • Multi-tenant & White-Label - Isolated organizations with role-based access and custom branding
  • Flexible Inventory - Agents, Lansweeper, SCCM/Intune, API, or CSV import
  • Smart Alerts - Email, Slack, Teams, Discord notifications with escalation policies
  • SaaS or Self-Hosted - Managed cloud at app.sentrikat.com, or 100% on-premises with air-gapped support and TOTP 2FA

Quick Start

SaaS No installation needed. Free during Early Access.

  1. Sign up at sentrikat.com, join Early Access
  2. Log in at app.sentrikat.com with your credentials
  3. Deploy agents to your endpoints (Windows, Linux, macOS)
  4. View results: vulnerabilities are matched automatically

Follow the full walkthrough: SaaS Quick Guides (8 step-by-step guides, ~30 minutes total)

On-Prem Deploy on your own infrastructure with Docker.

  1. Download SentriKat from the Customer Portal
  2. Extract the archive to your server:
    tar -xzf sentrikat-*.tar.gz
    cd sentrikat-*/
    docker load -i sentrikat-image-*.tar.gz
    
  3. Configure your environment:
    cp .env.example .env
    nano .env  # Set SECRET_KEY, ENCRYPTION_KEY, DB_PASSWORD. See .env.example
    
  4. Start with Docker Compose:
    docker compose up -d
    
  5. Access at http://localhost:5000 and complete the setup wizard

Detailed instructions: Docker Deployment Guide

Editions & Pricing

SaaS Plans

Plan Price Agents Users Highlights
Free €0/mo 3 1 Perfect for evaluation
Starter €59/mo 10 3 Small teams
Pro €249/mo 25 5 NIS2 reports, SIEM, issue trackers, API
Business €649/mo 50 10 Everything in Pro + priority support
Enterprise from €1,499/mo Custom Custom LDAP/SSO, multi-tenant, white-label

All SaaS plans include daily exploited-vulnerability feed, vendor advisory sync, software identity catalogue, and container image scanning.

Add-on: Compliance Pack (€199/mo, Pro and above): PCI-DSS v4.0, ISO/IEC 27001:2022, and SOC 2 gap-analysis reports.

During Early Access all plans are free; Early Access participants are grandfathered when pricing goes live.

On-Premises Editions

Community Edition Professional
Price Free EUR 4,999/yr
Users 3 Unlimited
Organizations 1 Unlimited
Products 100 Unlimited
Agents (Windows, Linux, macOS) 10 10 + agent packs
Basic dashboard included included
Daily exploited-vulnerability sync included included
Exploit probability scoring included included
Container scanning included included
Two-factor authentication (TOTP) included included
Backup export and restore included included
All vulnerability intelligence sources not included included
NIS2, DORA, BOD 22-01 reports not included included
SIEM/Syslog integration not included included
Jira, GitHub, GitLab integration not included included
Multi-tenant + White-Label not included included
LDAP/AD/SAML SSO not included included
Air-gapped deployment not included included
Scheduled backups and standard-format exports not included included

Multi-year discounts: 2 years (10% off), 3 years (15% off). Agent Packs: add more agents as needed (+25, +50, +100, unlimited).

See pricing details for more information.

Support