NIS2 · DORA · CRA compliant

Know every package across your fleet

Enterprise-grade visibility into software across every ecosystem — Python, npm, NuGet, Java, OS packages, and containers — on every device. CVE correlation, compliance reporting, and SBOM generation — air-gap ready, deployed on your infrastructure.

sentari — fleet dashboard
Sentari fleet dashboard — CVE findings, open alerts, and license/compliance posture across every ecosystem
NIS2 Ready
DORA Compliant
CRA Aligned
NATO/EU Ready

Your software fleet is a blind spot

Most organizations have no idea what's running across their endpoints. Sentari changes that.

No visibility

You don't know which packages are installed across your devices — Python, npm, NuGet, Java, OS packages, containers. Shadow environments proliferate unchecked.

CVEs go unnoticed

Vulnerable packages sit in production — pip and conda environments, npm and NuGet dependency trees, OS packages, and containers — and nobody knows.

Compliance gaps

NIS2 and DORA require a software inventory. Auditors ask for SBOMs. You can't generate what you can't see.

From blind spot to full control

A phased approach that delivers value from day one, with each phase building on the last.

Phase 1

Visibility

Discover every software environment on every device. Automatic scanning across ecosystems — Python (pip, conda, poetry, pipenv, venv), npm, NuGet, Java/Maven, OS packages, and containers.

Available now
Phase 2

Monitoring

CVE correlation against OSV and NVD databases. Policy enforcement, compliance reporting for NIS2/DORA/CRA, alert management.

In development
Phase 3

Remediation

Remote package updates with automatic rollback. Safe remediation across your fleet without touching production manually.

Planned

Built for enterprise. No compromises.

The only platform that scans deployed endpoints across every ecosystem. Not your CI/CD pipeline — your actual devices.

Air-gap ready

Every feature works without internet. Designed for classified and isolated networks from the ground up.

mTLS everywhere

Mutual TLS on all agent-server communication. Internal CA for certificate issuance. Zero trust by default.

Single binary agent

One binary, zero runtime dependencies. CGO_ENABLED=0. Deploy to any Linux, macOS, or Windows device.

On-premise included

No cloud markup. On-premise deployment included at every tier. Your data stays on your infrastructure.

SBOM generation

CycloneDX 1.6 and SPDX 2.3 generation built in. Feed your existing compliance toolchain.

7 scanner types

pip, conda, poetry, pipenv, venv, system-deb, system-rpm. No package manager left behind.

7
Scanner types
pip, conda, poetry, pipenv, venv, deb, rpm
0
Runtime dependencies
Single static binary
100%
Offline capable
Air-gap first architecture
<2min
First scan
Deploy to results in minutes

Up and running in minutes

Three steps from download to full fleet visibility. No configuration wizards, no cloud accounts.

01

Deploy the agent

Download a single binary. No dependencies, no runtime, no pip install. Deploy via Ansible, SCCM, or manual copy.

02

Scanning starts automatically

The agent discovers software across every ecosystem — Python, npm, NuGet, Java/Maven, OS packages, containers — and reports to your server.

03

See your fleet

The dashboard shows every device, every environment, every package. Filter by CVE severity, compliance status, or policy violation.

See Sentari in action

Get a personalized demo of Sentari for your organization. See how fleet-wide software visibility works in practice.