NIS2 · DORA · CRA · CyFun evidence, built in

Turn your fleet's real state into signed, regulator-ready evidence

Air-gap-deployable, under EU jurisdiction. Sentari inventories every package and runtime across your fleet — and turns it into evidence auditors can verify, not screenshots they have to trust.

The sovereign EU evidence engine.

sentari — compliance evidence
Sentari compliance dashboard — NIS2, DORA and CRA framework coverage from live fleet data, with control-level status, citations, and signed evidence you can hand to an auditor
NIS2 · DORA · CRA · CyFun evidence
From national governments to regulated enterprises
On-premise & air-gap
EU jurisdiction — no inventory egress

Seeing the risk isn't proving it

Security teams and compliance officers hit the same wall from opposite sides — exposure data that was never built into evidence. Sentari closes the gap from both ends.

For the CISO: exposure without evidence

Your vulnerability scanner already tells you what's exposed across the fleet — but its output is a baseline, not evidence an auditor will accept. Findings don't map to controls, and they aren't signed.

The gap between them: you can't prove what you can't see

Packages sprawl across Python, npm, NuGet, Java, OS packages, and containers on every device. Shadow environments proliferate — and you can't generate evidence for software you were never watching.

For the compliance office: evidence, on a clock

Auditors want signed, control-mapped evidence they can verify for themselves. And the clocks are running — the DORA Register of Information repeats annually, and Belgian CyFun CAB certification is due April 2027.

The whole lifecycle — ending in evidence, not a dashboard

Prevent, see, monitor, and remediate — every step feeding one signed, audit-ready evidence trail instead of four disconnected tools. Every step below is available today.

Prevent

Stop risky installs

A signed install-gate policy the agent enforces on every endpoint — block disallowed or vulnerable packages before they ever land.

Available now
See

Know what's installed

Discover every software environment on every device — Python (pip, conda, poetry, pipenv, venv), npm, NuGet, Java/Maven, OS packages, and containers.

Available now
Monitor

Catch exposure

CVE correlation against NVD, OSV & CERT-EU with CISA KEV flagging, VEX exploitability triage, policy enforcement, alerts, and signed NIS2/DORA/CRA/CyFun evidence packs.

Available now
Remediate

Close the loop

Turn findings into remediation campaigns — scope affected devices, assign fixes, and drive them to verified closure with a full audit trail.

Available now
sentari — fleet overview
Sentari fleet overview — a prioritized 'needs you now' work queue ranked by risk, KEV/EPSS exposure and EOL tiles, the fleet's risk mix, and live framework coverage

Built for enterprise. No compromises.

Fleet-wide endpoint scanning, EU regulatory evidence, and true air-gap deployment in one platform — not your CI/CD pipeline, your actual devices.

Air-gap + EU jurisdiction — structural, not a setting

Sentari runs fully offline on your own infrastructure, built and operated under EU jurisdiction. Air-gap architecture and EU data sovereignty aren't a config toggle — they're the design. SaaS-hosted and US-jurisdiction tools can't retrofit them.

mTLS everywhere

Mutual TLS on all agent-server communication. Internal CA for certificate issuance. Zero trust by default.

Single binary agent

One binary, zero runtime dependencies. CGO_ENABLED=0. Deploy to any Linux, macOS, or Windows device.

No cloud markup

On-premise deployment included at every tier — your inventory stays on your infrastructure, never a paid add-on.

SBOM generation

CycloneDX 1.6 and SPDX 2.3 generation built in. Feed your existing compliance toolchain.

Every ecosystem, one agent

Python (pip, conda, poetry, pipenv, venv), npm, NuGet, Java/Maven, OS packages (deb/rpm), containers, and AI-agent runtimes — read from metadata, never by invoking package managers.

Evidence your auditors can verify

Sentari generates reproducible, cryptographically signed evidence packs with frozen inputs. Every claim traces back to a scan, a timestamp, and an immutable audit log — not a screenshot.

NIS2

Evidence for software inventory, vulnerability handling, and risk-management measures — generated directly from your fleet's actual state.

DORA

ICT risk-management evidence for financial entities. Plus the Register of Information (Art. 28) module: maintain your ICT third-party providers, arrangements, and functions — with agent-observed suppliers surfaced for mapping and ITS-validated exports.

CRA

Evidence for products with digital elements — including known-exploited-vulnerability checks against CISA KEV and SBOM obligations.

CyFun

Map live fleet evidence to CCB CyberFundamentals controls — asset inventory, vulnerability management, and patch currency — for Belgian NIS2 conformity, drawn from real host data instead of a questionnaire.

Example evidence line — every claim maps to a control

CyFun ID.AM-1 (asset inventory) ← agent scan · signed 2026-08-12 · hash-chained

Illustrative. Each control maps back to a specific scan, timestamp, and entry in the immutable audit log.

sentari — evidence packs
Sentari evidence packs — signed, reproducible compliance packs per framework with catalog version, generation timestamp, content hash, and JSON / PDF / ZIP artifacts

Two buying centers, one platform

Whether you own exposure management or compliance automation, Sentari rides the budget line you already fund — and produces evidence for both. From national governments and EU institutions to banks and product manufacturers. Working with an integrator or managed-security provider? We partner.

Exposure management

For the CISO

Exposure management that ends with signed evidence. Correlate CVEs with CISA KEV and EPSS exploit-prediction scoring across the real fleet, triage exploitability with VEX, and hand your auditor evidence — not a scanner baseline.

Compliance automation

For the compliance office

Compliance automation fed by real fleet state, not questionnaires. Every NIS2, DORA, CRA, and CyFun control maps back to a scan, a timestamp, and an immutable audit-log entry.

CyFun

For Belgian NIS2 entities

CyFun evidence drawn from live host data — asset inventory, vulnerability management, and patch currency — ahead of the April 2027 CAB certification deadline.

DORA

For financial entities

ICT-risk evidence plus the DORA Register of Information (Art. 28): providers, arrangements, and functions, audit-ready — with agent-observed suppliers surfaced for mapping.

7
Ecosystems covered
Python, npm, NuGet, Java/Maven, OS packages, containers, AI agents
0
Runtime dependencies
Single static binary
100%
Offline capable
Air-gap first architecture
<2min
First scan
Deploy to results in minutes

Up and running in minutes

Three steps from download to full fleet visibility. No configuration wizards, no cloud accounts.

01

Deploy the agent

Download a single binary. No dependencies, no runtime, no pip install. Deploy via Ansible, SCCM, or manual copy.

02

Scanning starts automatically

The agent discovers software across every ecosystem — Python, npm, NuGet, Java/Maven, OS packages, containers — and reports to your server.

03

See your fleet

The dashboard shows every device, every environment, every package. Filter by CVE severity, compliance status, or policy violation.

On the roadmap

What's shipped is above — signed, in your hands today. These deepen the same evidence engine and are in active design. We don't market what isn't built.

In design

Configuration & hardening posture

CIS Benchmark and STIG checks against the same fleet agent — turning host configuration into control-mapped evidence alongside package and CVE data.

In design

Asset register

A first-class register of devices, owners, and business function — the asset-inventory backbone NIS2 and CyFun ask for, drawn from live fleet state.

In design

Regulatory incident reporting

Structured incident capture and notification workflows mapped to NIS2, DORA, and CRA reporting timelines.

See Sentari in action

Get a personalized demo of Sentari for your organization. See fleet-wide exposure, CVE triage, and signed, audit-ready NIS2/DORA/CRA/CyFun evidence — generated from a live environment.