From prevention to signed evidence — one platform
Prevent, see, monitor, and remediate — one platform for the whole software-risk lifecycle. Everything is available today unless it's explicitly marked in design.
Prevention
Available nowStop risky and unapproved packages before they ever reach your fleet.
Install gate
A signed deny/allow policy the agent enforces on every endpoint — block vulnerable or unapproved packages before they're ever installed.
Policy engine
Define what's allowed across your fleet by ecosystem, package, version, or CVE severity. Policies are cryptographically signed and consumed offline by the agent — no live server dependency.
Visibility
Available nowDiscover and catalog every package across your fleet, in every ecosystem.
Fleet inventory
Automatic discovery and inventory of every device and the software it runs. Real-time fleet overview.
Multi-ecosystem scanning
Python (pip, conda, poetry, pipenv, venv), npm, NuGet, Java/Maven, OS packages (deb/rpm), containers, and AI-agent runtimes. Every ecosystem covered, no binary invocation.
Device management
Track device status, last scan time, agent version, and environment count from a single dashboard.
Environment detection
Automatic detection of virtual environments, conda environments, npm/NuGet/Maven projects, OS packages, and containers.
Monitoring
Available nowCorrelate CVEs, triage with VEX, enforce policy, and generate signed compliance evidence.
CVE correlation
Correlate installed packages against NVD, OSV, and CERT-EU advisories, with CISA KEV flagging for known-exploited vulnerabilities. Know exactly which devices are affected the moment a CVE lands.
VEX & triage
Mark findings as affected, not affected, or fixed — with justifications. Suppress false positives, filter by VEX status, and export CycloneDX VEX for your auditors and downstream consumers.
NIS2 / DORA / CRA / CyFun evidence packs
Reproducible, cryptographically signed evidence packs with frozen inputs, mapped to specific controls. Hand auditors verifiable evidence generated directly from your fleet's real state.
DORA Register of Information (Art. 28)
Maintain your register of ICT third-party providers, contractual arrangements, and functions — with agent-observed software suppliers surfaced for mapping and ITS-validated register exports.
SBOM export
CycloneDX 1.6 and SPDX 2.3 formats. Generate SBOMs per device, per environment, or fleet-wide.
Alerting & policies
Define policies (e.g., 'no critical CVEs in production'), get alerted on violations, and track every finding through triage to closure.
Runtime & OS end-of-life tracking
Know which language runtimes and OS releases across your fleet are past — or approaching — end of life, before an auditor or an attacker finds out.

Remediation
Campaigns available nowOrchestrate and verify vulnerability remediation across your fleet.
Remediation campaigns
Turn CVE findings into campaigns: scope affected devices, assign remediation tasks, and drive them to verified closure — with a complete audit trail.
Progress tracking & verification
Track campaign progress per device and per task. Rescans verify that the fix actually landed — closure is evidence-based, not self-reported.
Automated rollouts (roadmap)
On the roadmap: push package updates remotely with canary groups, staged rollouts, and automatic rollback.
In design
Not yet availableIn active design — deepening the same evidence engine. We don't market these as available until they ship.
Configuration & hardening posture
CIS Benchmark and STIG checks against the same fleet agent — turning host configuration into control-mapped evidence alongside package and CVE data.
Asset register
A first-class register of devices, owners, and business function — the asset-inventory backbone NIS2 and CyFun ask for, drawn from live fleet state.
Regulatory incident reporting
Structured incident capture and notification workflows mapped to NIS2, DORA, and CRA reporting timelines.
See Sentari in action
Get a personalized demo of Sentari for your organization. See fleet-wide exposure, CVE triage, and signed, audit-ready NIS2/DORA/CRA/CyFun evidence — generated from a live environment.