SYS // DEFENSE GRID · ONLINE
SCAN ENGINES 8/8 NOMINAL
PROBE MESH · 142 NODES
LAT 25.276°N // LON 55.296°E
SECTOR · UAE GCC
TENANT · PROD-MSSP-01
ANOMALY · 10.0.4.22 · CONTAINED
KEV CVE-2024-3094 · QUARANTINED
PKT/S · 2.4B // EPS · 86K
UPLINK · ENCRYPTED · CHACHA20
Now in Early Access

See every threat.
Shield every asset.

The Continuous Threat Exposure Management platform that discovers real vulnerabilities with 80+ security tools, correlates them with KEV & EPSS exploit intelligence, and delivers them through one multi-tenant portal built for MSSPs.

▷ Watch Demo
No agent install for external scans Outbound-only probe for internal UAE NESA & PDPL aligned
Scroll
0
Scan Engines
0
Security Tools
0
API Endpoints
0
Licensable Modules
Live Demo

Watch SentraLens find real vulnerabilities

A two-minute tour of the platform — from attack surface discovery to AI-enriched findings and board-ready reports.

Scroll to auto-play · Click to start now
See It In Action

A unified command center for threat exposure

The Problem

Traditional scanners find vulnerabilities. We expose your real attack surface.

Most platforms validate whether your defenses work. SentraLens goes further — we discover what is actually broken, using the same tools real attackers use.

Real vulnerability discovery, not simulated attacks
80+ open-source and commercial tools orchestrated automatically
Internal + external attack surface in one platform
AI-powered enrichment and prioritization
Capabilities

Everything you need to own your attack surface

Ten core capabilities, purpose-built for security teams that need real results — not compliance checkboxes.

8 Engines · 80+ Tools
External Attack Surface Management

Automated reconnaissance with subdomain enumeration, port scanning, technology fingerprinting, WHOIS, DNS, SSL analysis, and vulnerability detection across your entire perimeter.

Genie Chatbot
AI-Powered
Intelligence

Ask your findings questions. Genie enriches every vulnerability with context, prioritizes by exploitability, and generates remediation guidance using multi-model AI orchestration.

Probe Agents
Internal Network Scanning

Lightweight Probe agents inside your network for internal vulnerability assessment, lateral-movement detection, and continuous exposure monitoring — no VPN headaches.

Full Campaign Management
Phishing Simulation

Realistic phishing campaigns with customizable templates, landing pages, credential-harvesting tracking, and employee awareness reporting — all within the same platform.

Visual Editor
Executive Reports

Drag-and-drop report builder with section templates, severity charts, and one-click PDF/HTML export. Generate board-ready reports that tell the story your leadership needs.

MSSP Ready
Multi-Tenant & Modular Licensing

Manage multiple clients from a single pane. License only the modules you need. Full tenant isolation, RBAC, and role-based access designed for managed security providers.

Agentless CVE Detection
Host Vulnerability Management

Probes collect installed packages from every host automatically. The platform correlates them against mirrored NVD/OSV CVE feeds with distro-aware version comparison — telling you which host needs which patch, enriched with KEV and EPSS scores.

MITRE ATT&CK Mapped
Attack Path Visualization

Findings are mapped to MITRE ATT&CK tactics and chained into kill-chain stages. See how an attacker would move from initial access through lateral movement to impact — across both external and internal scan results.

Initial Access Execution Lateral Move Impact
WebSocket Terminal
Reverse Console

Open a live terminal to any probe directly from the SaaS UI — no VPN, no SSH keys, no inbound ports. The probe initiates outbound, passing through firewalls. Full PTY with idle and session timeouts.

probe-edge-01 $netstat -an | grep ESTAB
tcp 0 0 10.0.4.22:443 198.51.x.x:51422 ESTABLISHED
probe-edge-01 $
Credential Vault
Authenticated Scanning

Store encrypted credentials (web login, HTTP headers, Git tokens) and attach them to scans. Playwright replays browser logins for SPAs. Nuclei, ZAP, and Katana receive auth headers automatically — finding vulnerabilities behind login pages no anonymous scanner will ever see.

🔒 AES-256 vault 🔑 Per-tenant keys 🍪 Cookie replay 🌐 SPA via Playwright 📡 Auth headers passthrough 🎯 SSO & OAuth 🛡 No plaintext storage ⏱ Auto-rotation
How It Works

Four steps to complete visibility

From discovery to executive reporting, SentraLens automates the entire CTEM lifecycle.

01

Discover

Map your entire external and internal attack surface automatically. Subdomains, IPs, ports, technologies, and certificates — nothing hides.

02

Scan

Orchestrate 80+ tools across 8 engines in parallel. Real vulnerability detection, not simulated probes. Full CVE correlation.

03

Analyze

AI enriches every finding with exploitability scores, attack path context, and prioritized remediation steps. Ask Genie anything.

04

Report

Generate board-ready PDF reports with the visual editor. Scheduled recurring scans keep your exposure data continuously fresh.

Detection Engine

Real findings, ranked by real exploitability

Other platforms simulate attacks. SentraLens runs a real detection pipeline that correlates CVE feeds with your actual installed packages, then ranks findings by exploit intelligence — not guesswork.

Mirrored CVE feeds

OSV.dev bulk feeds, NVD 2.0 API, and GHSA advisories are continuously mirrored into a local, tenant-isolated database. Distro-aware version comparators for Debian, Ubuntu, RHEL, Alpine, and more. No internet calls during scans.

KEV + EPSS overlay

Every finding is enriched with CISA KEV (Known Exploited Vulnerabilities) and FIRST.org EPSS exploit probability scores. A CVSS 7.2 that's actively exploited beats a CVSS 9.8 that no one can weaponise. Prioritise the real fires first.

Host patch correlation

The on-prem Probe collects the real installed package list from every Linux host via SSH. We compare installed versions against mirrored CVE data and tell you which host needs which patch, not just which CVE exists in the world.

8 engines, 80+ tools

Subfinder, Amass, Nmap, Naabu, Masscan, Nuclei, Dalfox, CRLFuzz, Katana, theHarvester, WHOIS, Nikto and more — all orchestrated by Celery with bounded retries, per-tenant module gating, and per-scan credential resolution.

Cross-scan correlation

Findings from the external attack surface and internal probes are joined into unified risk stories. When a harvested employee email from an OSINT scan matches a credential on an internal host, you see one finding with the full chain — not two disconnected alerts.

Finding lifecycle

Every finding has an owner, a due date, a status, and an audit trail. Assign, suppress, resolve, export — and when rules match, suppressions apply automatically on the next scan. No more CSV dumps to a ticket system that never closes.

findings · prod-tenant · filter:kev=true
CRITCVE-2024-3094KEVEPSS 0.94
└─ db-prod-04 · xz-utils 5.6.0 → patch to 5.6.2
HIGHCVE-2023-50164KEVEPSS 0.91
└─ web-edge-01 · struts-core 2.5.32
HIGHCVE-2024-4040KEVEPSS 0.88
└─ ftp-bastion · crushftp 10.7
MEDCVE-2024-7574EPSS 0.42
└─ jenkins-ci-02 · maven-plugin 3.6
MEDCVE-2024-2356EPSS 0.31
└─ redis-cache · openssl 3.0.7
3 KEV-tagged · 1 suppressed · 248 totalView all →

Findings inbox with KEV filter chip, severity tiles, and per-host patch correlator output.

Modular Architecture

License only what you need

7 independently licensable modules. Asset management and reporting are core to every plan — mix modules to build the exact security stack your organization requires.

WAS

External Attack Surface Management

Subdomain enumeration, port and technology fingerprinting, OWASP Top 10, Nuclei, Dalfox, CRLFuzz, Katana — external discovery and web application scanning in one module.

NIS

Internal Attack Surface Management

On-prem Probe agent with credentialed remote inventory via SSH, host patch correlation, port and service discovery. Outbound-only, no inbound firewall rules.

PHI

Phishing Simulation

Full campaign management — templates, landing pages, SMTP profiles, IMAP monitoring, target groups, directory, leaderboard, training, compliance reporting.

COG

Compliance & Governance

8 compliance frameworks mapped (ISO 27001, SOC 2, ISO 42001, PCI DSS 4.0, NIST CSF 2.0, UAE NESA, ADHICS, UAE PDPL), tenant-scoped audit log, and evidence export for auditors.

THI

Threat Intelligence

Mirrored CVE feeds from OSV.dev, NVD and GHSA, enriched with CISA KEV and FIRST.org EPSS scores. Patch correlation against real installed packages.

CLS

Code Lifecycle Security

Static application security testing with Semgrep (600+ OWASP rules) and Gitleaks secret detection. Source repository cloning, dependency analysis, and SAST-to-DAST correlation across scan results.

AI

AI Security

Genie — multi-model AI enrichment with a 4-layer guardrail pipeline. Auto-generated remediation, narrative reports, and a chat assistant that answers questions about your findings.

CORE

Always included

Asset management (domains, subdomains, IPs, ports, technologies), 8 report templates with a visual editor, multi-tenancy with 4-layer isolation, and the full CTEM workflow — scope, discover, prioritize, validate, mobilize.

Licensed Modules panel in Settings — per-tenant enforcement visible at a glance. Module state is checked at the gateway, orchestrator, and UI layers on every request.

Phishing Simulation

A full awareness programme in one module

Campaigns, realistic email templates, custom landing pages, SMTP + IMAP infrastructure, training assignments, and compliance reporting — without bolting on a second product.

PHI · Q4 phishing campaign · "Payroll update"
j.smith@
Finance · opened email at 09:14
Clicked link
m.lopez@
Marketing · reported phish at 09:22
Reported
a.khan@
Engineering · entered credentials
Compromised
r.patel@
Sales · assigned 4-min training module
In training
248 sent · 41 clicked · 12 entered · 86 reportedCompliance report →

Email template library — realistic lures, variables, and tracking pixels baked in.

Landing pages — credential-harvest simulations and automatic training redirects on capture.

SMTP + IMAP infrastructure — managed sending domains plus inbound monitoring for reported phishing.

Target groups & directory — sync from AD/IdP or import CSV; segment by department, geography, risk tier.

Training assignments — auto-enroll clickers; track completion alongside campaign metrics.

Compliance reporting — board-ready PDFs with click rates, training coverage, and risk improvement trends.

Included in the PHI module: Dashboard, Campaigns, Calendar, Target Groups, Directory, Leaderboard, Training, Email Templates, Landing Pages, Domains, SMTP Profiles, IMAP Monitor, Webhooks, Compliance, and Scheduled Reports.

Why SentraLens

How we stack up

C******e validates defenses. P****a proves exploitability. SentraLens discovers what is actually broken.

CapabilitySentraLensVendor C***Vendor P***Vendor H***
External Attack Surface Discovery✓ FullLimited
Real Vulnerability Scanning (80+ tools)✓ 80+ toolsLimited
Internal Network Scanning (Probe)✓ Outbound only
Phishing Simulation✓ Integrated
AI-Powered Intelligence✓ Multi-modelBasicBasic
Visual Report Editor✓ Drag-and-drop
Multi-Tenant / MSSP Portal✓ NativePartial
Modular Licensing✓ 7 modules
Host Vulnerability / Patch Detection✓ Per-host
Attack Path Visualization✓ MITRE-mapped
8 Compliance Frameworks (incl. UAE)✓ NESA/PDPL/ADHICSLimited
Security & Compliance

Built for the compliance bar you need

Multi-tenancy, supply-chain integrity, and audit trails engineered in from day one — not bolted on after the first incident.

4-layer tenant isolation

Every row in every table is scoped to a tenant UUID. No single mistake can cause a cross-tenant leak:

  • API gateway strips any client-supplied identity headers and re-injects the tenant ID from verified JWT claims
  • Gateway injects a shared-secret header that downstream services verify on every request — direct hits are rejected
  • Go repository methods take tenantID as a mandatory parameter — enforced at compile time
  • Python services use a @require_tenant decorator enforced in CI

Signed supply chain

On-prem probes pull signed images and verify them before every self-update — no tag-swap attacks:

  • Sigstore cosign keyless signatures with baked-in public key in the probe binary
  • Image references pinned by digest, not just tag — a moved tag fails verification
  • Update lifecycle has 5 phases (pending → downloading → verifying → restarting → completed) with operator-visible cancel
  • Per-probe rate-limited update requests prevent accidental or malicious update loops

Tamper-evident audit log

Every mutating action — who, what, when, from which IP, with which result — is recorded append-only in the tenant-scoped audit log.

  • Tenant admins get full read access through Settings
  • Suppression rules record created_by, match history, and expiry dates
  • Auditors can trace every silenced finding back to the operator who approved it
  • Evidence export packs for ISO 27001, SOC 2 Type II, and NESA audits

AIAI with 4-layer guardrails

Genie processes finding metadata through input sanitisation → policy filter → output review → audit log on every invocation.

  • Prompts and responses stay inside your tenant boundary
  • Never used to train third-party models
  • Configurable per-tenant token budgets
  • Turn it off entirely from Settings if you want the platform without the AI

Frameworks the platform currently supports

SentraLens ships with controls, evidence collection, and report templates mapped to the standards below — so your auditors get what they need without spreadsheets.

ISO 27001
Information security controls
SOC 2 Type II
Security, availability, confidentiality
ISO 42001
AI management systems
PCI DSS 4.0
Payment card security
NIST CSF 2.0
Cybersecurity framework
UAE NESA UAE
National & healthcare security
ADHICS UAE
Healthcare information security
UAE PDPL UAE
Personal data protection law
GDPR EU
EU data protection
HIPAA US
US healthcare data

Additional frameworks can be added on request — talk to us about your audit pack.

Free · No commitment

Start your free assessment

See what attackers see. Get a complimentary attack surface report for your organization — no commitment required.