11 Integrated Security Products

Every Layer Protected.
One Unified Platform.

From cloud posture to kernel-level runtime defense, Sentrafort delivers complete security coverage without the tool sprawl.

CSPM

Cloud Security Posture Management

Continuously scan cloud configuration for misconfigurations before attackers exploit them.

  • 222 AWS security checks that run against your live estatePublic Preview

    AWS scanning is in final pre-launch deployment — join the waitlist for first access.

  • Risk-prioritized fix queue with multi-factor scoringPublic Preview

    AWS scanning is in final pre-launch deployment — join the waitlist for first access.

  • Scan Microsoft Azure subscriptions for misconfigurationsPublic Preview

    Azure support is coming in a future release.

  • Scan Google Cloud projects for misconfigurationsPublic Preview

    Google Cloud support is coming in a future release.

  • Scan AWS resources for misconfigurationsPublic Preview

    AWS scanning is in final pre-launch deployment — join the waitlist for first access.

CSPM Dashboard
222
AWS Checks
AWS
Cloud Coverage
Multi-factor
Risk Score
<3m
Scan Time
CIEM

Cloud Identity & Entitlement Management

Map every identity, entitlement, and access path. Enforce least privilege.

  • Segregation-of-duties violation detectionPublic Preview

    Identity security is coming in a future release.

  • Unused access and excessive-permission detectionPublic Preview

    Identity security is coming in a future release.

  • Least-privilege recommendations with real IAM discoveryPublic Preview

    Identity security is coming in a future release.

  • Identity security available in Professional tierPublic Preview

    Identity security is coming in a future release.

CIEM Dashboard
SoD
Violation Engine
Real-time
Discovery
AWS
Cloud Coverage
Enterprise
Tier
DSPM

Data Security Posture Management

Discover and classify sensitive data (PII, PCI, PHI) across your cloud data stores.

  • Automatically discover sensitive data (PII, PCI, PHI) with entropy + Luhn + regex classificationPublic Preview

    Data security posture management is coming in a future release.

  • Scan S3 buckets for sensitive data exposurePublic Preview

    Data security posture management is coming in a future release.

  • Scan RDS databases for sensitive data exposurePublic Preview

    Data security posture management is coming in a future release.

  • Scan DynamoDB tables for sensitive data exposurePublic Preview

    Data security posture management is coming in a future release.

DSPM Dashboard
S3 / RDS / DynamoDB
Stores Scanned
PII / PCI / PHI
Classifications
Luhn + Shannon
Classifier
Professional+
Tier
CDR

Cloud Detection & Response

Respond to cloud threats with one-click isolation, credential revocation, and evidence snapshots.

  • One-click EC2 isolation via quarantine security groupPublic Preview

    Cloud detection & response is coming in a future release.

  • Quarantine S3 buckets by applying deny-all policy with CloudTrail exceptionPublic Preview

    Cloud detection & response is coming in a future release.

  • Disable compromised IAM users with AWSCompromisedKeyQuarantineV2 + key deactivationPublic Preview

    Cloud detection & response is coming in a future release.

CDR Dashboard
One-click
Response Actions
Undo
Safety
AWS
Cloud Coverage
Enterprise
Tier
IaC

Infrastructure-as-Code Security

Scan Terraform, CloudFormation, Kubernetes, and Helm manifests before they deploy.

  • Checkov-based IaC scanning across 8 frameworksPublic Preview

    IaC security scanning is coming in a future release.

  • GitHub webhook triggers scans with timing-safe HMAC-SHA256 signature verificationPublic Preview

    IaC security scanning is coming in a future release.

  • Automatic GitHub Pull Request creation with remediation diff attached to each findingPublic Preview

    IaC security scanning is coming in a future release.

IaC Dashboard
8
Frameworks
Checkov
Scanner
Auto-PR
Remediation
HMAC
Webhook Auth
Secrets

Exposed Credential & API Key Detection

Detect leaked AWS keys, GitHub tokens, API keys, and private certificates across your cloud surface.

  • Detect AWS keys, GitHub tokens, Stripe keys, private certificates, and morePublic Preview

    Secret scanning is coming in a future release.

  • Fingerprint-based deduplication prevents alert fatiguePublic Preview

    Secret scanning is coming in a future release.

Secrets Dashboard
13
Detectors
Fingerprint
Dedup
BullMQ
Scan Queue
Professional+
Tier
Containers

Container & Image Security

Import vulnerability results from Trivy scans you run yourself — they land in the unified findings view. Sentrafort-executed image and registry scanning, and SBOM generation, are in development.

  • Trivy results import — vulnerabilities from Trivy scans you run appear in your findings view
  • SBOM generation in SPDX and CycloneDX formatPublic Preview

    SBOM generation is coming in a future release.

  • Container security dashboard with per-image CVE drill-downPublic Preview

    The container security dashboard is coming in a future release.

Containers Dashboard
Trivy
Results Import
Findings
Surfaces In
SBOM: soon
SBOM
UI: soon
Dashboard
Runtime

Vigil Runtime Protection

eBPF-based kernel-level runtime detection for Linux workloads with minimal overhead.

  • Real eBPF agent for network, exec, and file-system event capturePublic Preview

    Runtime protection is coming in a future release.

  • gRPC agent enrollment with single-use tokens and mTLSPublic Preview

    Runtime protection is coming in a future release.

Runtime Dashboard
eBPF
Kernel-Level
Real-time
Detection
mTLS
Agent Auth
Linux
Platform
SIEM

SIEM Integration

Export security events to Splunk, Microsoft Sentinel, or any webhook endpoint.

  • Splunk HEC export with batched, retried HTTPS POST
  • Microsoft Sentinel Log Analytics ingestion with HMAC-SHA256 signing
  • Generic webhook export for any SIEM or ticketing system
SIEM Dashboard
Splunk HEC
Adapter
Sentinel HMAC
Adapter
Webhook
Adapter
Event-driven
Transport
Compliance

Compliance Automation

SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST frameworks with auto-collected evidence.

  • SOC 2 Type II framework with mapped controlsPublic Preview

    Compliance automation is coming in a future release.

  • ISO 27001 Annex A controlsPublic Preview

    Compliance automation is coming in a future release.

  • HIPAA Safeguards frameworkPublic Preview

    Compliance automation is coming in a future release.

  • PCI-DSS v4.0 frameworkPublic Preview

    Compliance automation is coming in a future release.

  • NIST Cybersecurity Framework 2.0Public Preview

    Compliance automation is coming in a future release.

  • Auditor-ready PDF compliance reports with one clickPublic Preview

    Compliance automation is coming in a future release.

Compliance Dashboard
5
Frameworks
230+
Controls
1-click
Report Gen
Auto
Evidence
Security Graph

Attack Path Analysis

Interactive graph visualization maps exploitable paths from internet exposure to crown-jewel data.

  • Bidirectional BFS attack-path discovery on Neptune graphPublic Preview

    Attack-path analysis is coming in a future release.

  • Remediation guidance with automation-ready action markers per path stepPublic Preview

    Attack-path analysis is coming in a future release.

Security Graph Dashboard
Neptune
Graph Backend
Bidirectional BFS
Algorithm
Production-safe
Guard
Growth+
Tier

See Sentrafort in Action

Book a personalized demo and see how every product works with your cloud environment.