11 Integrated Security Products

Every Layer Protected.
One Unified Platform.

From cloud posture to kernel-level runtime defense, Sentrafort delivers complete security coverage without the tool sprawl.

CSPM

Cloud Security Posture Management

Continuously scan cloud configuration for misconfigurations before attackers exploit them.

  • 259 AWS security checks that run against your live estate
  • Risk-prioritized fix queue with multi-factor scoring
  • Scan Microsoft Azure subscriptions for misconfigurationsPublic Preview

    Azure support is coming in a future release — AWS is fully supported today.

  • Scan Google Cloud projects for misconfigurationsPublic Preview

    Google Cloud support is coming in a future release — AWS is fully supported today.

  • Scan AWS resources for misconfigurations
CSPM Dashboard
259
AWS Checks
AWS
Cloud Coverage
Multi-factor
Risk Score
<3m
Scan Time
CIEM

Cloud Identity & Entitlement Management

Map every identity, entitlement, and access path. Enforce least privilege.

  • Segregation-of-duties violation detection
  • Unused access and excessive-permission detection
  • Least-privilege recommendations with real IAM discovery
  • Identity security available in Professional tier
CIEM Dashboard
SoD
Violation Engine
Real-time
Discovery
AWS
Cloud Coverage
Enterprise
Tier
DSPM

Data Security Posture Management

Discover and classify sensitive data (PII, PCI, PHI) across your cloud data stores.

  • Automatically discover sensitive data (PII, PCI, PHI) with entropy + Luhn + regex classification
  • Scan S3 buckets for sensitive data exposure
  • Scan RDS databases for sensitive data exposure
  • Scan DynamoDB tables for sensitive data exposure
DSPM Dashboard
S3 / RDS / DynamoDB
Stores Scanned
PII / PCI / PHI
Classifications
Luhn + Shannon
Classifier
Professional+
Tier
CDR

Cloud Detection & Response

Respond to cloud threats with one-click isolation, credential revocation, and evidence snapshots.

  • One-click EC2 isolation via quarantine security group
  • Quarantine S3 buckets by applying deny-all policy with CloudTrail exception
  • Disable compromised IAM users with AWSCompromisedKeyQuarantineV2 + key deactivation
CDR Dashboard
One-click
Response Actions
Undo
Safety
AWS
Cloud Coverage
Enterprise
Tier
IaC

Infrastructure-as-Code Security

Scan Terraform, CloudFormation, Kubernetes, and Helm manifests before they deploy.

  • Checkov-based IaC scanning across 8 frameworks
  • GitHub webhook triggers scans with timing-safe HMAC-SHA256 signature verification
  • Automatic GitHub Pull Request creation with remediation diff attached to each finding
IaC Dashboard
8
Frameworks
Checkov
Scanner
Auto-PR
Remediation
HMAC
Webhook Auth
Secrets

Exposed Credential & API Key Detection

Detect leaked AWS keys, GitHub tokens, API keys, and private certificates across your cloud surface.

  • Detect AWS keys, GitHub tokens, Stripe keys, private certificates, and more
  • Fingerprint-based deduplication prevents alert fatigue
Secrets Dashboard
13
Detectors
Fingerprint
Dedup
BullMQ
Scan Queue
Professional+
Tier
Containers

Container & Image Security

Scan container images and registries for CVEs and generate SBOMs in SPDX or CycloneDX format.

  • Trivy-based container image vulnerability scanning
  • SBOM generation in SPDX and CycloneDX format
  • Container security dashboard with per-image CVE drill-down
Containers Dashboard
Trivy
Scanner
SPDX + CycloneDX
SBOM
ECR / GCR / ACR
Registries
UI: soon
Dashboard
Runtime

Vigil Runtime Protection

eBPF-based kernel-level runtime detection for Linux workloads with minimal overhead.

  • Real eBPF agent for network, exec, and file-system event capturePublic Preview

    Runtime protection is coming in a future release — cloud posture management is fully supported today.

  • gRPC agent enrollment with single-use tokens and mTLSPublic Preview

    Runtime protection is coming in a future release — cloud posture management is fully supported today.

Runtime Dashboard
eBPF
Kernel-Level
Real-time
Detection
mTLS
Agent Auth
Linux
Platform
SIEM

SIEM Integration

Export security events to Splunk, Microsoft Sentinel, or any webhook endpoint.

  • Splunk HEC export with batched, retried HTTPS POST
  • Microsoft Sentinel Log Analytics ingestion with HMAC-SHA256 signing
  • Generic webhook export for any SIEM or ticketing system
SIEM Dashboard
Splunk HEC
Adapter
Sentinel HMAC
Adapter
Webhook
Adapter
Event-driven
Transport
Compliance

Compliance Automation

SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST frameworks with auto-collected evidence.

  • SOC 2 Type II framework with mapped controls
  • ISO 27001 Annex A controls
  • HIPAA Safeguards framework
  • PCI-DSS v4.0 framework
  • NIST Cybersecurity Framework 2.0
  • Auditor-ready PDF compliance reports with one click
Compliance Dashboard
5
Frameworks
230+
Controls
1-click
Report Gen
Auto
Evidence
Security Graph

Attack Path Analysis

Interactive graph visualization maps exploitable paths from internet exposure to crown-jewel data.

  • Bidirectional BFS attack-path discovery on Neptune graph
  • Remediation guidance with automation-ready action markers per path step
  • Production-safe: mock provider cannot ship
Security Graph Dashboard
Neptune
Graph Backend
Bidirectional BFS
Algorithm
Production-safe
Guard
Growth+
Tier

See Sentrafort in Action

Book a personalized demo and see how every product works with your cloud environment.