Vulnerability scanning built for security, not just compliance.
Sentinel scans your external attack surface and web applications on a cadence you choose. Our team reviews the results, filters the noise, and hands you findings already mapped to SOC 2, ISO 27001, and HIPAA.
We set it up. It runs. You get a clean report your auditor accepts.
Included in every Securest engagement.
No agent installation required for external scanning.
A pentest is a snapshot. Scanning is the part your auditor asks about every quarter.
You likely need both — and we run both. But if you're choosing where to start, it helps to know what each one is actually for.
Deep, manual, once a year
A human tries to break in, chains findings together, and tells you what a determined attacker could actually do. Invaluable — and already twelve months stale by your next audit.
Broad, automated, continuous
Every asset checked against 11,000+ known vulnerability signatures on a set cadence. It catches the thing you shipped last Tuesday, and it proves the cadence to your auditor.
The ongoing half, managed
Auditors don't just want a report — they want evidence the program ran on schedule and that findings got resolved. Sentinel produces that record, every cycle, without your team maintaining it.
Five steps, and only one of them is yours.
You authorize the assets. We handle everything after that.
Authorize the scope
You attest to the assets we're allowed to scan. Subdomains inherit authorization from their parent domain. Approver and timestamp are logged.
Discover the surface
Subdomain enumeration, port discovery, and service fingerprinting build a live picture of what's actually exposed — usually more than expected.
Scan on cadence
Every discovered service is checked against a version-pinned template library covering 11,000+ CVEs, plus OWASP Top 10 testing on web apps.
Triage the noise
Info findings auto-suppress. Low and medium go through analyst review. High and critical reach you with remediation guidance attached.
Report and remediate
You get the audit-ready PDF and the in-app board. We work the remediation plan with you and re-verify on the next run.
The engines underneath
Battle-tested, industry-standard scanners — managed, tuned, and version-pinned by us so every report is reproducible.
External attack surface: subdomain discovery, port and service enumeration, CVE detection against a continuously updated template library.
Web application DAST against your discovered HTTP services, including authenticated scans with production-safety exclusions.
Container and image scanning for the vulnerabilities your base images and dependencies bring with them.
Cloud infrastructure posture checks across your AWS, Azure, and GCP accounts, mapped to the same control set.
Internal network scanning behind the firewall — servers, workstations, and databases that never face the internet.
Your attack surface, inventoried — then scanned on a schedule you control.
Add a domain and Sentinel enumerates the subdomains behind it, so nothing quietly falls out of scope. Pick weekly, bi-weekly, or monthly during setup, and change it whenever your risk profile does — your history stays intact.
- ✓Domains, subdomains, and IP ranges in one inventory, with discovery keeping it current
- ✓Per-asset authorization attested and logged before anything is scanned
- ✓Pause or reschedule any time without losing scan history
- ✓Findings deduplicated across runs — a re-scan updates a finding, it doesn't clone it
We triage it first. Then your team tracks it to done.
Raw scanner output is mostly noise, and handing a client 400 findings isn't a service. Every scan lands in our internal review queue first: info-level findings are auto-suppressed, low and medium go through a Securest analyst, and high and critical are surfaced to you with remediation guidance attached. What reaches your dashboard is work that's actually worth doing.
One lifecycle, end to end
Every finding carries a status, an owner, and a full history — the audit trail your assessor wants when they ask “what did you do about it?”
Resolved findings are re-checked on the next scan. If one reappears, it reopens automatically — no silent regressions.
Disputes and false positives, handled
Flag a finding as a false positive and we re-scan to verify. Disputed and suppressed findings drop out of your default view but stay in the trail permanently, with the reason and the approver recorded.
Disable TLS 1.0 and 1.1 at the load balancer and restrict the cipher suite to TLS 1.2+ with forward secrecy. In AWS, attach the ELBSecurityPolicy-TLS13-1-2-2021-06 policy to the listener, then re-scan to verify.
What lands in your hands after every scan.
The report is the point. It's branded, timestamped, framework-mapped, and written to be handed straight to your auditor without a covering explanation.
Audit-ready PDF report
Branded, timestamped, framework-mapped. Hand it straight to your auditor.
In-platform findings view
Severity, source, and remediation status for every finding, live in Securest.
Scan history and evidence trail
A complete record proving scans ran on schedule, cycle after cycle.
Remediation guidance
Clear, specific steps per finding — reviewed by the analyst who triaged it.

Frameworks: SOC 2 · ISO 27001 · HIPAA
Report ID: SNT-2026-0914-AH
Immutable artifact. Timestamped, version-pinned scanner templates, retained for the full audit period.
Push findings straight into your GRC platform as evidence.
Sentinel reports don't sit in a shared drive waiting for someone to remember them. Each scan can be pushed into your compliance platform, attached to the controls it satisfies, on the same cadence your evidence collection runs. As the #1 Secureframe MSP partner, this is the part we've done a few hundred times.
Internal network scanning, for when external isn't enough.
External scanning covers SOC 2 and HIPAA scope. ISO 27001 A.8.8 — and the more thorough auditors — expect coverage behind the firewall too: servers, workstations, and databases that never touch the internet.
Sentinel's internal scanning runs on a dedicated appliance reachable by agent or VPN, and feeds the same dashboard, the same triage queue, and the same report. It's a separate module with its own scoping and security review — talk to your vCISO about whether your scope needs it.
- Same dashboard, same reportInternal findings land in the identical triage queue and PDF template — no second tool to learn.
- Agent or VPN reachableDeployed on a dedicated appliance inside your network. Nothing internal is ever exposed outward.
- Required for ISO 27001 A.8.8Full technical vulnerability management coverage, which external-only scanning doesn't satisfy.
- Scoped separatelyIts own contract and security review, so the blast radius is agreed before anything is deployed.
Let's scan your external attack surface.
Give us your domain and the frameworks you're working toward. We'll get authorization on file, run the first scan, and walk you through the findings with a vCISO — not a PDF dropped in your inbox.
Every scan is authorized in writing before it runs, per asset, with the approver and timestamp logged.
