Skip to content
  Sentinel — Vulnerability Scanner

Vulnerability scanning built for security, not just compliance.

Sentinel scans your external attack surface and web applications on a cadence you choose. Our team reviews the results, filters the noise, and hands you findings already mapped to SOC 2, ISO 27001, and HIPAA.

We set it up. It runs. You get a clean report your auditor accepts.

Included in every Securest engagement.
No agent installation required for external scanning.

app.getsecurest.com / sentinel / findings
Findings — Acme Health
Last scan Sep 14, 2026 · bi-weekly cadence
TRIAGED & RELEASED
CRITICAL
1
HIGH
4
MEDIUM
9
LOW
14
CRITICAL
Exposed admin console, no authentication
ops.acmehealth.io:8443
Remediating
HIGH
Outdated TLS configuration accepts TLS 1.0
api.acmehealth.io:443
Open
HIGH
Publicly readable object storage bucket
acme-static-assets
Verified
MEDIUM
Missing security headers on login flow
app.acmehealth.io
Triaging
41 info findings auto-suppressed on ingest · 12 low/medium held for Securest review
Findings mapped toSOC 2ISO 27001HIPAA
Scanning vs. pentesting

A pentest is a snapshot. Scanning is the part your auditor asks about every quarter.

You likely need both — and we run both. But if you're choosing where to start, it helps to know what each one is actually for.

Penetration test

Deep, manual, once a year

A human tries to break in, chains findings together, and tells you what a determined attacker could actually do. Invaluable — and already twelve months stale by your next audit.

Vulnerability scanning

Broad, automated, continuous

Every asset checked against 11,000+ known vulnerability signatures on a set cadence. It catches the thing you shipped last Tuesday, and it proves the cadence to your auditor.

Sentinel's job

The ongoing half, managed

Auditors don't just want a report — they want evidence the program ran on schedule and that findings got resolved. Sentinel produces that record, every cycle, without your team maintaining it.

How it works

Five steps, and only one of them is yours.

You authorize the assets. We handle everything after that.

1You

Authorize the scope

You attest to the assets we're allowed to scan. Subdomains inherit authorization from their parent domain. Approver and timestamp are logged.

2Securest

Discover the surface

Subdomain enumeration, port discovery, and service fingerprinting build a live picture of what's actually exposed — usually more than expected.

3Securest

Scan on cadence

Every discovered service is checked against a version-pinned template library covering 11,000+ CVEs, plus OWASP Top 10 testing on web apps.

4Securest

Triage the noise

Info findings auto-suppress. Low and medium go through analyst review. High and critical reach you with remediation guidance attached.

5Together

Report and remediate

You get the audit-ready PDF and the in-app board. We work the remediation plan with you and re-verify on the next run.

The engines underneath

Battle-tested, industry-standard scanners — managed, tuned, and version-pinned by us so every report is reproducible.

ProjectDiscoveryLIVE

External attack surface: subdomain discovery, port and service enumeration, CVE detection against a continuously updated template library.

OWASP ZAPLIVE

Web application DAST against your discovered HTTP services, including authenticated scans with production-safety exclusions.

TrivyLIVE

Container and image scanning for the vulnerabilities your base images and dependencies bring with them.

ProwlerLIVE

Cloud infrastructure posture checks across your AWS, Azure, and GCP accounts, mapped to the same control set.

OpenVASCOMING SOON

Internal network scanning behind the firewall — servers, workstations, and databases that never face the internet.

Assets & cadence

Your attack surface, inventoried — then scanned on a schedule you control.

Add a domain and Sentinel enumerates the subdomains behind it, so nothing quietly falls out of scope. Pick weekly, bi-weekly, or monthly during setup, and change it whenever your risk profile does — your history stays intact.

  • Domains, subdomains, and IP ranges in one inventory, with discovery keeping it current
  • Per-asset authorization attested and logged before anything is scanned
  • Pause or reschedule any time without losing scan history
  • Findings deduplicated across runs — a re-scan updates a finding, it doesn't clone it
Assets+ Add asset
acmehealth.io
Root domain · 14 subdomains discovered
AUTHORIZED
api.acmehealth.io
Inherited from acmehealth.io
AUTHORIZED
203.0.113.0/28
IP range · 6 hosts responding
AUTHORIZED
Scan cadence
WeeklyBi-weeklyMonthly
Next scan: Sep 28, 2026 · 02:00 UTCAuthorization on file
Triage & remediation

We triage it first. Then your team tracks it to done.

Raw scanner output is mostly noise, and handing a client 400 findings isn't a service. Every scan lands in our internal review queue first: info-level findings are auto-suppressed, low and medium go through a Securest analyst, and high and critical are surfaced to you with remediation guidance attached. What reaches your dashboard is work that's actually worth doing.

One lifecycle, end to end

Every finding carries a status, an owner, and a full history — the audit trail your assessor wants when they ask “what did you do about it?”

OpenTriagingRemediatingResolvedVerifiedSuppressedDisputed

Resolved findings are re-checked on the next scan. If one reappears, it reopens automatically — no silent regressions.

Disputes and false positives, handled

Flag a finding as a false positive and we re-scan to verify. Disputed and suppressed findings drop out of your default view but stay in the trail permanently, with the reason and the approver recorded.

Outdated TLS configuration accepts TLS 1.0
api.acmehealth.io:443 · CVE-2011-3389 · CVSS 7.4
HIGH
Source
External scan
First seen
Jul 02, 2026
Last seen
Sep 14, 2026
Status
Open
Remediation guidanceReviewed by Securest

Disable TLS 1.0 and 1.1 at the load balancer and restrict the cipher suite to TLS 1.2+ with forward secrecy. In AWS, attach the ELBSecurityPolicy-TLS13-1-2-2021-06 policy to the listener, then re-scan to verify.

Satisfies
SOC 2 CC6.7ISO 27001 A.8.24HIPAA §164.312(e)(1)
Mark remediatingAsk SecurestFlag false positive
Deliverables

What lands in your hands after every scan.

The report is the point. It's branded, timestamped, framework-mapped, and written to be handed straight to your auditor without a covering explanation.

Audit-ready PDF report

Branded, timestamped, framework-mapped. Hand it straight to your auditor.

In-platform findings view

Severity, source, and remediation status for every finding, live in Securest.

Scan history and evidence trail

A complete record proving scans ran on schedule, cycle after cycle.

Remediation guidance

Clear, specific steps per finding — reviewed by the analyst who triaged it.

Securest
External Vulnerability Scan Report
Acme Health, Inc.
Scan window: Sep 14–15, 2026
Frameworks: SOC 2 · ISO 27001 · HIPAA
Report ID: SNT-2026-0914-AH
Contents
Scope and authorization02
Methodology and tooling03
Findings summary by severity05
Finding detail with CVE and status07
Per-control evidence appendix18
1
CRIT
4
HIGH
9
MED
14
LOW

Immutable artifact. Timestamped, version-pinned scanner templates, retained for the full audit period.

Evidence, not attachments

Push findings straight into your GRC platform as evidence.

Sentinel reports don't sit in a shared drive waiting for someone to remember them. Each scan can be pushed into your compliance platform, attached to the controls it satisfies, on the same cadence your evidence collection runs. As the #1 Secureframe MSP partner, this is the part we've done a few hundred times.

SecureframeVantaDrata
Control mapping — excerpt
Outdated TLS configuration
SOC 2 CC6.7 · ISO A.8.24
Missing security headers
SOC 2 CC6.6 · ISO A.8.9
Unauthenticated admin interface
SOC 2 CC6.1 · HIPAA §164.312(a)
Scan ran on defined cadence
ISO A.8.8 · SOC 2 CC7.1
Unmapped findings surface as uncategorized — never dropped.
Internal scanning — coming soon

Internal network scanning, for when external isn't enough.

External scanning covers SOC 2 and HIPAA scope. ISO 27001 A.8.8 — and the more thorough auditors — expect coverage behind the firewall too: servers, workstations, and databases that never touch the internet.

Sentinel's internal scanning runs on a dedicated appliance reachable by agent or VPN, and feeds the same dashboard, the same triage queue, and the same report. It's a separate module with its own scoping and security review — talk to your vCISO about whether your scope needs it.

  • Same dashboard, same report
    Internal findings land in the identical triage queue and PDF template — no second tool to learn.
  • Agent or VPN reachable
    Deployed on a dedicated appliance inside your network. Nothing internal is ever exposed outward.
  • Required for ISO 27001 A.8.8
    Full technical vulnerability management coverage, which external-only scanning doesn't satisfy.
  • Scoped separately
    Its own contract and security review, so the blast radius is agreed before anything is deployed.

Let's scan your external attack surface.

Give us your domain and the frameworks you're working toward. We'll get authorization on file, run the first scan, and walk you through the findings with a vCISO — not a PDF dropped in your inbox.

Every scan is authorized in writing before it runs, per asset, with the approver and timestamp logged.