Skip to content
Sentinel — Vulnerability Scanner

Vulnerability scanning built for security, not just compliance.

Sentinel continuously scans everything you have facing the internet — domains, subdomains, IPs, web apps, cloud, and containers — and tells you what an attacker could actually use. Our team reviews every result, so you get real issues with a fix, not a wall of alerts.

Find real weaknesses before someone else does — continuous external and web app scanning, not an annual snapshot.
Fix them with help, not homework — every finding comes with remediation steps, and our engineers work the plan with you.
Satisfy the scanning requirement automatically — SOC 2, ISO 27001, and HIPAA all expect ongoing scanning. The evidence generates itself.

Included with every Securest engagement. No agents to install for external scanning.

app.getsecurest.com / sentinel / findings
Findings — Acme Health
Last scan Sep 14, 2026 · bi-weekly cadence
TRIAGED & RELEASED
CRITICAL
1
HIGH
4
MEDIUM
9
LOW
14
CRITICAL
Exposed admin console, no authentication
ops.acmehealth.io:8443
Remediating
HIGH
Outdated TLS configuration accepts TLS 1.0
api.acmehealth.io:443
Open
HIGH
Publicly readable object storage bucket
acme-static-assets
Verified
MEDIUM
Missing security headers on login flow
app.acmehealth.io
Triaging
Info findings auto-suppressed on ingest · low and medium held for Securest review
Findings mapped toSOC 2ISO 27001HIPAA
Two problems, one program

Stronger security and a cleaner audit come from the same work.

Most teams start scanning because a customer or an auditor asked. What they get is a clearer picture of their own infrastructure than they've ever had — and the compliance evidence falls out of it.

See it

You can't secure what you don't know about

Forgotten staging environments, a subdomain from a project two years ago, a database port left open during a migration. Sentinel maps what's actually reachable from the internet, then re-checks it every cycle as your infrastructure changes.

Fix it

A finding without a fix is a liability

Every issue we surface includes what it is, why it matters, and the specific change that closes it — written for engineers, not security specialists. Our team helps you sequence the work and confirms the fix landed on the next scan.

Prove it

The evidence is a by-product, not a project

SOC 2, ISO 27001, and HIPAA all expect ongoing scanning with findings tracked to closure. Running the program produces that record automatically — scan history, severity, ownership, and resolution, mapped to the controls it satisfies.

How it works

Five steps. One of them is yours.

You authorize the assets. We do the rest.

1You

Authorize the scope

You tell us what we're allowed to scan. Subdomains inherit authorization from the parent domain. We log who approved it and when.

2Securest

Find what's actually exposed

We enumerate your subdomains, scan for open ports, and fingerprint what's running on each one. It's usually more than people expect.

3Securest

Scan on your cadence

We recommend weekly. Monthly is the floor. Every discovered service gets checked against a version-pinned template library, plus OWASP Top 10 testing on your web apps.

4Securest

Cut the noise

Info-level findings are suppressed on ingest. Low and medium go through one of our analysts. High and critical reach you with guidance already attached.

5Together

Fix it and prove it

You get the report and the vulnerability dashboard. We can open the Jira ticket, work the plan with you, and confirm the fix on the next scan.

The engines underneath

We tried sending clients to Rapid7 and Tenable first. The tools were fine. Getting evidence out of them that satisfied an auditor, and getting them to play nicely with Secureframe and Vanta, was not. So we built our own on top of the same industry-standard engines, version-pinned so every report is reproducible.

ProjectDiscoveryLIVE

Your external attack surface. Subdomain discovery, port and service enumeration, and CVE detection against a template library that updates within hours of a new disclosure.

OWASP ZAPLIVE

Web app testing against your live services, authenticated or not. You give us an exclusion list so nothing touches logout, delete, or anything else destructive.

TrivyLIVE

Containers and images. The vulnerabilities your base image and your dependencies brought along without telling you.

ProwlerLIVE

Cloud posture across AWS, Azure, and GCP, mapped to the same control set as everything else.

OpenVASCOMING SOON

Internal network scanning behind the firewall. Servers, workstations, and databases that never face the internet.

Triage and remediation

Every scan lands in our review queue before it lands in yours.

Scanners are noisy by design — they report everything and let someone else decide what matters. That someone is us. Our analysts verify each result, discard what isn't real, rank what is, and attach the fix before it reaches your dashboard. You spend your time remediating instead of investigating.

Severity sets the deadline

Critical and high get fixed on a clock. Medium and low can go on the risk register with a documented decision — a legitimate answer, and one auditors accept when it's written down.

Critical  →  3–14 days
High      →  30 days
Medium   →  90 days
Low       →  best effort

Findings are never deleted

Fix something and it's marked resolved, then verified on the next scan — it doesn't vanish. That history is what an auditor tests: when it appeared, who owned it, how long it took, and whether it stayed fixed. If it reappears, it reopens automatically.

OpenTriagingRemediatingResolvedVerifiedSuppressedDisputed

Work it where your team already works

Push a finding to Jira with the severity, affected hosts, and remediation steps prefilled, or track it in the vulnerability dashboard. Either satisfies an auditor, as long as the tracking is real and the dates line up.

Outdated TLS configuration accepts TLS 1.0
api.acmehealth.io:443 · CVE-2011-3389 · CVSS 7.4
HIGH
Source
External scan
First seen
Jul 02, 2026
Last seen
Sep 14, 2026
Status
Open
Remediation guidanceReviewed by Securest

Disable TLS 1.0 and 1.1 at the load balancer and restrict the cipher suite to TLS 1.2+ with forward secrecy. In AWS, attach the ELBSecurityPolicy-TLS13-1-2-2021-06 policy to the listener, then re-scan to verify.

Satisfies
SOC 2 CC6.7ISO 27001 A.8.24HIPAA §164.312(e)(1)
Create Jira ticketAsk SecurestFlag false positive
Deliverables

Auditor-accepted evidence, and a security posture that actually improved.

After every scan you get a branded, timestamped, framework-mapped report written for your auditor — alongside the working record of what was found, who fixed it, and when.

Audit-ready PDF report

Scope, methodology, findings by severity, and a per-control evidence appendix. Hand it over as-is.

Live vulnerability dashboard

Severity, source, first and last seen, owner, and remediation status for every finding.

Scan history and evidence trail

Proof the program ran on schedule, cycle after cycle, retained for the full audit period.

Remediation guidance

The specific change that closes each finding, reviewed by the analyst who triaged it.

Securest
External Vulnerability Scan Report
Acme Health, Inc.
Scan window: Sep 14–15, 2026
Frameworks: SOC 2 · ISO 27001 · HIPAA
Report ID: SNT-2026-0914-AH
Contents
Scope and authorization02
Methodology and tooling03
Findings summary by severity05
Finding detail with CVE and status07
Per-control evidence appendix18
1
CRIT
4
HIGH
9
MED
14
LOW

Immutable artifact. Timestamped, version-pinned scanner templates, retained for the full audit period.

Evidence, not attachments

Push findings straight into your GRC platform as evidence.

Reports don't sit in a shared drive waiting for someone to remember them at audit time. Each scan is pushed into your compliance platform and attached to the controls it satisfies, on the same cadence your evidence collection already runs.

As the #1 Secureframe MSP partner, this is the part we've done a few hundred times. Pick your platform to see where the report lands.

SecureframeControls › Evidence
Control
CC7.1 — Vulnerability detection and monitoring
SOC 2 Type II · Owner: Securest
Linked evidence
Sentinel_Scan_2026-09-14.pdf
Uploaded by Securest · auto-sync
ACCEPTED
Findings mapped to this control
Outdated TLS configurationCC6.7
Missing security headersCC6.6
Scan ran on defined cadenceCC7.1
Evidence freshnessCurrent — next sync Sep 28
VantaTests › Documents
Test
Vulnerability scanning performed on schedule
ISO 27001 A.8.8 · Owner: Securest
Test passing — document attached
Sentinel_Scan_2026-09-14.pdf
Policy document · renews bi-weekly
Findings mapped to this test
Outdated TLS configurationA.8.24
Missing security headersA.8.9
Scan ran on defined cadenceA.8.8
Last checked2 hours ago
DrataMonitoring › Evidence Library
Requirement
Infrastructure vulnerabilities are identified and tracked
SOC 2 & HIPAA · Owner: Securest
Evidence library
Sentinel_Scan_2026-09-14.pdf
Sep 14, 2026 · current period
LINKED
Sentinel_Scan_2026-08-31.pdf
Aug 31, 2026 · archived
HISTORY
Findings mapped to this requirement
Unauthenticated admin interface§164.312(a)
Outdated TLS configurationCC6.7
CollectionAutomated — bi-weekly

Unmapped findings surface as uncategorized — never dropped.

Internal scanning — coming soon

Internal network scanning, for when external isn't enough.

External scanning covers SOC 2 and HIPAA scope. ISO 27001 A.8.8 — and the more thorough auditors — expect coverage behind the firewall too: servers, workstations, and databases that never touch the internet.

Internal scanning runs on a dedicated appliance reachable by agent or VPN, and feeds the same dashboard, the same triage queue, and the same report. It's a separate module with its own scoping and security review — talk to your vCISO about whether your scope needs it.

  • Same dashboard, same report
    Internal findings land in the identical triage queue and PDF template — no second tool to learn.
  • Agent or VPN reachable
    Deployed on a dedicated appliance inside your network. Nothing internal is ever exposed outward.
  • Required for ISO 27001 A.8.8
    Full technical vulnerability management coverage, which external-only scanning doesn't satisfy.
  • Scoped separately
    Its own contract and security review, so the blast radius is agreed before anything is deployed.
Scanning and pen testing

A pentest is a snapshot. Your vulnerability program runs continuously.

Both come up in every audit cycle, and they answer different questions. Sentinel doesn't replace a pen test — we arrange those too. Here's how they fit together.

Penetration test

How far could someone get?

A specialist spends days chaining weaknesses together to prove real-world impact — the kind of judgment no scanner replicates. It's a point-in-time assessment, usually annual, and it reflects your environment on the day it ran.

Vulnerability scanning

What's exposed right now?

Every asset checked against thousands of known vulnerability signatures, every cycle. It catches the certificate that expired last week and the service someone spun up on Tuesday — the changes that happen between pen tests.

Together

Depth once, coverage always

The pen test finds what automation can't reason about. Continuous scanning makes sure the gap between tests doesn't become the gap someone walks through. Auditors expect evidence of both, and they check the dates.

Let's scan your external attack surface.

Give us your domain and the frameworks you're working toward. We'll get authorization on file, run the first scan, and walk you through the findings with a vCISO — not a PDF dropped in your inbox.

Every scan is authorized in writing before it runs, per asset, with the approver and timestamp logged.