Swiss · Attack Surface & Vulnerability Management

See what attackers see.

Find every exposed system, scan your network inside and out, and get one fix list ordered by business risk.

Controlled benchmark 59 scored issues · 14 hosts · August 2026

87.3% detection accuracy. 331% faster.

In a controlled comparison with a leading commercial scanner, Sentinel found more known issues and completed the scan over 4 times faster.

Detection accuracy Higher is better
Sentinel 87.29%
Commercial reference 74.58%
Known issues found Higher is better
Sentinel 93.22%
Commercial reference 77.97%
Scan time Lower is better
Sentinel 11m 40s
Commercial reference 50m 15s

Both scanners assessed the same test network under the same conditions. We checked every result against the known security issues in that network.

Source · Endolum controlled scanner benchmark
Free security scan Deleted after 24 hours

See what your public IP exposes in 30 to 60 minutes.

Report is usually delivered within 60 minutes
Your free report includes
Open ports and matched CVEs on your current public IP
A plain language summary ordered by business risk
Clear remediation steps that tell you what to fix first
One free scan per public IP every 7 days
How Sentinel works Discover · Scan · Prioritize · Verify
01 / Discovery

Start with one domain and see the whole surface.

Sentinel finds the subdomains, IP addresses, certificates, and live services connected to your company. It watches certificate logs continuously, so new internet facing hosts reach your change feed the day they appear.

02 / External scan

Fix the risks that matter first.

Sentinel discovers ports, identifies services, matches CVEs, checks exploit activity, and safely tests for default credentials and misconfigurations. Your report ranks the evidence by business impact and tells you what to do next.

03 / Internal scan

Cover the network your firewall hides.

Run one container that only connects outward from your network. Sentinel finds live hosts, assesses them, and adds every internal finding to the same dashboard and report, with no inbound ports or appliance.

04 / Expert analysis

Add an analyst when the stakes demand it.

On Enterprise, an analyst verifies the evidence, reviews threat activity in your sector, and traces attack paths automated scans can miss. You receive one report for your board or auditor, with every fix in priority order.

What changes for you One product · One login

See every exposed asset and know exactly what to fix first.

CHF 299 per month gives you external discovery, scheduled scans, internal coverage for up to 256 live assets, and reports in English or German. Buy it online and start the same afternoon, with no annual minimum or integration project.

01 / Forgotten services

Find the systems everyone forgot.

Sentinel surfaces public RDP, Telnet, SMB, test servers, and vendor access that outlived their purpose. You see each one in the first report, with the evidence needed to close it.

02 / Outdated software

Know which outdated software needs attention first.

Every finding names the affected version, CVE, available fix, and whether public exploit code exists. EPSS and CISA KEV data show which weaknesses deserve immediate attention.

03 / Weak credentials

Catch default credentials before they become an entry point.

Sentinel safely checks common defaults on exposed routers, storage devices, and services. The test stops at the first match and never exploits the target.

04 / Finding lifecycle

Know whether every fix stays fixed.

Sentinel separates new, resolved, and returned findings. If a weakness comes back, you see it as a regression with its history intact.

05 / AI reporting

Get the right report depth for your environment.

Home uses a standard model. Business uses a premium model. Enterprise uses the most capable model.

06 / Change alerts

Choose which changes deserve your attention.

Set email or webhook alerts for new hosts, vanished services, and expiring certificates. Every muted change stays in the feed, so the history remains complete.

Choose your coverage Home · Business · Enterprise
All prices in CHF · VAT excluded · Swiss jurisdiction
Questions Common

What is Attack Surface Management?

Attack Surface Management continuously finds and monitors everything your company exposes to the internet: domains, subdomains, IP addresses, certificates, and live services. Give Sentinel one verified domain and it builds the inventory, watches for changes, and lets you scan the hosts that matter.

We have a firewall. Why scan?

A firewall enforces the rules it has today. Sentinel checks the result from the internet and finds old forwards, forgotten exceptions, and services that should have closed. That outside view shows what an attacker can actually reach.

Are we too small to be a target?

Automated scanners do not filter by headcount. They probe public IPs for exposed VPNs, servers, and known flaws. One unpatched gateway creates the same opening at a 20 person business as it does at a company with 5000 people.

Will the scan break anything?

Sentinel identifies services and matches them with known CVEs. Credential checks use common defaults and stop at the first match. Sentinel does not exploit a finding, change the target, or install software.

What does internal scanning require?

Run one Docker container on a host inside your network. It makes an outbound connection to Sentinel, discovers live hosts, and sends findings into the same dashboard. You open no inbound port, build no VPN, and install no appliance.

How is this different from an internet search engine?

Internet search engines provide broad public data. Sentinel assesses systems you own on demand, shows the evidence, and turns it into a prioritized remediation plan. Use Sentinel when the next question is what your team should fix first.

What is the annual assessment?

On Enterprise, an analyst reviews your full external surface, exposed services, current threats in your sector, and the evidence behind every finding. The final report traces combined attack paths and puts each fix in business priority order. We agree the scope and price with you before the assessment.

Is this legal?

Sentinel only scans systems you own or are authorized to assess. The free scan checks the public IP your request comes from. Business targets require DNS or administrator verification before Sentinel accepts them.

What about my data?

Free scan data is deleted 24 hours after delivery. Business data is encrypted at rest and retained while your subscription remains active. The platform runs in Frankfurt, while your customer agreement falls under Swiss jurisdiction.

Can my MSP resell this?

Swiss IT providers, MSPs, security consultants, and system integrators can resell Sentinel under recurring service agreements. Approved partners receive a private rate card in the written agreement and keep the customer relationship. See the partner program.

See what your public IP exposes in 30 to 60 minutes for CHF 0.