A Cyber Risk Intelligence Platform built on one canonical model.
SentriScope is not an AI platform. It normalizes fragmented security data through governed connectors, produces deterministic Risk Decision Objects with full lineage, and gives analysts investigation workflows to act on what matters, with read-only AI as optional decision support.
- Ingest Governed connectors Audited, tenant-scoped ingestion from scanners, directories, and CTI providers.
- Normalize Canonical model Assets, vulnerabilities, identities, and findings share one spine with provenance.
- Decide Risk Decision Objects Deterministic scoring with explainable, overridable prioritization decisions.
- Investigate Analyst workflows Guided investigation sessions connect ranked signals to analyst action.
The product spine: how capabilities connect through canonical data and traceable decisions.
Three capabilities at the center of the platform
Exposure intelligence, deterministic prioritization, and analyst investigation: the depth most security teams evaluate first.
Attack surface visibility and multi-signal vulnerability prioritization
Unified view of external and internal exposure with asset and finding normalization across sources. Vulnerabilities are prioritized using CVSS v3/v4 arbitration, EPSS exploitation probability, CISA KEV, SSVC triage, and business context, not raw severity alone.
See connector catalog- Attack Surface & Exposure with environment classification
- CVSS, EPSS, KEV, and SSVC beyond raw CVSS severity
- Asset and finding normalization into the canonical model
Deterministic prioritization with auditable Risk Decision Objects
Governed, deterministic risk scoring combines exploit velocity, business impact, control effectiveness, and CTI signals. Every prioritization decision is recorded as a Risk Decision Object with explainability, override governance, and a full audit trail. Attack path context supports analyst-driven prioritization. This is contextual analysis, not autonomous discovery.
How decisions are governed- Risk Decision Objects with transparent reasoning chains
- Risk Snapshots & Explainability for audit and review
- Contextual attack path analysis to inform prioritization
Guided investigation sessions and analyst-driven scenario work
Structured investigation sessions with evidence tracking connect CTI, vulnerabilities, and exposures in a guided workbench. Analysts use contextual attack path analysis to explain why a finding matters: analyst-controlled correlation across the canonical model, not autonomous discovery.
Explore investigation workflows- Investigation & Scenarios with evidence tracking
- Attack Path Intelligence: analyst-driven path analysis
- What-if scenarios linked to Risk Decision Objects
Additional modules grouped by domain
Beyond the three core modules, SentriScope extends across intelligence, platform services, data integration, and bounded AI guardrails.
-
Intelligence and CTIThreat Intelligence & Newsfeed Full-lifecycle CTI with IOC enrichment, fusion scoring, threat actor and campaign tracking, and credential leak monitoring correlated with canonical assets.Identity Intelligence Canonical identity model with risk aggregation, privilege tier assessment, Entra ID profiling, and credential risk scoring.Attack Path Intelligence Analyst-driven attack path analysis correlates assets, exposures, and controls to explain plausible paths in context. This is contextual analysis, not autonomous discovery.
-
Platform and governanceControls & Control Effectiveness Security controls governance with coverage assessment, effectiveness scoring, and audit-ready reporting against your asset inventory.Incident Lifecycle Incident management from detection through response and post-incident review, linked to investigations and Risk Decision Objects.Network Intelligence Network command center with IP addressing, DNS, DHCP, segmentation, and OT/ICS context correlated with asset risk.Assessment & Pentest Tracking Ingest pentest findings and security assessments with scope, targets, evidence, and remediation tracking tied to live risk posture.
-
Data integration and DevSecOps foundationsDevSecOps & SBOM Data Integration Ingest SBOM components and artifact lineage into the canonical model for supply-chain risk context. Data integration foundations via API and ingestion. There is no dedicated tenant SBOM UI.
-
Security and AI guardrailsLLM-assisted investigation Guardrailed, read-only LLM workflows: schema-grounded, SQL-validated, no credentials in context. Tenant- and plan-configurable decision support when enabled, with no autonomous remediation.
Related platform areas
Intelligence
CTI review queues, IOC enrichment, and analyst-controlled correlation workflows.
Platform
Three-surface architecture, connector governance, and organizational knowledge.
Integrations
Live connector catalog: ingestion sources and CTI enrichment providers.
Security
Tenant isolation, tamper-evident audit, RBAC, and LLM guardrail depth.
Questions about SBOM data integration or supply-chain ingestion? Contact our team or explore published documentation.
Evaluate the platform against your stack
Review integrations for your sources, explore intelligence workflows, or talk to our team about canonical normalization and governed prioritization.