Continuous monitoring · mesh-locked appliance

Pentest the inside of your network on a schedule.

Trustivum Sentry is a drop-in appliance that joins our private mesh network and runs continuous internal vulnerability and share-exposure scans inside your LAN. Findings stream into your portal with severity, CVSS, and remediation. No inbound firewall holes. No agent on every endpoint.

2 locks
private mesh + bearer token, AND'd
0
inbound firewall holes, customer side
~30s
poll cadence; jobs picked up live
YOUR LAN hosthosthostshare SENTRY scheduled scans → WireGuard mesh → portal
How it works

Three steps from box to first scan.

Sentry ships ready to go. The customer plugs it in, the analyst configures the scan windows, and the platform does the rest.

STEP 01

Plug it in.

Ethernet + USB-C power. The Sentry boots, joins the Trustivum private mesh via an outbound encrypted tunnel, and registers with the orchestrator.

~3 minutes
STEP 02

Submit the scoping form.

The customer fills out subnets, scan windows, restricted hosts, incident contact, and a typed authorization signature in the portal. The analyst reviews and approves.

analyst-reviewed
STEP 03

Findings stream in.

Sentry polls the orchestrator. New / changed / resolved findings appear in the portal as scans complete — de-duplicated by stable key, with severity, CVSS, and remediation.

live in the portal
Choose your tier

Four ways to use Trustivum.

Start with the one-shot external pentest if you just need an audit deliverable. Move up the tiers as you want continuous coverage and internal-network visibility.

SKU 1

One-Time External

The original Trustivum pentest. External-only, audit-credible, $2,495 flat.

  • External pentest
  • Internal network
  • Recurring scans
  • On-site Sentry appliance
  • Branded PDF report
  • SOC 2 / HIPAA mapping
  • Free retest within 30 days
Learn more →
SKU 2

Continuous External

Continuous perimeter monitoring run by Trustivum's analyst-operated scanner platform. No on-site appliance required.

  • External pentest baseline
  • Internal network
  • Recurring scans
  • On-site Sentry appliance
  • Findings dashboard
  • Manual retest on request
  • SOC 2 control evidence
Talk to us →
MOST POPULAR SKU 3

Continuous Total

External + internal continuous monitoring. On-site Sentry appliance for the life of the subscription; returns when you cancel.

  • External pentest baseline
  • Internal network
  • Recurring scans
  • On-site Sentry appliance
  • Findings dashboard
  • Manual retest on request
  • SOC 2 + HIPAA evidence
Talk to us →
SKU 4

Deep One-Time

One-shot internal + external pentest. On-site Sentry ships, runs, and returns. For audits that demand internal coverage.

  • External pentest baseline
  • Internal network
  • Recurring scans
  • On-site Sentry (returns after scan)
  • Branded PDF report
  • Free retest within 30 days
  • SOC 2 + HIPAA evidence
Talk to us →
Security model

Two AND'd locks. No exceptions.

A security tool that ships customers gear has to hold itself to a higher bar than the threat models it's helping you escape. Every Sentry → Trustivum communication has two independent locks. Both must hold.

1

Network: private mesh membership

The orchestrator's scanner API endpoints only resolve and accept connections from inside the dedicated Sentry private mesh — a separate, isolated overlay from any other Trustivum infrastructure. WireGuard encrypts the transport, defense-in-depth on top of TLS.

The Sentry mesh can't reach Trustivum customer-data planes — blast-radius isolated. A stolen Sentry on any other network has nowhere to send.

2

Application: per-Sentry bearer token

Every Sentry has a unique bearer token. The orchestrator stores only a SHA-256 hash; the plaintext lives solely on the device (root-owned, mode 0600). Token rotation is a single admin API call — recovery from a lost device is seconds, not hours.

Per-scanner sliding-window rate limits on poll/report endpoints, and every request is audit-logged with scanner ID, source IP, and outcome.

— logical AND — mesh without token: 401 · token without mesh: nowhere to connect
Questions

Common Sentry questions.

Do we have to open inbound firewall ports?

No. The Sentry reaches out over an encrypted WireGuard tunnel to join the private mesh — nothing connects inbound to your network. Zero inbound firewall holes on the customer side.

What happens if a Sentry is lost or stolen?

It's useless off your network: it needs both private-mesh membership and a valid bearer token to talk to anything, and the mesh can't reach customer-data planes anyway. Token rotation is a single admin call, so recovery is seconds.

Do we need an agent on every endpoint?

No. A single Sentry appliance scans the network from the inside — host discovery, CVE checks, share enumeration, and service fingerprinting — with no per-endpoint agent to deploy or maintain.

How do findings reach us?

Sentry polls the orchestrator roughly every 30 seconds and streams new, changed, and resolved findings into your portal as scans complete — de-duplicated by a stable key, each with severity, CVSS, and remediation.

Continuous coverage

Cover the other 364 days.

Start with an external pentest for the audit, then drop a Sentry on the LAN for continuous internal visibility. Talk to an analyst about the right tier.

Talk to an analyst → See the pentest platform