Trustivum Sentry is a drop-in appliance that joins our private mesh network and runs continuous internal vulnerability and share-exposure scans inside your LAN. Findings stream into your portal with severity, CVSS, and remediation. No inbound firewall holes. No agent on every endpoint.
Sentry ships ready to go. The customer plugs it in, the analyst configures the scan windows, and the platform does the rest.
Ethernet + USB-C power. The Sentry boots, joins the Trustivum private mesh via an outbound encrypted tunnel, and registers with the orchestrator.
The customer fills out subnets, scan windows, restricted hosts, incident contact, and a typed authorization signature in the portal. The analyst reviews and approves.
Sentry polls the orchestrator. New / changed / resolved findings appear in the portal as scans complete — de-duplicated by stable key, with severity, CVSS, and remediation.
Start with the one-shot external pentest if you just need an audit deliverable. Move up the tiers as you want continuous coverage and internal-network visibility.
The original Trustivum pentest. External-only, audit-credible, $2,495 flat.
Continuous perimeter monitoring run by Trustivum's analyst-operated scanner platform. No on-site appliance required.
External + internal continuous monitoring. On-site Sentry appliance for the life of the subscription; returns when you cancel.
One-shot internal + external pentest. On-site Sentry ships, runs, and returns. For audits that demand internal coverage.
A security tool that ships customers gear has to hold itself to a higher bar than the threat models it's helping you escape. Every Sentry → Trustivum communication has two independent locks. Both must hold.
The orchestrator's scanner API endpoints only resolve and accept connections from inside the dedicated Sentry private mesh — a separate, isolated overlay from any other Trustivum infrastructure. WireGuard encrypts the transport, defense-in-depth on top of TLS.
The Sentry mesh can't reach Trustivum customer-data planes — blast-radius isolated. A stolen Sentry on any other network has nowhere to send.
Every Sentry has a unique bearer token. The orchestrator stores only a SHA-256 hash; the plaintext lives solely on the device (root-owned, mode 0600). Token rotation is a single admin API call — recovery from a lost device is seconds, not hours.
Per-scanner sliding-window rate limits on poll/report endpoints, and every request is audit-logged with scanner ID, source IP, and outcome.
No. The Sentry reaches out over an encrypted WireGuard tunnel to join the private mesh — nothing connects inbound to your network. Zero inbound firewall holes on the customer side.
It's useless off your network: it needs both private-mesh membership and a valid bearer token to talk to anything, and the mesh can't reach customer-data planes anyway. Token rotation is a single admin call, so recovery is seconds.
No. A single Sentry appliance scans the network from the inside — host discovery, CVE checks, share enumeration, and service fingerprinting — with no per-endpoint agent to deploy or maintain.
Sentry polls the orchestrator roughly every 30 seconds and streams new, changed, and resolved findings into your portal as scans complete — de-duplicated by a stable key, each with severity, CVSS, and remediation.
Start with an external pentest for the audit, then drop a Sentry on the LAN for continuous internal visibility. Talk to an analyst about the right tier.