Multi-tenant threat analysis · SaaS · 100% EU

From raw logs to
triaged findings.
In one console.

Sherlock Guard ingests your logs, CSV/JSON, product SBOMs and CVE reports — or pulls straight from GitHub, GitLab, Gitea, AWS, Azure, GCP, Microsoft 365 and Have I Been Pwned — classifies findings, enriches them with CWE/CVE and threat-intel context, maps them to compliance frameworks, and produces audit-ready exports. Analyst review built in.

30-day free trial No credit card required Self-serve sign-up
Console preview
Total findings
1,284
across uploads
Critical + High
37
needs attention
Open
52
awaiting triage
Avg confidence
0.82
classifier
Findings by severityillustrative
CVE-2024-1234RCE in API · classified criticalCWE-94
Built for teams in
ManufacturingHealthcarePublic sectorLegalLogisticsFinanceAutomotiveEnergy & utilitiesIT & MSPs
What Sherlock Guard does

Twelve capabilities,
one console.

Collect, connect, classify, prioritize, automate and prove compliance — without stitching together a dozen tools.

Collection

Endpoint agent

The sgagent CLI inventories your machines — packages, applications, services, OS/EOL — and flags vulnerabilities with guided remediation. From the install command generated in the console to a live agent in under two minutes.

  • Windows · Linux · macOS
  • 2-minute install, defensive & on-box only
  • CVE matching (OSV · NVD · MSRC)
  • Signed self-update + watch mode
Connectors

Data connectors

Pull findings straight from systems you own: GitHub, GitLab and Gitea repositories, plus AWS, Azure, GCP and Microsoft 365 cloud accounts.

  • GitHub, GitLab & Gitea (Dependabot, repos)
  • Cloud spend anomalies + Defender/SCC posture
  • M365 secure score, MFA gaps & risky users
  • HIBP breached-account monitoring
Classification

Classify, enrich & triage

Findings are classified by severity, tagged with CWE and enriched with CVE context — AI-assisted with a deterministic fallback — then reviewed, assigned and annotated by your analysts.

  • AI-assisted + deterministic fallback
  • CWE/CVE context
  • Analyst review workflow
  • Incidents & clustering
Intelligence

CTI & prioritization

Threat feeds plus KEV and EPSS signals to prioritize what's actually exploited — with a grounded CTI Q&A assistant.

  • Threat feeds (TAXII/MISP)
  • KEV + EPSS prioritization
  • CTI Q&A with sources
Automation

Triage & response

Auto-triage rules, playbooks and outbound actions: notify webhooks or open tickets in your own Jira / ServiceNow.

  • Auto-triage rules
  • Playbooks & webhooks
  • Jira / ServiceNow tickets
Compliance

Frameworks & evidence

Map open findings to SOC 2, ISO 27001, PCI DSS, NIST CSF, CIS, NIS2, ACN (NIS2 Italy), DORA, TISAX, GDPR and CRA controls — with per-framework certification guides and an AI compliance advisor grounded on your real coverage.

  • 11 frameworks + guides
  • AI compliance advisor
  • Evidence & continuous verification
CRA / SBOM

Product SBOMs

Upload each product's CycloneDX SBOM: components are matched against CVE sources, re-uploads reconcile automatically, VEX records your triage decisions — and one search answers the Log4j question across every product.

  • Per-product SBOM inventory + VEX
  • KEV triggers, Art. 14 readiness panel
  • “Are we affected?” component search
Trust

Documents & questionnaires

A document library for policies, certificates and audit evidence; security questionnaires answered for you from your live coverage; a public, NDA-gated trust portal for your customers.

  • Document library
  • Questionnaire auto-answer
  • Public trust portal (NDA-gated)
Reporting

Compliance exports

Produce CSV, JSON and PDF exports — with formula-injection-safe CSV — plus scheduled recurring reports, ready for audits.

  • CSV / JSON / PDF
  • Formula-safe CSV
  • Scheduled reports
Visibility

Dashboards & risk

An executive dashboard and threat overview for management, custom widgets, a risk register and an asset graph — the state of your security at a glance.

  • Executive & threat overview
  • Risk register
  • Asset graph + hunt
Identity

Enterprise access

Sign in with your corporate identity provider: SSO via OIDC (Entra ID, Google) and SAML 2.0 (ADFS and legacy IdPs), with JIT provisioning and enforced SSO. 2FA and role-based access for everyone.

  • SSO: OIDC + SAML 2.0
  • 2FA (TOTP) + recovery codes
  • JIT provisioning & roles
Support

Help that answers

Contextual help on every page, an AI assistant grounded on curated product knowledge, and live chat with a human operator when you need one.

  • Live chat: AI + operator
  • Contextual help everywhere
  • Guides & documentation
How it works

Sign up, collect,
review.

No six-month rollout. Create an org, deploy the agent to inventory your hosts — or upload logs and CSV from the console — and let the worker do the first pass.

01

Sign up & create your org

Start a 30-day free trial — no card. Your tenant is provisioned with row-level isolation in Postgres.

02

Deploy the agent or connect your sources

Generate the install command in the console and paste it on each host — under two minutes to a live agent, defensive and on-box only, on Windows, Linux and macOS. Or connect GitHub, GitLab, Gitea, AWS, Azure, GCP, Microsoft 365 and HIBP, or upload logs, CSV and product SBOMs from the console.

03

Classify, review, export

The worker classifies findings; analysts review and triage; you export compliance-ready reports.

sgagent · quickstart
$ sgagent register --backend $API --token $TOKEN→ registered: device 9f3a…          ok$ sgagent collect 412 packages · 31 services · OS/EOL (1.2s)$ sgagent watch --interval 300→ collecting every 5m · on-box only$ sgagent recommendations --ndjson{"action":"upgrade","pkg":"openssl"} ×3
100% EU
Software & data
made in Italy, EU-hosted
11
Compliance frameworks
from SOC 2 to the CRA
8
Data connectors
GitHub · GitLab · Gitea · AWS · Azure · GCP · M365 · HIBP
RLS
Tenant isolation
enforced in Postgres
Plans

Plans that grow with you.

Every plan starts with a 30-day free trial — no card. Prices are per month, billed in EUR, VAT excluded.

Plus
€69/ monthVAT excl.

For small teams getting started with real workloads.

  • 25 monitored assets (extra: €2.00/asset/mo)
  • 2 analysts + unlimited viewers
  • GitHub, GitLab, Gitea, AWS, Azure, GCP, M365 & HIBP connectors
  • Document library (20 docs)
  • CSV export
  • API access
  • 90-day retention
  • Email support (48h)
Start free trial
Most popular
Pro
€249/ monthVAT excl.

The complete plan: more formats, watch mode, audit export.

  • 150 monitored assets (extra: €1.80/asset/mo)
  • 8 analysts + unlimited viewers
  • GitHub, GitLab, Gitea, AWS, Azure, GCP, M365 & HIBP connectors
  • Document library (100 docs)
  • CSV + JSON export
  • Scheduled watch mode
  • Public trust portal (NDA-gated evidence)
  • Audit export
  • 1-year retention
  • Email support (24h)
Start free trial
Max
€599/ monthVAT excl.

High volume, every format, custom dashboards and MSP multi-tenant.

  • Everything in Pro, plus:
  • 500 monitored assets (extra: €1.60/asset/mo)
  • 25 analysts + unlimited viewers
  • Document library (500 docs)
  • All export formats (CSV/JSON/PDF)
  • Custom dashboard widgets
  • MSP multi-tenant
  • 2-year retention
  • Chat support
Start free trial
Just exploring? Start freeLarger or multi-tenant needs? Enterprise is custom-priced — contact us.
Ready to start?

Create your account and run your first classification in minutes.

Start free trial Already have an account? Sign in
30-day trial · no credit card required.