Sherlock Guard ingests your logs, CSV/JSON, product SBOMs and CVE reports — or pulls straight from GitHub, GitLab, Gitea, AWS, Azure, GCP, Microsoft 365 and Have I Been Pwned — classifies findings, enriches them with CWE/CVE and threat-intel context, maps them to compliance frameworks, and produces audit-ready exports. Analyst review built in.
Collect, connect, classify, prioritize, automate and prove compliance — without stitching together a dozen tools.
The sgagent CLI inventories your machines — packages, applications, services, OS/EOL — and flags vulnerabilities with guided remediation. From the install command generated in the console to a live agent in under two minutes.
Pull findings straight from systems you own: GitHub, GitLab and Gitea repositories, plus AWS, Azure, GCP and Microsoft 365 cloud accounts.
Findings are classified by severity, tagged with CWE and enriched with CVE context — AI-assisted with a deterministic fallback — then reviewed, assigned and annotated by your analysts.
Threat feeds plus KEV and EPSS signals to prioritize what's actually exploited — with a grounded CTI Q&A assistant.
Auto-triage rules, playbooks and outbound actions: notify webhooks or open tickets in your own Jira / ServiceNow.
Map open findings to SOC 2, ISO 27001, PCI DSS, NIST CSF, CIS, NIS2, ACN (NIS2 Italy), DORA, TISAX, GDPR and CRA controls — with per-framework certification guides and an AI compliance advisor grounded on your real coverage.
Upload each product's CycloneDX SBOM: components are matched against CVE sources, re-uploads reconcile automatically, VEX records your triage decisions — and one search answers the Log4j question across every product.
A document library for policies, certificates and audit evidence; security questionnaires answered for you from your live coverage; a public, NDA-gated trust portal for your customers.
Produce CSV, JSON and PDF exports — with formula-injection-safe CSV — plus scheduled recurring reports, ready for audits.
An executive dashboard and threat overview for management, custom widgets, a risk register and an asset graph — the state of your security at a glance.
Sign in with your corporate identity provider: SSO via OIDC (Entra ID, Google) and SAML 2.0 (ADFS and legacy IdPs), with JIT provisioning and enforced SSO. 2FA and role-based access for everyone.
Contextual help on every page, an AI assistant grounded on curated product knowledge, and live chat with a human operator when you need one.
No six-month rollout. Create an org, deploy the agent to inventory your hosts — or upload logs and CSV from the console — and let the worker do the first pass.
Start a 30-day free trial — no card. Your tenant is provisioned with row-level isolation in Postgres.
Generate the install command in the console and paste it on each host — under two minutes to a live agent, defensive and on-box only, on Windows, Linux and macOS. Or connect GitHub, GitLab, Gitea, AWS, Azure, GCP, Microsoft 365 and HIBP, or upload logs, CSV and product SBOMs from the console.
The worker classifies findings; analysts review and triage; you export compliance-ready reports.
$ sgagent register --backend $API --token $TOKEN→ registered: device 9f3a… ok$ sgagent collect✓ 412 packages · 31 services · OS/EOL (1.2s)$ sgagent watch --interval 300→ collecting every 5m · on-box only$ sgagent recommendations --ndjson{"action":"upgrade","pkg":"openssl"} ×3
Every plan starts with a 30-day free trial — no card. Prices are per month, billed in EUR, VAT excluded.
For small teams getting started with real workloads.
The complete plan: more formats, watch mode, audit export.
High volume, every format, custom dashboards and MSP multi-tenant.