Skip to main content

About Cyentrix Scan

A serious vulnerability scanner that never leaves your network.

Cyentrix Scan is a professional vulnerability scanner you run on your own hardware — discovery, CVE / KEV / EPSS scoring, credentialed checks, TLS and compliance. The cloud console only queues work and shows results. Your targets, credentials and evidence stay on-premise, by design.

Who's behind Cyentrix

Built by practitioners. Designed for the real world.

Cyentrix is built by cybersecurity practitioners with over 20 years of real-world experience helping organisations identify, assess, and reduce cyber risk.

Every capability in the platform is shaped by hands-on experience—not assumptions. From vulnerability management and security assessments to risk prioritisation and remediation, Cyentrix is designed around the challenges security teams face every day.

We believe security tools should help you solve problems, not create more of them. That's why Cyentrix focuses on clear evidence, actionable insights, and practical remediation rather than overwhelming dashboards or unnecessary complexity.

Our philosophy is simple: build security products that we would want to use ourselves—fast, accurate, practical, and focused on helping organisations improve their security posture with confidence.

CISACISSPCEH20+ YRS · IT AUDIT & CYBER SECURITY

What it is

Enterprise-grade scanning, without shipping your network to a SaaS.

01Principle

Runs on your hardware.

A single static binary on a box inside your network — Windows or Linux, no dependencies. All scanning, credentials and raw evidence stay on-premise. The node dials out over HTTPS; no inbound ports, no VPN, no data leaving your walls.

Deployone binary
Connectionoutbound-only HTTPS
02Depth

Real coverage, not a port list.

Nmap discovery and version detection, matched to CVE, enriched with CISA KEV and EPSS, and probed with Nuclei plus TLS and misconfiguration checks. Add SSH / WinRM credentials for authenticated results and run compliance benchmarks alongside.

EngineNmap · Nuclei
ScoringCVE · KEV · EPSS
03Boundary

The console can't scan.

Create scans, watch progress and read findings from the cloud console on any device. It queues jobs your node executes and can never run a tool itself — that boundary is enforced in the software, not just hidden in the UI. Control plane in the cloud; execution strictly on your node.

Console doesqueue · monitor · report
Console neverruns a scan
04Approach

Independent & honest.

Built and run by a practitioner for teams, MSSPs and consultants who can't send client networks to a cloud scanner — regulated, air-gapped or field engagements. Pay-as-you-go by IP, no seat licences, no upsell to consulting.

Billingper IP · pay as you go
Datastays on-premise

Set up in minutes · your data never leaves

See what's exposed. Then fix it.

Create an account, drop the node inside your network, and queue your first scan from the console tonight.

Open the console →