Self-hosted vulnerability management platform that closes what it finds.
SITEY imports findings from the scanners you already run. Its autonomous remediation engine validates each one with AI, writes the fix for that host, applies it under your approval and checks the host again to confirm it is closed. Installed on your own servers.
Remediation that runs itself, inside the limits you set.
SITEY's engine takes a finding from diagnosis to verified closure. It investigates the host through its agent, writes a fix for that host, waits at your approval gate, applies the change and checks the host again before it closes the finding. You decide how far it may go, and on which machines.
Off
The engine leaves the finding to your team. Nothing runs automatically.
Diagnose only
Runs read-only checks on the host and keeps their output in the machine's script history. Never changes a host.
Until Gate 1
Diagnoses, builds the remediation plan for that host, then stops and waits for a person to approve.
Default for critical and highFull auto
Applies the fix and runs the follow-up check without waiting, but only on your canary or rollout-wave hosts. Every other host waits for approval.
Policies, not scripts
Scope autonomy by agent group and severity. Policies created in the dashboard start at Gate 1 for critical and high findings and ask for a snapshot before each fix.
A classifier caps every policy
Exempt agents drop to off, hosts marked critical never change without a person's approval, and database and web findings wait at Gate 1 by default.
Automatic changes stay small
Before the engine approves a fix on its own, it checks the kill switch, the change pause, a per-host backlog breaker, a cap of 5 active automatic changes per policy and your canary list.
A follow-up check decides the ending
After a fix the engine looks again, through fresh inventory, a scanner re-test or a screened check script. If the issue is still open, the finding goes to your team with the reason recorded.
Bounded self-heal
When a fix script fails, the engine analyses the error and writes a revised script, up to two retries by default. Under Gate 1 policies each retry waits for approval too.
Stop it with one switch
The kill switch halts new engine work. A pause on changes only, fleet-wide or per agent group, blocks automatic changes while diagnosis keeps running.
The brains behind the engine, and how they check each other.
This is the network from SITEY’s own autonomy dashboard, where it replays the engine’s recent activity. The default engine runs from day one: the Orchestrator drives each finding, the workers diagnose, write and deliver the fix, and the Learning Curator keeps what worked. An optional agentic mode adds a control plane that holds the AI to fixed rules. Your team sets every policy.
- Your teamOrchestratorPolicy: until Gate 1
- OrchestratorScript EngineWrite a check for this host
- Script EnginePatchTyped check compiled
- PatchAgentRead-only job handed over
- AgentOrchestratorIssue confirmed on host
- OrchestratorYour teamFix waiting at Gate 1
- Your teamOrchestratorFix approved
- PatchAgentSnapshot, then the fix
- AgentOrchestratorFollow-up check: closed
- AgentLearning CuratorScript saved for reuse
In the product this panel is drawn from your engine’s recent activity log. When there is no activity yet, it shows representative traffic like this.
Every policy and every Gate 1 decision belongs to an admin.
Your team
Admins write the autonomy policies, approve or reject each fix waiting at Gate 1 after seeing the host and a preview of what will run, exempt machines, and can halt new engine work with one switch. Each of these actions is logged under the admin’s account.
These parts run whenever a policy covers a finding.
Orchestrator
Picks up the open findings your policies cover, ranks them by CVSS score and moves each through diagnosis, fix, Gate 1, verification and close. An agent result or an approval wakes it early.
Script Engine
Asks your AI endpoint for a typed plan built from the host’s OS and latest inventory, then compiles it into PowerShell or bash with fixed code. A host with an unknown OS gets a safe inconclusive check, not a guess.
FP Analysis
Checks a suspected false positive on the host itself. At default settings an AI verdict does not close the finding: it stays open and the result is logged for an analyst.
Patch
Carries each fix to its host as a tracked job. Agents are handed only approved jobs, a job with a maintenance window waits for it, and temporary failures retry with backoff, up to 5 attempts.
Agent
Runs approved jobs on your Windows or Linux host under its own secret, re-checks each script against its own blocklist first, and journals results so a restart or network drop does not lose them.
Learning Curator
Saves scripts that ran successfully and reuses one only for a closely matching finding on the same OS family, after a fresh safety check. It does not learn from failed jobs or timeouts.
Off until an admin switches it on. Its change tools run only under full auto, and these controllers hold the AI to fixed rules.
Execution Sequencer
Refuses a change job until the finding has a snapshot or a recorded waiver, and while the finding’s previous change has no recorded outcome.
Script Controller
Checks fix scripts before their job exists. Known destructive patterns, such as disk formatting, disabling Defender or clearing event logs, are stopped and sent back to the AI.
Job Progress Controller
Gives an agent job more time while the agent keeps sending heartbeats, up to a 30 minute cap (60 for KB and package jobs), and nudges jobs no agent has picked up.
Await Analyzer
When a job overruns, it names the reason, such as not picked up, agent not checking in, stalled or no result, and saves it on the job before the job is extended, requeued or failed.
Execution Semantics
Reads each fix job’s outcome. If a fix timed out or stalled, it blocks further changes for that finding for the rest of the run, while read-only checks continue.
A loop that closes itself
Every finding is scanned, verified, scored, assigned, fixed and re-tested, without manual hand-offs.
Discovery & Scanning
Continuous asset discovery and multi-scanner detection.
Collection & Dedup
Repeat reports of the same finding from a scanner update its existing record.
AI Validation
False positives flagged with written evidence for an analyst to confirm.
Risk Scoring
Re-scored against your environment, not just CVSS.
Smart Assignment
Routed to the right owner with an SLA clock.
AI Remediation
Exact commands for that host, not generic advice.
Automated Patching
Applied under approval gates you control.
Retest & Closure
Engine fixes close only after a follow-up check confirms them.
AI triage you can audit.
Every verdict comes with the evidence behind it. When SITEY flags a finding as a likely false positive, you can see why, and an analyst makes the call. A verdict you cannot audit is just a deleted finding.
- False-positive flags with evidence you can review
- Remediation written for the specific host, not generic advice
- Executive and technical reports, generated from your own data
- Human approval before every high-impact change
Watch the whole estate in one place
Open findings, risk trend, riskiest assets and every automated action, live.
One platform. 28 modules.
Everything a security team needs to run vulnerability management end to end, on your own servers.
Patch Management
Orchestrate and verify patches across your fleet.
AI Remediation
A fix plan written for each host, with the exact commands.
Approval Gates
High-impact fixes wait for a person to approve them before anything runs.
Attack Surface
Map internal exposure and the hosts no one has scanned.
Retest & Closure
Engine fixes close only after a follow-up check confirms them.
Reporting
Board-ready and technical reports from your own data.
Keep the scanners you already own
SITEY brings their output into one prioritized worklist, then its autonomous engine carries each finding through to a verified fix.
16 scanner integrationsImport results from every oneLaunch scans directly for Nessus and OpenVAS
What you gain, and how you stay protected.
Every line below describes what the shipped software does today, checked against its code. No roadmap promises.
What you gain
What your team gets once SITEY is running.
One findings list for 16 scanners
Import results from Nessus, Qualys, OpenVAS, Burp Suite, Nuclei and 11 more into one list sorted by severity. SITEY also starts Nessus and OpenVAS scans on your own scanner servers.
Fixes written for each host
For Windows and Linux hosts running the SITEY agent, the engine prepares the fix from that host's OS, installed software and diagnosis. The agent runs it after the approvals your policy requires.
Closure you can check
An engine fix closes the finding only after a follow-up check confirms it: fresh host inventory, a scanner re-test or a screened check script. The closing note records who approved, the method and the result.
Evidence before any false-positive call
Suspected false positives are checked on the host, and at default settings a person makes the final call.
Fewer AI calls over time
Scripts that ran successfully are saved and reused on closely matching findings on the same OS family, instead of paying for a new AI call.
One screen for the whole engine
The autonomy dashboard shows active and closed workflows, approvals waiting, verified closures, success rate and a filterable activity log, plus the network view of the engine's parts.
Reports and approved patch jobs
Export findings as PDF, Excel or Word. Fix jobs you send to hosts wait for admin approval and for the maintenance window you set.
A license without meters
The license sets an expiry date, an IP limit and an agent limit. It does not count scans and does not switch modules on or off.
How you stay protected
Built in and on by default, with switches you control.
Your approval comes first
Dashboard policies start at Gate 1 for critical and high findings: the engine diagnoses, prepares a fix and waits for an admin to approve it. With no matching policy it starts no work.
Destructive commands are refused
Diagnostic scripts must pass a read-only check before they are sent, and the agent refuses scripts that match its blocklist, such as disk formatting or download-and-run code.
Automatic changes stay small
Before the engine approves a fix on its own, it checks the kill switch, the change pause, a per-host backlog breaker and a cap of 5 active automatic changes per policy. In full auto, only your canary or rollout-wave hosts change without approval.
One switch halts new work
The kill switch halts new engine work. A change pause, fleet-wide or per agent group, blocks automatic changes while diagnosis continues.
Nothing is left hanging
Checks time out after 15 minutes and fixes after 30 by default, with the reason recorded. Work for an offline host waits for its next check-in, and a fix that times out goes to your team.
A person takes over, with the reason
When the engine hands a finding back, it cancels its pending fix, keeps the finding open, records what it saw and why, and does not restart work on it by itself.
Agents and accounts locked down
Each agent authenticates with its own secret, stored as a salted hash, and sees only its own jobs. Stored AI keys and mail passwords are encrypted, and five failed sign-ins in 15 minutes block further tries from that address.
Your servers, a short outbound list
SITEY and its PostgreSQL database run on your Linux servers. It calls siteyvm.com for license checks and your AI endpoint, which receives finding and host details to analyze. If siteyvm.com is unreachable, SITEY keeps working for up to 14 days after its last successful check.
Flat price. No per-asset fees.
Buy online, deploy yourself, roll out your own agents. No sales calls required.
Monthly
Full platform, billed monthly. Cancel anytime.
- All 28 modules & 8-phase automation
- AI validation & remediation (bring your own AI key)
- Unlimited scans, no per-asset fees
- Self-service deployment, your infrastructure
- Email support
- Cancel anytime
Lifetime
Own it forever. One payment, perpetual license.
- Everything in Monthly
- Perpetual license, no recurring fees
- 1 year of updates & engine feed included
- Priority support
- Pays for itself in 10 months
All prices in USD. Secure checkout by Stripe.
Frequently asked questions
Do I install SITEY myself?
Yes. You buy online, download the installer and deploy it on your own server. You roll out agents to your hosts yourself. There is no onboarding consultant.
Where does my data live?
In your own database, on your own server. Two connections go to us: license activation and the engine feed, and neither carries your scan data. If you enable the AI features, finding text is sent to the AI provider you configure with your own key; you can point it at a model you host yourself or leave it off. The security page lists every outbound connection.
Monthly or Lifetime: what is the difference?
Monthly is $599 recurring, cancel anytime. Lifetime is $5,999 once for a perpetual license, including one year of updates and engine feed.
Can I try it first?
Explore the live demo, or start monthly and cancel if it is not a fit.
Which scanners are supported?
SITEY imports results from 16 scanners: Nessus, Tenable, Qualys, OpenVAS, Nexpose, Nmap, Nuclei, Burp Suite, OWASP ZAP, Acunetix, AppScan, Arachni, Netsparker, Intruder, Fortify and MobSF. It launches Nessus and OpenVAS scans directly.
Let the engine close what your scanners find.
Start at Gate 1: the engine plans every fix and waits for your approval. Deploy SITEY on your own servers today.