Autonomous · AI‑driven · Self‑hosted

Self-hosted vulnerability management platform that closes what it finds.

SITEY imports findings from the scanners you already run. Its autonomous remediation engine validates each one with AI, writes the fix for that host, applies it under your approval and checks the host again to confirm it is closed. Installed on your own servers.

4autonomy levels you control
16scanner integrations
28platform modules
8automated phases
Autonomous Remediation Engine

Remediation that runs itself, inside the limits you set.

SITEY's engine takes a finding from diagnosis to verified closure. It investigates the host through its agent, writes a fix for that host, waits at your approval gate, applies the change and checks the host again before it closes the finding. You decide how far it may go, and on which machines.

Level 1

Off

The engine leaves the finding to your team. Nothing runs automatically.

Level 2

Diagnose only

Runs read-only checks on the host and keeps their output in the machine's script history. Never changes a host.

Level 3

Until Gate 1

Diagnoses, builds the remediation plan for that host, then stops and waits for a person to approve.

Default for critical and high
Level 4

Full auto

Applies the fix and runs the follow-up check without waiting, but only on your canary or rollout-wave hosts. Every other host waits for approval.

Policies, not scripts

Scope autonomy by agent group and severity. Policies created in the dashboard start at Gate 1 for critical and high findings and ask for a snapshot before each fix.

A classifier caps every policy

Exempt agents drop to off, hosts marked critical never change without a person's approval, and database and web findings wait at Gate 1 by default.

Automatic changes stay small

Before the engine approves a fix on its own, it checks the kill switch, the change pause, a per-host backlog breaker, a cap of 5 active automatic changes per policy and your canary list.

A follow-up check decides the ending

After a fix the engine looks again, through fresh inventory, a scanner re-test or a screened check script. If the issue is still open, the finding goes to your team with the reason recorded.

Bounded self-heal

When a fix script fails, the engine analyses the error and writes a revised script, up to two retries by default. Under Gate 1 policies each retry waits for approval too.

Stop it with one switch

The kill switch halts new engine work. A pause on changes only, fleet-wide or per agent group, blocks automatic changes while diagnosis keeps running.

Inside the Engine

The brains behind the engine, and how they check each other.

This is the network from SITEY’s own autonomy dashboard, where it replays the engine’s recent activity. The default engine runs from day one: the Orchestrator drives each finding, the workers diagnose, write and deliver the fix, and the Learning Curator keeps what worked. An optional agentic mode adds a control plane that holds the AI to fixed rules. Your team sets every policy.

Engine communication networkIllustrative run
AGENTIC MODE CONTROL PLANEYour teamOrchestratorSequencerScript ControllerJob ProgressAwait AnalyzerSemanticsLearning CuratorFP AnalysisScript EngineAgentPatch
Message feed
  1. Your teamOrchestratorPolicy: until Gate 1
  2. OrchestratorScript EngineWrite a check for this host
  3. Script EnginePatchTyped check compiled
  4. PatchAgentRead-only job handed over
  5. AgentOrchestratorIssue confirmed on host
  6. OrchestratorYour teamFix waiting at Gate 1
  7. Your teamOrchestratorFix approved
  8. PatchAgentSnapshot, then the fix
  9. AgentOrchestratorFollow-up check: closed
  10. AgentLearning CuratorScript saved for reuse

In the product this panel is drawn from your engine’s recent activity log. When there is no activity yet, it shows representative traffic like this.

YouYour team stays in charge

Every policy and every Gate 1 decision belongs to an admin.

Your team

Admins write the autonomy policies, approve or reject each fix waiting at Gate 1 after seeing the host and a preview of what will run, exempt machines, and can halt new engine work with one switch. Each of these actions is logged under the admin’s account.

Default engineOn from day one

These parts run whenever a policy covers a finding.

Orchestrator

Picks up the open findings your policies cover, ranks them by CVSS score and moves each through diagnosis, fix, Gate 1, verification and close. An agent result or an approval wakes it early.

Script Engine

Asks your AI endpoint for a typed plan built from the host’s OS and latest inventory, then compiles it into PowerShell or bash with fixed code. A host with an unknown OS gets a safe inconclusive check, not a guess.

FP Analysis

Checks a suspected false positive on the host itself. At default settings an AI verdict does not close the finding: it stays open and the result is logged for an analyst.

Patch

Carries each fix to its host as a tracked job. Agents are handed only approved jobs, a job with a maintenance window waits for it, and temporary failures retry with backoff, up to 5 attempts.

Agent

Runs approved jobs on your Windows or Linux host under its own secret, re-checks each script against its own blocklist first, and journals results so a restart or network drop does not lose them.

Learning Curator

Saves scripts that ran successfully and reuses one only for a closely matching finding on the same OS family, after a fresh safety check. It does not learn from failed jobs or timeouts.

Agentic modeOptional control plane

Off until an admin switches it on. Its change tools run only under full auto, and these controllers hold the AI to fixed rules.

Execution Sequencer

Refuses a change job until the finding has a snapshot or a recorded waiver, and while the finding’s previous change has no recorded outcome.

Script Controller

Checks fix scripts before their job exists. Known destructive patterns, such as disk formatting, disabling Defender or clearing event logs, are stopped and sent back to the AI.

Job Progress Controller

Gives an agent job more time while the agent keeps sending heartbeats, up to a 30 minute cap (60 for KB and package jobs), and nudges jobs no agent has picked up.

Await Analyzer

When a job overruns, it names the reason, such as not picked up, agent not checking in, stalled or no result, and saves it on the job before the job is extended, requeued or failed.

Execution Semantics

Reads each fix job’s outcome. If a fix timed out or stalled, it blocks further changes for that finding for the rest of the run, while read-only checks continue.

The Pipeline

A loop that closes itself

Every finding is scanned, verified, scored, assigned, fixed and re-tested, without manual hand-offs.

AUTONOMOUSLOOPno manual hand-offs01Discover02Dedup03Validate04Score05Assign06Plan07Patch08Retest
PHASE 01

Discovery & Scanning

Continuous asset discovery and multi-scanner detection.

PHASE 02

Collection & Dedup

Repeat reports of the same finding from a scanner update its existing record.

PHASE 03

AI Validation

False positives flagged with written evidence for an analyst to confirm.

PHASE 04

Risk Scoring

Re-scored against your environment, not just CVSS.

PHASE 05

Smart Assignment

Routed to the right owner with an SLA clock.

PHASE 06

AI Remediation

Exact commands for that host, not generic advice.

PHASE 07

Automated Patching

Applied under approval gates you control.

PHASE 08

Retest & Closure

Engine fixes close only after a follow-up check confirms them.

A Thinking Defense Core

AI triage you can audit.

Every verdict comes with the evidence behind it. When SITEY flags a finding as a likely false positive, you can see why, and an analyst makes the call. A verdict you cannot audit is just a deleted finding.

  • False-positive flags with evidence you can review
  • Remediation written for the specific host, not generic advice
  • Executive and technical reports, generated from your own data
  • Human approval before every high-impact change
Operations Center

Watch the whole estate in one place

Open findings, risk trend, riskiest assets and every automated action, live.

Product interface · sample data
Integrations

Keep the scanners you already own

SITEY brings their output into one prioritized worklist, then its autonomous engine carries each finding through to a verified fix.

NessusNetwork
TenableNetwork
QualysNetwork
OpenVASNetwork
NexposeNetwork
NmapDiscovery
NucleiTemplates
Burp SuiteWeb
OWASP ZAPWeb
AcunetixWeb
AppScanWeb
ArachniWeb
NetsparkerWeb
IntruderExternal
FortifyCode
MobSFMobile

16 scanner integrationsImport results from every oneLaunch scans directly for Nessus and OpenVAS

When you buy SITEY

What you gain, and how you stay protected.

Every line below describes what the shipped software does today, checked against its code. No roadmap promises.

What you gain

What your team gets once SITEY is running.

  • One findings list for 16 scanners

    Import results from Nessus, Qualys, OpenVAS, Burp Suite, Nuclei and 11 more into one list sorted by severity. SITEY also starts Nessus and OpenVAS scans on your own scanner servers.

  • Fixes written for each host

    For Windows and Linux hosts running the SITEY agent, the engine prepares the fix from that host's OS, installed software and diagnosis. The agent runs it after the approvals your policy requires.

  • Closure you can check

    An engine fix closes the finding only after a follow-up check confirms it: fresh host inventory, a scanner re-test or a screened check script. The closing note records who approved, the method and the result.

  • Evidence before any false-positive call

    Suspected false positives are checked on the host, and at default settings a person makes the final call.

  • Fewer AI calls over time

    Scripts that ran successfully are saved and reused on closely matching findings on the same OS family, instead of paying for a new AI call.

  • One screen for the whole engine

    The autonomy dashboard shows active and closed workflows, approvals waiting, verified closures, success rate and a filterable activity log, plus the network view of the engine's parts.

  • Reports and approved patch jobs

    Export findings as PDF, Excel or Word. Fix jobs you send to hosts wait for admin approval and for the maintenance window you set.

  • A license without meters

    The license sets an expiry date, an IP limit and an agent limit. It does not count scans and does not switch modules on or off.

How you stay protected

Built in and on by default, with switches you control.

  • Your approval comes first

    Dashboard policies start at Gate 1 for critical and high findings: the engine diagnoses, prepares a fix and waits for an admin to approve it. With no matching policy it starts no work.

  • Destructive commands are refused

    Diagnostic scripts must pass a read-only check before they are sent, and the agent refuses scripts that match its blocklist, such as disk formatting or download-and-run code.

  • Automatic changes stay small

    Before the engine approves a fix on its own, it checks the kill switch, the change pause, a per-host backlog breaker and a cap of 5 active automatic changes per policy. In full auto, only your canary or rollout-wave hosts change without approval.

  • One switch halts new work

    The kill switch halts new engine work. A change pause, fleet-wide or per agent group, blocks automatic changes while diagnosis continues.

  • Nothing is left hanging

    Checks time out after 15 minutes and fixes after 30 by default, with the reason recorded. Work for an offline host waits for its next check-in, and a fix that times out goes to your team.

  • A person takes over, with the reason

    When the engine hands a finding back, it cancels its pending fix, keeps the finding open, records what it saw and why, and does not restart work on it by itself.

  • Agents and accounts locked down

    Each agent authenticates with its own secret, stored as a salted hash, and sees only its own jobs. Stored AI keys and mail passwords are encrypted, and five failed sign-ins in 15 minutes block further tries from that address.

  • Your servers, a short outbound list

    SITEY and its PostgreSQL database run on your Linux servers. It calls siteyvm.com for license checks and your AI endpoint, which receives finding and host details to analyze. If siteyvm.com is unreachable, SITEY keeps working for up to 14 days after its last successful check.

In every licenseAll 28 modulesUnlimited scansWindows and Linux agents4 autonomy levelsOptional agentic modeAutonomy dashboardEmail support
Pricing

Flat price. No per-asset fees.

Buy online, deploy yourself, roll out your own agents. No sales calls required.

Monthly

$599/mo

Full platform, billed monthly. Cancel anytime.

  • All 28 modules & 8-phase automation
  • AI validation & remediation (bring your own AI key)
  • Unlimited scans, no per-asset fees
  • Self-service deployment, your infrastructure
  • Email support
  • Cancel anytime
Start Monthly

All prices in USD. Secure checkout by Stripe.

Compliance

Evidence for the vulnerability controls you answer to

Scan history, remediation records and retest results support the vulnerability management requirements in these frameworks.

FAQ

Frequently asked questions

Do I install SITEY myself?

Yes. You buy online, download the installer and deploy it on your own server. You roll out agents to your hosts yourself. There is no onboarding consultant.

Where does my data live?

In your own database, on your own server. Two connections go to us: license activation and the engine feed, and neither carries your scan data. If you enable the AI features, finding text is sent to the AI provider you configure with your own key; you can point it at a model you host yourself or leave it off. The security page lists every outbound connection.

Monthly or Lifetime: what is the difference?

Monthly is $599 recurring, cancel anytime. Lifetime is $5,999 once for a perpetual license, including one year of updates and engine feed.

Can I try it first?

Explore the live demo, or start monthly and cancel if it is not a fit.

Which scanners are supported?

SITEY imports results from 16 scanners: Nessus, Tenable, Qualys, OpenVAS, Nexpose, Nmap, Nuclei, Burp Suite, OWASP ZAP, Acunetix, AppScan, Arachni, Netsparker, Intruder, Fortify and MobSF. It launches Nessus and OpenVAS scans directly.

Read all FAQs

Get started

Let the engine close what your scanners find.

Start at Gate 1: the engine plans every fix and waits for your approval. Deploy SITEY on your own servers today.