SITEY is one platform made of focused modules. Each one owns a stage of the vulnerability lifecycle, and they share a single record so nothing has to be reconciled between tools. Every module below runs in your own infrastructure.
Discovery and visibility
- Command Center / Dashboard: One screen that turns findings, assets, scans, tasks and patch jobs into a single risk picture. See where your security program stands in ten seconds.
- Asset & Inventory: Keep a current security asset inventory: installed software, services, listening ports, patch state and posture per host, with snapshot diffs that show what changed.
- Agent Management: Deploy, authenticate and track SITEY endpoint agents on Windows and Linux. Per-agent secrets, inventory snapshots, liveness states and fleet version control.
- Group & Domain Management: Organize agents into named groups and domains into scan target lists, then point scheduled scans, bulk scans and autonomy policies at those groups.
- Attack Surface Management (ASM): Sweep your own IP ranges with Nmap, separate agent-covered hosts from unmanaged ones, and layer your Active Directory graph on the same screen.
- Network Scanning & Reachability: Discover the hosts on your VLANs with nmap, then prove your scanner actually reached each target instead of silently skipping it. See how it works.
Scanning and collection
- Scan Management: Launch, schedule and track vulnerability scans from one console: group targets, OpenVAS preflight and depth profiles, deduplicated import from 16 scanner formats.
- Scanner Integrations: Connect Nessus, OpenVAS, Burp, Acunetix and 12 more scanners. Launch scans, import reports and normalize every finding into one deduplicated work queue.
- Manual Vulnerability Entry: Log pentest, code review and disclosure findings as first-class records in SITEY. Bulk CSV import, deduplication, revision history and full audit trail.
The AI layer
- AI Triage & Validation: Score, deduplicate and validate every scanner finding automatically. SITEY proves false positives on the host before an analyst opens a single ticket.
- AI Remediation Planning: SITEY turns a confirmed vulnerability into a host-specific, approval-gated fix plan: classification, live diagnostics, compiled scripts and safety gates.
- AI Command Center: Run, watch and govern every AI action in SITEY from one console: goal-driven orchestration, contextual risk scoring, playbooks, cost and activity logs.
- Security Assistant (Chat): Ask SITEY about your own vulnerability data in plain language. The Security Assistant reads live findings and only acts after you approve each action.
- AI Operations Log: Every AI-driven remediation the SITEY agent runs is recorded as a structured JSON Lines entry: command, outcome, captured output, duration and risk level.
- AI Daily Summary: Get one daily security picture: live critical and high counts, week-over-week trend, top open vulnerabilities, SLA warnings and an AI written report.
- AI Usage & Cost Analytics: Track every AI call SITEY makes: tokens, cost by model and endpoint, daily trends and OpenAI invoice reconciliation, all inside your own network.
- Learned Scripts: SITEY stores remediation scripts that pass its learning checks, scores them by success rate, and reuses proven code instead of regenerating every fix from scratch.
Action and closure
- Vulnerability Lifecycle: Track every finding from first detection to verified closure: deduplication, validated status changes, full audit history, and evidence-based retest closure.
- Patch Management: Turn approved fixes into tracked patch jobs: batch creation, admin approval, pre-flight checks, snapshots, leased delivery to agents, and a documented rollback path.
- Autonomous Operations: Set policies that decide how far SITEY may fix vulnerabilities on its own, then watch every autonomous action, gate and rollback in one console.
- Approval Gates: Decide where SITEY’s automation stops and a person takes over. Role-gated approval on remediation batches, risky AI actions and task chains, with an audit record per decision.
- Retest & Closure: Prove a vulnerability is actually fixed. SITEY re-runs the original scanner, matches the exact finding, and only then marks it resolved, keeping a dated record of every attempt.
Team and governance
- Task Management: Turn vulnerabilities into owned work items: multi-assignee tasks, a five-stage workflow, assignment history, smart assignment suggestions and bulk actions.
- Team Workflow & Assignment: Assign vulnerabilities by workload and role, track every handoff, and see team load in one board. Suggestions scored from real task data, applied by you.
- Process Management: See every vulnerability detection, assignment, start and completion on a monthly calendar, then open any day for a filtered, chronological timeline.
- Notifications: SITEY Notifications turns task, comment, critical-finding and SLA events into a per-user inbox with an unread badge and a daily email digest for administrators.
- User Management & RBAC: Scope every SITEY account by role, cut off sessions the moment you disable a user, and keep patch approval behind an administrator gate. Runs in your own deployment.
Reporting
- Reporting & Chart Builder: Build PDF, Excel and Word vulnerability reports from live data. Credentials inside HTTP evidence are masked before the file is written. Fully self-hosted.
- Compliance Mapping: Turn vulnerability findings into audit evidence: CVE/CWE/CVSS identifiers, an automatic change and approval trail, SLA timers, and exportable PDF, Excel and Word packs.
Not sure where to start? See how deployment works or view pricing.