About SITEY: Autonomous Vulnerability Management, Built to Close the Loop

SITEY builds autonomous vulnerability management: scanners find, we close. See how our AI-driven loop works, what we promise, and what we refuse to claim.

SITEY exists because of a pattern we kept running into on the other side of the table.
For years we ran penetration tests and vulnerability assessments for organisations of every size,
and the finding was almost always the same: they were good at discovering vulnerabilities and bad
at closing them. Scanner output landed in spreadsheets, critical issues aged quietly in a backlog
nobody owned, and the next assessment rediscovered the same hosts. The problem was never detection.
It was everything after detection.

Who builds SITEY

SITEY is built by SITEY Bilisim, based at Giresun Teknopark in Bulancak, Turkiye.
The company was founded by Omer Yilmaz, an independent security researcher working
in the field since 2014, across penetration testing, vulnerability research and critical
infrastructure assessment.

That matters for one reason. The people who designed this remediation workflow spent a decade on
the delivery side of it. The eight phase pipeline is not a product diagram invented in a meeting.
It is the process we wished existed while writing reports we knew would not get acted on.

Published vulnerability research

Our founder’s research has produced vulnerabilities registered in international databases.
Two are public:

Identifier Affected software Class
CVE-2021-40960 Galera WebTemplate 1.0 Path Traversal (CWE-22)
CVE-2022-3792 Liman Terminal Operating System, below 5.0.13 SQL Injection (CWE-89)

The second is the one we are asked about most. Liman Terminal Operating System runs port and
terminal operations. The vulnerability was disclosed to the vendor, fixed in version 5.0.13, and the
case was reported in the Turkish national press, including Haberturk and Milliyet,
under headlines about a critical weakness in port operations being closed before it could be
exploited.

We mention this not as a trophy. When you are deciding whether to run a security platform inside
your own network, it is fair to ask who wrote it and whether they have done real work in this field.

Why we built a product instead of selling more assessments

Consulting scales badly and it stops at the report. We wanted the part that actually reduces risk,
the closing of findings, to keep running after the engagement ends. So we built the thing we kept
describing to clients: a platform that takes output from the scanners you already own, removes the
duplicates, decides what genuinely matters in your environment, writes the fix for the specific host
in front of it, applies that fix under an approval gate you control, then re-tests to prove the
finding is gone.

Read how that works in the platform overview, or browse the
individual modules.

How we build

  • Your data stays yours. SITEY runs on your server. Findings, assets and reports
    live in your database. We publish exactly which outbound connections exist and why on the
    security page, including which of them are optional.
  • Decisions are inspectable. When the AI suppresses a finding or writes a
    remediation plan, the reasoning is stored in full and can be reviewed and reversed. A suppression
    you cannot audit is just a deleted finding.
  • High impact actions stop for a human. Anything that restarts a service, changes
    a firewall rule or touches accounts waits at a gate that shows you the exact command before you
    approve it.
  • We say what is not built yet. Where a capability is partial, the module pages
    say so rather than implying more than the code does.

How we sell

Self service. You buy online, download the installer and deploy it yourself. There is no sales
call, no discovery workshop and no implementation consultant, because the product is meant to be
installable by the team that will run it. Pricing is public on the pricing
page
: 599 USD per month, or 5,999 USD once for a perpetual licence.

If something about your environment makes you unsure whether SITEY fits, write to us before you
buy rather than after. Contact details are here.

Company details

Company SITEY Bilisim
Address Giresun Teknopark, Bulancak, Giresun, Turkiye
Phone +90 530 857 81 39
General info@siteyvm.com
Sales sales@siteyvm.com
Data protection kvkk@siteyvm.com