This vulnerability management FAQ covers what security teams actually ask before they buy: how the license works, what you have to run yourself, where your data sits, and how billing is handled. Answers are short and specific. If yours is not here, write to info@siteyvm.com or use the contact page.
Buying & Licensing
What is SITEY?
SITEY is an autonomous vulnerability management platform you run in your own infrastructure. It executes eight phases end to end: Discovery & Scanning, Collection & Dedup, AI Validation & Triage, Risk Scoring, Smart Assignment, AI Remediation Plan, Automated Patching, and Retest & Closure. Your defense is now autonomous: the loop runs without a human pushing each finding forward.
How is SITEY different from a plain vulnerability scanner?
A scanner produces findings. SITEY consumes findings, from its own scans and from 17 integrated scanners, then deduplicates them, validates them, scores real risk, assigns an owner, writes the fix, applies it and retests to confirm the finding is gone. The deliverable is a closed ticket with evidence, not a PDF for someone else to work through.
Do I have to replace the scanners I already own?
No. SITEY ingests results from Nessus, OpenVAS, Nmap, Nuclei, OWASP ZAP, Trivy, MobSF, Acunetix, SonarQube, Semgrep and others. Keep the licences you already pay for; SITEY handles deduplication and the closure loop on top of them.
Monthly or lifetime. Which should I buy?
Monthly is $599 per month, recurring, cancel anytime. Lifetime is $5,999 once: a perpetual licence including one year of updates and engine feed plus priority support. Lifetime equals ten months of the monthly plan, so if you expect to run SITEY longer than ten months it pays for itself. Both options are on pricing.
What happens if I cancel the monthly subscription?
Your licence stays valid to the end of the period you already paid for, then stops validating and the platform stops running new scans. There is no notice period and no cancellation fee. Your database stays on your server. We delete nothing, and resubscribing brings the same deployment back.
Can I move the licence to another server?
Yes. A licence is bound to one active deployment at a time, not permanently to one machine. Deactivate on the old host, then activate on the new one. If the old server is gone and you cannot deactivate it, mail info@siteyvm.com and we release the seat.
Is there a trial or a demo?
We run a demo environment you can walk through before buying. Request access from the contact page. There is no self-serve free trial, because the product deploys inside your network rather than ours. Tell us what you need to see and we will show that specific part.
Deployment & Requirements
How do I get SITEY installed?
You buy online with a card, create an account, download the installer and run it on a server you own. There is no sales call, no onboarding consultant and no professional services fee. The installation guide covers the whole path from a blank host to the first scan.
What does the server need to run?
The platform server runs on 64-bit Linux. For a mid-size estate, plan a dedicated host with at least 8 CPU cores, 16 GB RAM and 250 GB of disk. Scan history and evidence are what consume storage over time. Exact minimums and supported distributions are listed in the installation guide supplied with your licence.
How are agents deployed to my hosts?
You roll them out yourself with whatever you already use: GPO, SCCM, Intune, Ansible or a shell script. Each agent enrols against your own SITEY server with a token and reports over an outbound connection, so you do not need inbound firewall rules to every endpoint. We never touch your environment.
Can I scan hosts without installing an agent?
Yes. Agentless network scanning covers anything reachable from the server: network gear, appliances, hosts where you cannot install software. Agents add local detail such as installed package inventory and patch state, and they are what makes automated patching possible on that host.
How many hosts can I scan?
Pricing is per deployment, not per host, so the licence does not meter your asset count. The practical limit is the hardware you give the server and how often you scan. If you are sizing a large estate, send us the numbers via contact and we will tell you what to provision.
Does SITEY need internet access?
Two things do: licence activation and the engine feed, which delivers vulnerability intelligence and remediation content. Scanning, triage, patching, reporting and your database all run locally with no outbound dependency. Restricted and air-gapped networks are handled with an offline update bundle, confirm the details with us before you buy.
Security & Data
Where does my data live?
On your servers, under your control. The database, scan results, evidence, scan credentials and reports never leave your infrastructure. SITEY is not a SaaS console with your findings sitting in our cloud.
Do you see my findings?
No. The only traffic between your deployment and us is licence activation and the engine feed download. Neither carries your hostnames, asset inventory, findings or scan output.
What exactly does licence activation send?
A licence key and a deployment identifier, so one licence cannot be run on many installations at once. It carries no asset data, no findings and no user data. Activation is a periodic check, not a live tunnel into your network.
Does the AI send my data to an external model provider?
That is your decision, not ours. The AI layer runs against a model endpoint configured in your own deployment, so you choose between a provider API and a model you host yourself. If your policy forbids sending data outside the network, configure a local endpoint and nothing leaves.
Who can see what inside the platform?
Access is role-based and every action is written to an audit trail, including actions the automation takes on its own. Scan credentials are stored encrypted and used only by the scan engine. You administer all of it. We hold no account on your deployment.
Does buying SITEY make us ISO 27001 or PCI DSS compliant?
No, and treat any vendor who claims otherwise with suspicion. SITEY maps findings and controls to ISO 27001, PCI DSS, SOC 2, GDPR, KVKK and BDDK, and produces the evidence auditors ask for on vulnerability management. We are not a certification body and we do not claim to be certified on your behalf.
Product & Features
What are the eight phases?
Discovery & Scanning, Collection & Dedup, AI Validation & Triage, Risk Scoring, Smart Assignment, AI Remediation Plan, Automated Patching, and Retest & Closure. Each phase hands off to the next automatically. You place the approval gates; everything between two gates runs unattended.
What is the AI actually doing?
Three concrete jobs. It validates findings and removes false positives before they reach a human queue. It scores risk using asset context instead of raw CVSS. And it writes the remediation plan, the specific patch, command or config change for that host, then reads the retest result to decide whether the finding is genuinely closed.
Does it patch automatically without asking?
Only if you configure it that way. Automated patching sits behind approval gates you define per asset group, severity and change window. Every action, whether a person approved it or a policy did, is logged with the evidence that triggered it.
Which scanners are supported?
17 scanners are integrated, including Nessus, OpenVAS, Nmap, Nuclei, OWASP ZAP, Trivy, MobSF, Acunetix, SonarQube and Semgrep. Their output lands in one deduplicated backlog rather than four separate consoles. The full list is on features.
What does “close critical vulnerabilities in 72 hours” mean?
It is the target the workflow is engineered around: from detection to verified closure of a critical finding within 72 hours, with the phases running unattended between your gates. Whether you hit it depends on your change windows and how much you choose to automate. The platform measures the time in each phase, so you can see exactly where it goes.
What are the 23 modules?
Patch Management, Team & Tasks, Attack Surface, Assets & Agents, Compliance and AI Reporting, plus seventeen more, all in one console. They share a single asset inventory, so a host in Attack Surface is the same record as in Patch Management, no reconciliation between tools. The breakdown is on features.
Billing & Refunds
How do I pay?
By credit card at checkout, processed by Stripe, in USD. Monthly plans bill on a recurring cycle until you cancel from your account. Lifetime is a single charge with nothing to renew.
Is my card data safe?
We never see it. Card details go directly to Stripe, a PCI DSS Level 1 certified provider, and our systems store only a customer reference and the subscription status. There is no card number in our database to leak.
How do refunds work?
Ask within 14 days of purchase and we refund it, no forms and no retention call. After that window, monthly plans can be cancelled at any time and you keep access until the end of the period you paid for. Refunds are returned to the original card through Stripe.
Can I get a company invoice?
Yes. Enter your company name, address and tax or VAT number at checkout and the invoice is issued with those details. You can download it from your account whenever you need it. If procurement needs a different format, mail info@siteyvm.com.
What happens after the first year on a lifetime licence?
The licence is perpetual, so the software keeps running whatever you decide. Updates and the engine feed are included for the first year; after that you can renew the feed to keep receiving new detections and remediation content. Nothing switches off if you choose not to renew.
How do I get support?
Mail info@siteyvm.com or open a ticket from your account. Lifetime licences include priority support. We support the product, not your environment. We never remote in, so include your version number and the relevant logs.
Still have a question?
Send it to info@siteyvm.com or use the contact page. If it is a pre-sales question about sizing, deployment or licensing, say so and you will get a technical answer, not a call request.