Mid-Market Vulnerability Management Platform for Lean Security Teams

For mid-size companies with a lean security team and an existing scanner: flat-priced, self-hosted vulnerability management that turns findings into fixes.

SITEY is a mid-market vulnerability management platform for companies that already run a scanner but lack the people to work through what it finds: a security team of one to five people looking after hundreds of hosts or more. SITEY collects findings from your scanners, triages them with AI, writes a fix script for the specific host, holds it at an approval gate, has an agent apply it, and closes the finding only after a retest. You buy it online at a flat price and run it on your own Linux server.

16scanner integrations
8pipeline phases
4autonomy levels
$599flat monthly price, no per-asset fee

Who SITEY is for, and who it is not for

Vulnerability management for mid-size companies has a particular shape: an estate too big to patch from memory, a budget that covers a scanner but not a bigger team, and the same few people handling scanning, triage, change requests and audits.

A lean security team

One to five people who own vulnerability management alongside other work.

A scanner you already run

Nessus, Qualys, OpenVAS, Nexpose, Burp Suite or another supported tool. SITEY works on top of your scanner; it does not replace it.

Hundreds of hosts or more

Enough Windows and Linux machines that writing fixes by hand is the bottleneck, within the IP quota of one license.

Someone who can run a Linux server

SITEY is self-hosted. At least one person installs it, keeps it updated and backs up its database.

It is the wrong purchase if you have fewer than about 100 assets (a per-device product will very likely cost less), if you do not run a scanner yet (SITEY is not a scanner), or if nobody on the team can operate a Linux server and PostgreSQL.

Where a small IT team’s hours actually go

Lean teams are rarely short of findings; they are short of the hours between a finding and a verified fix. The same issue arrives from two scanners under two names, proving a “critical” is noise means logging into the host, approval happens in a chat thread, and nobody rescans to prove the fix held.

For a team of two, the scan is the cheap part. Everything after the scan is where the week goes.

How SITEY reduces the workload for a lean security team

Each finding moves through eight phases: discovery and scanning, collection and deduplication, AI validation, risk scoring, assignment, AI remediation planning, approval-gated patching, and retest and closure.

  1. One queue from every scanner

    SITEY imports results from 16 scanners and testing tools and launches scans directly in Nessus and OpenVAS. Findings share one schema and severity scale, and a re-reported finding raises its detection count instead of opening a new row.

  2. AI triage ranks and filters

    AI triage gives each finding a false-positive probability and a priority score using CVSS, EPSS and the CISA KEV catalog, and groups likely duplicates from different sources. The reasoning is stored, so an analyst can read it and reverse the verdict.

  3. A suggested owner, confirmed by a person

    SITEY suggests who should take each task based on workload and role. Nothing is assigned until someone confirms it.

  4. A fix script written for that host

    AI remediation planning writes a bash or PowerShell script for the specific machine, with a risk warning and a verification command. When only the vendor can fix a finding, SITEY records a vendor contact instead of guessing.

  5. A person approves high-impact changes

    Approval gates, with four autonomy levels and 18 risk-classified AI actions, put high-impact changes in front of a person who reads the script and target host first. At the default level, until Gate 1, the pipeline stops for approval before any fix runs.

  6. The agent applies it, and a retest decides

    Agents on Windows and Linux endpoints run the approved script and report the result and inventory. The finding moves to awaiting retest, not resolved, and retest and closure re-runs the original scanner where it has a retest path: Nessus, Acunetix and Burp Suite retests check that specific finding, while an OpenVAS retest works at scan level. Findings from other sources fall back to an agent-based check on the host.

NessusTenableQualysOpenVASNexposeNmapNucleiBurp SuiteOWASP ZAPAcunetixAppScanArachniNetsparkerIntruderFortifyMobSF

Where flat pricing pays off in the mid-market, and where it does not

SITEY costs $599 per month, cancel anytime, or $5,999 for a lifetime license (perpetual, with one year of updates and engine feed). There is no per-asset fee and no scan quota, but it is not unlimited: each license has an IP quota, see the pricing page. AI usage is not included.

Here is SITEY next to published list prices a mid-market buyer is likely to compare, as shown on the vendor’s page or AWS Marketplace listing on 24 September 2026.

Listed price What the listing covers
SITEY, monthly $599 per month ($7,188 over 12 months) All 28 modules, flat price, self-hosted. IP quota per license. Scanner licenses and AI usage not included.
SITEY, lifetime $5,999 once Perpetual license with one year of updates and engine feed.
ManageEngine Vulnerability Manager Plus Professional, on-premises $695 per year 100 computers with 1 technician. Cloud edition: $895 per year.
Rapid7 InsightVM, AWS Marketplace $3,840 for 12 months Up to 128 assets, unlimited scan engines and templates, up to 3 consoles.
Qualys VMDR (US only), 128 hosts $596 per month AWS Marketplace, SaaS, 1-month contract. A 12-month contract saves up to 17%.
Qualys VMDR (US only), 512 hosts $1,489 per month Same listing and terms.
Qualys VMDR (US only), 1,024 hosts $2,352 per month Same listing and terms.

The honest reading: at around 100 hosts, SITEY is the more expensive option. The monthly plan comes to $7,188 a year, roughly ten times ManageEngine’s on-premises Professional price for 100 computers and nearly twice Rapid7’s 128-asset InsightVM listing. It is about the same as Qualys VMDR’s 128-host tier on the 1-month contract, and more than that tier on a 12-month contract with its saving of up to 17%. Nor are these like-for-like: SITEY is not itself a scanner and its price excludes scanner licenses, so your budget also carries your scanner, AI usage and the server SITEY runs on.

The picture changes as the estate grows. Qualys VMDR’s listing rises to $1,489 per month at 512 hosts and $2,352 at 1,024 hosts, about two and a half and nearly four times SITEY’s monthly price; the 12-month saving of up to 17% narrows that gap without closing it. Rapid7 prices larger estates by private offer and ManageEngine sells in device-count bands, so check their quotes at your size. SITEY stays flat as long as your estate fits the license’s IP quota. Our vulnerability management pricing guide goes deeper.

What it takes to run SITEY

SITEY is self-service: you buy online, download the installer and deploy it yourself, with no sales call. The server runs on Linux only (Ubuntu 22.04 or 24.04, Debian 12, RHEL or Rocky 9) with your own PostgreSQL database, and agents run on Windows and Linux endpoints. The getting started guide covers installation and agent rollout.

What SITEY does not do

SITEY is not SaaS: you run it on your own Linux server and need at least one technical person for installation, updates and backups. There is no Windows server edition. Each license has an IP quota, so a very large estate may not fit one license. SITEY is not air-gapped: it connects to siteyvm.com for license activation and validation and for the engine feed, neither of which carries scan data. AI features use an OpenAI-compatible endpoint you choose, with your own key and at your own cost, and that endpoint receives finding text and host context. You can use a model endpoint you host yourself, or turn AI off.

The full list of outbound connections, including the optional ones, is in the FAQ below. Our security and data handling page describes what the license activation channel sends and how we handle account and billing data.

Example scenario: two people, about 600 hosts

Illustrative example

A composite scenario to show how the workflow fits a small team. It is not a customer story, and it assumes the estate fits within one license’s IP quota; check the pricing page for your size.

A manufacturing company runs about 600 IP addresses. Security is one engineer plus a systems administrator who owns the servers. They already run Nessus and test their customer portal with Burp Suite.

The engineer launches a Nessus scan from SITEY and uploads the latest Burp Suite export. Both land in one queue, where repeat findings raise a detection count instead of opening new items. AI triage ranks the queue and flags likely false positives; the engineer reverses two verdicts.

For the top findings on agent hosts, SITEY drafts PowerShell for Windows and bash for Linux. The administrator reads each script at the approval gate, approves most, and rejects one he would rather apply by hand. A flaw in a commercial product becomes a vendor contact record. After the agents apply the approved scripts, retests re-run Nessus and close only the findings that no longer appear.

Who builds SITEY

SITEY is built by SITEY Bilisim at Giresun Teknopark in Bulancak, Turkey. The founder has worked as a security researcher since 2014 and is credited with CVE-2021-40960 and CVE-2022-3792.

Frequently asked questions

Is SITEY worth it if we have fewer than 100 assets?

Probably not. ManageEngine lists Vulnerability Manager Plus Professional at $695 per year on-premises for 100 computers with one technician, while SITEY’s monthly plan comes to $7,188 a year. The flat price makes sense at hundreds of hosts, when the bottleneck is fixing findings rather than finding them.

Do we need our own scanner?

Yes. SITEY imports results from 16 scanners and testing tools and launches scans directly in Nessus and OpenVAS. Scanner licenses are not included. If you plan to use OpenVAS, note that Greenbone says its free edition is designed for private use and non-professional IT infrastructures.

Is SITEY air-gapped, and what data leaves our network?

No, SITEY is not air-gapped. Findings are stored in your own PostgreSQL database. The server connects to siteyvm.com for license activation and validation and for the engine feed; neither carries scan data. Optional calls go to the OpenAI-compatible AI endpoint you choose, which receives finding text and host context (you can point it at a model you host yourself, or turn AI off), and to NVD, CISA KEV, FIRST EPSS, MSRC and the Microsoft Update Catalog.

Will SITEY change our servers without approval?

High-impact changes wait for a person, and at the default autonomy level, until Gate 1, the pipeline stops for approval before any fix runs. Some steps happen without separate approval: read-only diagnostic scripts run on agent hosts during analysis; findings above your false-positive threshold are marked as false positives with a comment, which an analyst can reverse; and in the autonomous pipeline, once a retest verifies a fix, the rollback snapshot taken before the change is deleted and the deletion is logged.

How much does the AI cost?

AI usage is not included. You bring your own key for an OpenAI-compatible endpoint and pay that provider directly; SITEY logs each AI call with its token count and an estimated cost. The priority score and false-positive signals work without an AI key.

Sources

  1. ManageEngine Vulnerability Manager Plus pricing: manageengine.com/vulnerability-management/pricing.html, accessed 24 September 2026.
  2. ManageEngine store, Vulnerability Manager Plus: store.manageengine.com/vulnerability-management/, accessed 24 September 2026.
  3. Rapid7 InsightVM, AWS Marketplace listing: aws.amazon.com/marketplace/pp/prodview-iytoknlkgcesm, accessed 24 September 2026.
  4. Qualys VMDR (US Only), AWS Marketplace listing: aws.amazon.com/marketplace/pp/prodview-5g6ecotizcru6, accessed 24 September 2026.
  5. Greenbone, OPENVAS FREE: greenbone.net/en/openvas-free/, accessed 24 September 2026.

ManageEngine is a trademark of Zoho Corporation. Rapid7, InsightVM and Nexpose are trademarks of Rapid7, Inc. Qualys and VMDR are trademarks of Qualys, Inc. Nessus and Tenable are trademarks of Tenable, Inc. OpenVAS and Greenbone are trademarks of Greenbone AG. Burp Suite is a trademark of PortSwigger Ltd. AWS Marketplace is a trademark of Amazon.com, Inc. or its affiliates. Other names are trademarks of their respective owners. SITEY is not affiliated with or endorsed by any of these companies.