On-Premise Vulnerability Management Software on Your Own Servers

Run vulnerability management on your own Linux server and PostgreSQL, with agents for Windows and Linux hosts. See every outbound call SITEY makes.

SITEY is on-premise vulnerability management software that you install on your own Linux server, backed by a PostgreSQL database you control. It collects findings from the scanners you already run, triages them, writes a fix script for each affected host, holds changes at an approval gate, has its agents apply the approved fix, and retests before closing. There is no hosted tenant and no copy of your findings on our side. SITEY is also not air-gapped, so this page lists every outbound connection it makes, what each one carries, and which ones you can switch off.

Your server

The platform runs on a Linux host you own. You install it, you hold the administrator account, and we have no remote access path into it.

Your PostgreSQL

Assets, findings, remediation scripts, approvals and audit history live in your own PostgreSQL database. Backups and retention follow your policy, not ours.

Your scanners

SITEY is not a scanner. It launches Nessus and OpenVAS scans directly and imports results from 14 other tools, so the scanners you already pay for stay in place.

16scanner integrations
28modules
8pipeline phases
2connections to siteyvm.com

Vulnerability management without SaaS

Most vulnerability management is sold as a hosted service, with your findings in the vendor’s database. That is convenient, and for many teams it is the right choice. It is harder to accept when the findings list is itself sensitive, or when policy says data about internal systems stays on internal systems.

With SITEY the platform runs inside your network. You buy a license online and deploy it yourself, with no sales call. Nobody from our side touches your environment: no support tunnel, no vendor-held credential. Agents on your Windows and Linux hosts report to your SITEY server, never to us.

On-premise here means the platform and its database run on your hardware. It does not mean nothing ever leaves your network, and the table below shows exactly what does.

Data flow: what stays inside and what leaves

Everything SITEY produces stays on your server: asset inventory, scan output, normalised findings, triage records, remediation scripts, approval decisions, retest history, agent inventory snapshots and reports. Scanner credentials are kept in your installation’s configuration file. These are the outbound calls:

What is sent Can you switch it off?
siteyvm.com: license activation and validation License key, a hashed machine fingerprint, hostname and product version. No scan data. No. The license does not activate without it.
siteyvm.com: engine feed A download of detection and remediation content updates. No scan data is sent. No. It is how detection and remediation content stays current; the lifetime license includes one year of it.
Your AI endpoint (any OpenAI-compatible endpoint you choose) The finding text and host context needed for the triage or remediation you requested. Yes. AI stays off until you add a key, and you can point it at a model endpoint you host yourself.
NVD CVE identifiers, for enrichment. Yes. Triage continues without the extra context.
FIRST EPSS CVE identifiers, for the exploit probability score. Yes.
CISA KEV Nothing identifying. It is a catalogue download. Yes.
MSRC and Microsoft Update Catalog Product and KB identifiers, for Windows patch lookup and download. Yes, but Windows KB patching depends on it.

One more path: when an approved patch job needs a vendor package, the agent fetches it over HTTPS from a fixed allowlist of official vendor hosts, or from your own SITEY server if you uploaded the package through the API.

Full detail

The security and data handling page covers what we hold as a vendor and how to report a flaw in SITEY itself.

AI triage and remediation: the platform on your servers, the model where you choose

AI triage gives each finding a false-positive probability and a priority score, using CVSS, EPSS and CISA KEV, and stores its reasoning so an analyst can overturn it. AI remediation then writes a bash or PowerShell script for the specific host, not a generic advisory.

The model does not run inside SITEY. With AI enabled, SITEY sends the finding text and host context to an OpenAI-compatible endpoint you configure, with your own API key. So on-premise AI vulnerability management with SITEY means the platform, the database and the decisions stay on your servers, and the model runs wherever you decide:

A model endpoint you host

Point SITEY at an OpenAI-compatible endpoint inside your network, and the data travels only as far as that endpoint.

A public provider

Use your own account with a provider such as OpenAI. The data goes to that provider under your own agreement with them.

AI switched off

The deterministic part of triage (priority scoring, false-positive signals, duplicate grouping) still runs on your server. AI-written analysis and fix scripts need an endpoint.

AI usage is not included in the SITEY price. You pay your provider, or you run your own model.

How a fix moves through your network

  1. Findings arrive

    Scanner results are imported, or Nessus and OpenVAS scans are launched, then normalised and deduplicated in your database.

  2. AI triage

    False-positive probability and priority score, with the reasoning kept for review.

  3. Host-specific script

    For a confirmed finding, AI remediation writes a bash or PowerShell script for that host.

  4. Approval gate

    Four autonomy levels set how far the pipeline runs unattended, and 18 AI actions are classified by risk. High-impact changes wait for a person to approve them.

  5. Agent applies the fix

    The SITEY agent on the host runs the approved script and reports the result and its inventory back to your server.

  6. Retest and close

    A retest checks the fix before the finding is closed.

Execution and approvals are detailed on the patch management module page.

System requirements

Minimum Recommended
Server operating system 64-bit Linux: Ubuntu 22.04 or 24.04 LTS, Debian 12, RHEL or Rocky 9 Ubuntu 24.04 LTS
CPU 4 cores 8 or more cores
Memory 8 GB RAM 16 GB RAM
Disk 100 GB SSD 250 GB or more SSD
Database PostgreSQL 14 or later Your own managed PostgreSQL, with backups
Agents Windows and Linux endpoints Rolled out with the tooling you already use
Outbound network HTTPS to siteyvm.com Through your existing egress proxy

There is no Windows server installation; Windows is supported for agents. Each license has an IP quota; see the pricing page. Running SITEY is a Linux administration job, so plan for someone who can manage a service, a database and an agent rollout. The getting started guide covers the path from checkout to the first closed finding.

Works with the on-prem scanners you already run

SITEY does not replace your scanner. It launches Nessus and OpenVAS scans directly (see Nessus and OpenVAS). For the other 14 tools you run the scan in that tool and import the export. Findings from every tool land in one schema. A repeat detection is linked to the original record instead of creating a new one, and when several tools report the same issue, triage groups those findings together so the queue shows them as one group (see scanner integrations). Commercial scanners need your own licenses.

NessusTenableQualysOpenVASNexposeNmapNucleiBurp SuiteOWASP ZAPAcunetixAppScanArachniNetsparkerIntruderFortifyMobSF

Other on-prem vulnerability management options

On-prem is not unique to SITEY. Several established vendors offer it, and some are stronger than SITEY in specific areas. Here is what each vendor states:

On-prem offering, per the vendor Worth knowing
SITEY Self-hosted on your Linux server with your PostgreSQL. Not air-gapped. $599/month or $5,999 lifetime, published online. Works on top of scanners you keep.
Qualys The Qualys Private Cloud Platform runs “on your own premises”. Qualys is not cloud-only.
Tenable Security Center Described as “managed on-prem”. Annual subscription priced by IP; perpetual licensing is also available. No price on the page. Tenable Patch Management (on-premises or SaaS) covers Windows, Mac, Linux and 20,000+ third-party applications.
Rapid7 Nexpose The product page is titled “On-Premise Vulnerability Scanner”. A scanner in its own right; no price on the page.
ManageEngine Vulnerability Manager Plus On-premises and cloud editions. Professional on-premises: $695 per year for 100 computers (with 1 technician), or $2,085 perpetual. Far cheaper than SITEY for a small estate.
Greenbone OPENVAS AI Uses a “built-in on-premise LLM” and states that data never leaves your network. Listed under “Upcoming Solutions”. Turns scan results into remediation actions and automatable tasks.
SentriKat Describes itself as “100% on-premises” and states support for air-gapped installation. If you need air-gap, SentriKat claims it and SITEY does not.

Where SITEY fits: a flat price published online, and one platform that takes an imported finding through AI triage, a host-specific script, an approval gate, agent execution and retest. Where others fit better: Tenable and Rapid7 bring their own scanning, Tenable Patch Management covers macOS and a wide third-party catalogue, and ManageEngine costs much less at small scale.

What SITEY does not do

It is not SaaS: you install and operate it, which takes a technical person comfortable with Linux, PostgreSQL and agent rollout. It is not air-gapped: license activation and the engine feed need outbound HTTPS to siteyvm.com. It is not a scanner. Each license has an IP quota. AI features need your own endpoint and key, and their cost is yours.

Pricing and who builds it

Two plans: $599 per month, cancel anytime, or $5,999 for a lifetime license, which is perpetual and includes one year of updates and engine feed. The price is flat, with no per-asset fee and no scan quota, but each license has an IP quota; the pricing page has the details.

SITEY is built by SITEY Bilisim at Giresun Teknopark in Bulancak, Turkey. The founder has worked as a security researcher since 2014 and is credited with CVE-2021-40960 and CVE-2022-3792.

Frequently asked questions

Is SITEY air-gapped?

No. License activation and validation, and the engine feed, need outbound HTTPS to siteyvm.com. Neither carries scan data, but a network with no outbound access cannot activate SITEY. The AI endpoint and public data sources (NVD, EPSS, CISA KEV, Microsoft) are optional.

Does SITEY need the cloud?

The platform and its database run on your server, and there is no SITEY tenant holding your findings. It needs internet access for the two siteyvm.com connections. For AI you choose: a public provider, a model endpoint you host, or no AI at all.

Does the AI run on my server?

No. SITEY sends the finding text and host context to the OpenAI-compatible endpoint you configure. If you host that endpoint, the data stays within your network; if it is a public provider, it goes to that provider. AI costs are not included in the price.

Can I install the SITEY server on Windows?

No. The server runs only on Linux: Ubuntu 22.04 or 24.04, Debian 12, RHEL or Rocky 9. Agents run on both Windows and Linux endpoints.

Do I still need a vulnerability scanner?

Yes. SITEY is not a scanner. It launches Nessus and OpenVAS scans directly and imports results from 14 other tools, including Qualys, Nexpose, Burp Suite and Nuclei. Commercial scanners need your own licenses.

Sources

Nessus and Tenable are trademarks of Tenable, Inc. Qualys, Rapid7, Nexpose, ManageEngine, Greenbone, OpenVAS, SentriKat and the other product names on this page are trademarks of their respective owners. SITEY is not affiliated with or endorsed by any of these companies.