
Collect, connect, classify, prioritize, automate, manage vendor and incident risk, coordinate regulatory work, draft DPAs, train your people, and prove compliance — without stitching together a dozen tools.
The sgagent CLI inventories your machines — packages, applications, services, OS/EOL — and flags vulnerabilities with guided remediation. From the install command generated in the console to a live agent in under two minutes.
Pull findings straight from systems you own: GitHub, GitLab and Gitea repositories, plus AWS, Azure, GCP and Microsoft 365 cloud accounts.
Findings are classified by severity, tagged with CWE and enriched with CVE context — AI-assisted with a deterministic fallback — then reviewed, assigned and annotated by your analysts.
Threat feeds plus KEV and EPSS signals to prioritize what's actually exploited — with a grounded CTI Q&A assistant.
Auto-triage rules, playbooks, metric alerts and outbound actions: notify signed webhooks or open tickets in your own Jira / ServiceNow.
Step-by-step procedures for NIS2/ACN, the Cyber Resilience Act, ISO 27001, CIS Controls v8, DORA, GDPR, SOC 2, NIST CSF 2.0, PCI DSS, TISAX (automotive, VDA ISA), ISO 13485 (medical devices) and ISO 22716 (cosmetics GMP): checklists, evidence attachable to every step, decisions that conclude which obligations are yours, and a branded handbook — in Italian and English. Plus your open findings mapped to the controls of 13 frameworks, with a curated crosswalk between them, including what the agent finds on your machines. Audit readiness assembles a unified accountability dossier from that evidence, exports it for a certification body (PDF/JSON/ZIP with checksum), and shares a read-only portal with an external auditor who records findings — evidence of review, not a certification.
Run a regulatory, contractual or audit matter from its source or confirmed clause through obligations, ownership, evidence, approval, communication, receipt and a checksum dossier. Version contracts and review AI-assisted, cited clause proposals manually; then use live deadlines, recurring obligations and pilot trends to find work that needs attention. The workspace supports human decisions — it does not determine legal applicability or compliance.
Manage your suppliers as a portfolio: onboarding, risk tiering and scoring, security assessments sent and scored, contract and DPA tracking with renewal reminders — evidence gathered through a public assessment portal. Advanced scoring adds a portfolio risk heatmap, per-vendor score trend (delta & slope) and a curated sector benchmark.
Run security incidents end to end: case timeline, tasks, evidence custody and the NIS2/ACN 24h/72h regulatory-notification workflow — with playbooks to standardise the response. Advanced reporting adds a visual swimlane timeline, checklist templates, per-task approvals and Jira/ServiceNow ticket linkage with pull sync.
A governance register for decisions and approvals, a GDPR Record of Processing Activities (RoPA) with processors and DPAs, and policy management — the organisational half of compliance, not just the technical one.
Make accountability explicit: assign R/A/C/I roles to people on any resource, register formal delegations of authority with a legal or operational mandate, record a legal review as evidence, and read each delegation's tamper-evident audit trail. Governance decisions get a named Accountable owner. A recorded review is evidence, never a claim of legal validity.
Draft Data Processing Agreements (GDPR Art. 28) from versioned templates, merging vendor and RoPA data into the clauses, with clause variants by vendor risk. Send a draft to external counsel through a secure review portal, record their verdict, sign off internally with two-person approval, and promote the approved agreement into your contract register with renewal tracking. Drafts only — never a claim of legal validity.
Assign the right security training to the right people: a predefined, versioned course catalogue with a course for every one of the 13 compliance frameworks (ISO 27001, ACN, NIS2, GDPR, CRA, SOC 2, PCI DSS, NIST CSF, CIS v8, DORA, TISAX, plus ISO 13485/22716 quality-GMP) auto-assigned by role, with due dates and recurrence when a certificate lapses, generated PDF certificates, a per-course guide with by-role expectations and the regulator link, and completion reporting surfaced as a positive attestation on the Compliance pages. It surfaces material and records completion — it does not host full course content (video/SCORM) or grade an exam.
Upload each product's CycloneDX SBOM: components are matched against CVE sources, re-uploads reconcile automatically, VEX records your triage decisions — and one search answers the Log4j question across every product.
A document library for policies, certificates and audit evidence; a grounded document Q&A that answers from your library with citations; security questionnaires answered for you from your live coverage; a public, NDA-gated trust portal for your customers.
Produce CSV, JSON and PDF exports — with formula-injection-safe CSV — plus scheduled recurring reports, ready for audits.
Deliver your cyber-insurance / posture report straight to a broker or insurer — as an email attachment or a signed webhook — with a tracked send history, and keep policy renewals on the radar with due dates and status reconciliation.
Receive alerts pushed from your SIEM/SOC (Splunk, Elastic, QRadar, Sentinel or any source) over a tokenised inbound webhook, correlate them to incidents with a confidence score, and open incidents automatically with SOC playbooks. Inbound and defensive only — we never reach out to your SIEM.
Interoperate with ServiceNow GRC, OneTrust, Archer and other GRC platforms via standard formats: export controls, findings and risks as JSON/XML/CSV (download or signed webhook), and import external frameworks into your control model with control-to-control mapping. Standard-format interoperability — no fragile vendor lock-in.
Notify authorities by real PEC (certified email over standard SMTP/IMAP) with your provider mailbox — Aruba, Postel, Italpost — and keep the official proof trail: acceptance/delivery receipts pulled automatically, plus the ACN/CSIRT portal protocol number. PEC is a real transport; portal submission stays operator-driven (no fabricated authority API).
An executive dashboard and threat overview for management, custom widgets, a risk register, an asset graph and cross-module search — the state of your security at a glance.
Sign in with your corporate identity provider: SSO via OIDC (Entra ID, Google) and SAML 2.0 (ADFS and legacy IdPs), with SCIM 2.0 and JIT provisioning and enforced SSO. 2FA and custom role-based access for everyone.
Contextual help on every page, an AI assistant grounded on curated product knowledge, and live chat with a human operator when you need one.
No six-month rollout. Create an org, deploy the agent to inventory your hosts — or upload logs and CSV from the console — and let the worker do the first pass.
Start a 30-day free trial — no card. Your tenant is provisioned with row-level isolation in Postgres.
Generate the install command in the console and paste it on each host — under two minutes to a live agent, defensive and on-box only, on Windows, Linux and macOS. Or connect GitHub, GitLab, Gitea, AWS, Azure, GCP, Microsoft 365 and HIBP, or upload logs, CSV and product SBOMs from the console.
The worker classifies findings; analysts review and triage; you export compliance-ready reports.
$ sgagent register --backend $API --token $TOKEN→ registered: device 9f3a… ok$ sgagent collect✓ 412 packages · 31 services · OS/EOL (1.2s)$ sgagent watch --interval 300→ collecting every 5m · on-box only$ sgagent recommendations --ndjson{"action":"upgrade","pkg":"openssl"} ×3
Every plan starts with a 30-day free trial — no card. Prices are per month, billed in EUR, VAT excluded.
Monthly, semiannual (−10%) or annual (−20%) billing — pick the cadence above the cards. Active promotions are shown on each card.
For small teams getting started with real workloads.
The complete plan: more formats, watch mode, audit export.
High volume, every format, custom dashboards and MSP multi-tenant.