Skip to content
sentrasec

Self hosting

Running Sentrasec inside your own environment, with your source and findings staying there.

Self-hosting means scanning, findings and storage run inside your infrastructure. Your source code and results stay with you. Detection rules and vulnerability intelligence arrive from the Sentrasec engine over a single encrypted connection, or not at all if you prefer.

What stays in your environment

  • Source code. Analysis happens where your code already lives. It is not transmitted to Sentrasec.
  • Findings and scan history. Stored in your own database, under your retention policy.
  • Decisions and evidence. Accepted risks, downgrades and their reasoning stay with your deployment.
  • Policy. Severity thresholds, exceptions and gating rules are yours to define and enforce.

What crosses the boundary

In a connected deployment, your environment requests detection rules and vulnerability intelligence from the Sentrasec engine. Those requests carry only what is needed to answer them, such as rule versions and package names, never your source code.

The connection is:

  • Encrypted in transit.
  • Outbound only. Nothing inbound needs to be opened into your network.
  • Optional. Disconnect it and scanning continues against bundled intelligence.

Why the connection is optional

Your deployment ships with bundled detection rules and offline vulnerability data. Disconnected, it still scans, deduplicates, stores and reports.

That is a deliberate constraint: the Sentrasec engine improves a finding with richer context, current vulnerability data and exploitability reasoning, but it is never required to produce one. It is what makes fully disconnected operation the same product rather than a reduced edition. See air-gapped.

Data residency

Because scanning and storage run in your environment, self-hosted deployments satisfy residency requirements without special arrangement. You choose the region, the storage, the retention period and the backup regime, because they are yours.

Getting set up

Deployment sizing, installation, upgrade procedures and onboarding are handled as part of the commercial engagement, tailored to your environment and constraints.

Talk to us about a self-hosted deployment.