Three things have to be happening at once before guarding means anything. A sensor forms a view about each machine. A layer beneath it keeps every source together so those views can be set against each other. And a human being, awake, decides. Six lines here, and the human is included in all six.
Signature matching asks whether a file has been encountered before. A decent question, until attackers began shipping a fresh build per victim. The SentinelOne sensor asks about conduct instead. The order events happened in. What spawned what. What got written, and where the socket went. Whether the overall shape looks like harvesting, like encryption, or like somebody feeling a way sideways by torchlight. It reaches its view on the machine, so an unreachable laptop is never an unwatched laptop.
Beneath that, Fluency keeps the rest of the hour. Authentication events, mail events, flow records, and logs from products you had bought before we arrived, all filed against one clock. An alert delivered with its hour attached can be acted on. An alert arriving unaccompanied must be researched before anything else, and researching is the costly half.
Level one observes and reports. Level two enlarges the frame, so an authentication from a city nobody in the firm has visited and an odd executable two desks away get read as one event with two halves. Level three moves without asking permission: take the machine off the network, put back what was altered, produce the paperwork afterwards.
Cluster nodes hold three lines of their own. The sensor differs, the behavior underneath differs, and folding nodes into an endpoint total would inflate what you pay while looking neat. Count nodes. Pods are not a billing unit anywhere on this site.
Figures on this page come from billing at the moment it opens. Anything you add rests on your manifest, and stays put while you read.
The sensor forms an opinion about behavior. The desk turns that opinion into an instruction. You receive a verdict with the working shown underneath it, and nobody posts you a dashboard and hopes for the best.
| Bolted to | SentinelOne, with Fluency keeping the joined record |
|---|---|
| Seals | Enrolled Windows, macOS and Linux endpoints |
| Stored for | The correlation window settled for this line during scoping |
| Opens with | A verdict from an analyst sitting at the Fortify 24x7 desk |
| Audited by | Engineers on shift, writing every finding onto a claim |
Same sensor, larger frame. A login nobody expected and a peculiar program somewhere across the office stop arriving as two separate puzzles and start arriving as one narrative with an order to it.
| Bolted to | SentinelOne, with Fluency correlating across sources |
|---|---|
| Seals | Endpoints, plus whichever login, mail and network feeds you connect |
| Stored for | The wider window fixed at the point those feeds are connected |
| Opens with | A verdict from an analyst reading every feed at once |
| Audited by | Fortify 24x7 engineers, with the working kept on the claim |
The wide line, handbrake fitted. Where a pattern is beyond argument the machine gets severed and the damage reversed, instead of somebody being telephoned at three in the morning to say yes to the obvious.
| Bolted to | SentinelOne, with Fluency correlation informing the action |
|---|---|
| Seals | Enrolled endpoints, severed one machine at a time |
| Stored for | The wider window, plus a permanent note of every action |
| Opens with | Rules you approved beforehand, or an engineer acting live |
| Audited by | A written account of each severance, filed onto your claim |
The same guarding, rebuilt for cluster hardware. The sensor lives on the node and reads container behavior from underneath, which is a different job with different economics and therefore its own price.
| Bolted to | SentinelOne node sensor, with Fluency correlating |
|---|---|
| Seals | Worker nodes, and whatever containers they happen to host |
| Stored for | The correlation window settled for cluster telemetry |
| Opens with | A verdict from an analyst sitting at the desk |
| Audited by | Fortify 24x7 engineers, recording findings cluster by cluster |
Cluster evidence set next to the rest of what you run. A workload behaving oddly and a credential surfacing where it has no business being are far easier to judge when both land inside a single view.
| Bolted to | SentinelOne node sensor, with Fluency correlating across sources |
|---|---|
| Seals | Cluster nodes, plus whichever login, mail and network feeds you connect |
| Stored for | The wider window fixed at the point those feeds are connected |
| Opens with | A verdict from an analyst reading cluster and estate together |
| Audited by | Fortify 24x7 engineers, with the working kept on the claim |
Severance for cluster hardware. A node behaving like somebody else's staging post gets cut away from its neighbours, under rules written on a calm afternoon and not invented during a bad night.
| Bolted to | SentinelOne node sensor, with Fluency correlation informing the action |
|---|---|
| Seals | Cluster nodes, severed individually and never wholesale |
| Stored for | The wider window, plus a permanent note of every action |
| Opens with | Rules you approved beforehand, or an engineer acting live |
| Audited by | A written account of each severance, filed onto your claim |
Guarding buys a shorter interval between the first odd event and a competent human decision about it. The interval never reaches zero, and anybody promising you zero is describing an aspiration.
Heads up: card statements show FORTIFY 24X7 - Client Data Armor is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.