Sensagraph is an agentless external security scanning platform that shows you your web applications the way an attacker sees them: from the public internet, with nothing to install and no code to change. Point Sensagraph at a domain, verify ownership once, and it maps any app's real attack surface across five focused capabilities: Web Application Vulnerability Detection (SQL injection, XSS, CSRF, and the rest of the OWASP Top 10), Web Server Configuration Analysis,…
$19
per month
Tenable Vulnerability Management
Score 9.0 out of 10
N/A
Vulnerability management specialist Tenable offers their cloud application and container security platform Tenable Web App Scanning (formerly Tenable.io), a vulnerability management tool that emphasizes visibility of web applications, automatic scanning, and a unified view of cloud infrastructure and possible inconsistencies indicating a vulnerability.
N/A
Pricing
Sensagraph
Tenable Vulnerability Management
Editions & Modules
Scout
$19
per month
Sentinel
$49
per month
Ops
$119
per month
Scout
$190
per year
Sentinel
$490
per year
Ops
$1,190
per year
No answers on this topic
Offerings
Pricing Offerings
Sensagraph
Tenable Vulnerability Management
Free Trial
No
No
Free/Freemium Version
Yes
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
Sensagraph is priced as a simple, self-serve subscription with no setup fees, no long procurement cycle, and no mandatory sales call to get started. A free plan includes 1 full external scan per month, so you can evaluate the product on your own domain before paying anything.
Paid plans are built to scale with how much you scan and how many domains you monitor, which makes the product a good fit for a range of buyers: solo developers securing a single site, SaaS teams watching their production environment, and agencies managing many client domains from one account. There are no agents to license per host and no per-endpoint charges, so pricing stays predictable as your footprint grows.
Every plan includes the same core scanning engine and the client-ready PDF report, so you are choosing based on scan volume and domain coverage, not being locked out of key security features at lower tiers.
—
More Pricing Information
Community Pulse
Sensagraph
Tenable Vulnerability Management
Considered Both Products
Sensagraph
No answer on this topic
Tenable Vulnerability Management
Verified User
Anonymous
Chose Tenable Vulnerability Management
I think Tenable and Qualys have a lot of similarities, I continue to go back to Tenable because of my familiarity and comfort level with it. I've also used a company called SecurityMetrics which has vulnerability scanning included but it is not as comprehensive as Tenable.
Tenable.io was a clear winner in regards to features and capability when compared to OpenVAS, Qualys, and Nexpose. OpenVAS is a fork of an older version of Nessus Scanner(from Tenable) and has been updated over the years to a great free alternative. It takes a lot more manual …
Tenable.io has a comparable set of features, with excellent support and a competitive price. After less than desirable experiences with another company, we moved to Tenable and haven't looked back since.
Rapid7 is actually very comparable to Tenable.io in terms of automated scans, automated reporting, internal and external scanners, and remediation of external scans. But for less than the cost of a Rapid7 solution that comes with internal scans only, I received more hosts …
Tenable.io is a cost effective Internal and External scanner. The Internal scanner came with a .ova, so it was very simple and quick to deploy it into our ESXi environment. It has a cloud-based dashboard for management and the internal scanner is configured to auto-update from Tenable.io. The license came with 4 External PCI scans (with remediation) a year.
Support is usually really great at walking you through any steps you need to take when you get stuck on something. There are a few false positives and errors that have come up over the years that required their help to get through. Unfortunately, the steps required to diagnose some problems are more tedious than I think should be necessary. (IE: SQL instances can throw errors that clog up your logs because one plugin affects it in a certain way. The process to diagnose this is to watch timestamps of plugins in a log while monitoring the SQL logs at the same time and using your best guess as to what is causing it.)
I think Tenable and Qualys have a lot of similarities, I continue to go back to Tenable because of my familiarity and comfort level with it. I've also used a company called SecurityMetrics which has vulnerability scanning included but it is not as comprehensive as Tenable.
We're able to mitigate over 90% of our vulnerability risk without too much effort. It helps find where automated patching fails and we can plan a fix from the findings.
A side effect of our scanning reveals new devices on our network that aren't cleared to be.