Platform

Security and compliance, built into the control plane

Sencai is the control plane for infrastructure you already run, across eleven cloud providers and your own bare-metal servers, and security here isn't a layer bolted on afterward. Every action taken through it — a firewall change, a patch rollout, an approved elevation — writes to the same tamper-evident record. Access expires by default, changes reach the provider directly instead of a cached copy of it, and when a security review or an auditor asks for evidence, you export it instead of assembling it from memory. Sencai is built and operated by a Czech company under EU law, which is a fact you can point to, not a claim you have to explain on a call.

Every provider, one inventory, from the moment you connect

Connect an existing Hetzner, OVHcloud, Scaleway, UpCloud, AWS, Azure, Google Cloud, DigitalOcean, Vultr, Akamai/Linode, or Oracle Cloud account, and Sencai inventories what's already there — instances, networks, storage, DNS — within minutes. Nothing migrates. The account, the contract, and the bill stay exactly where they are; you're giving Sencai read access to encrypted, revocable credentials, not handing over ownership. Every discovered resource is opt-in, one at a time, to active management — connecting an account doesn't hand Sencai control of everything in it by default. If you'd rather not run your own provider account for new capacity, Sencai can provision and bill it directly: one contract, one invoice, the provider's own cost plus a 2% margin shown as its own line on the statement. Both models sit in the same organisation, so a team that starts by connecting its existing AWS account can add Sencai-billed capacity next to it, or the other way around, without a second dashboard or a second audit trail. See the full list of connected providers or read how inventory and provisioning works in more detail.

Firewall, network, and DNS changes reach the provider directly

Most tools that claim to manage your cloud are really managing a copy of it — a snapshot in their own database that drifts the moment someone edits a security group by hand. Where Sencai has built live, synchronous management, a change you make in Sencai is the change at the provider: a firewall rule, a DNS record, a virtual-network update goes out over the provider's own API, and the response comes back before the screen updates. That coverage is not the same for every capability. DNS reaches the most providers today, firewall and security-group management reaches fewer, and live virtual-network management reaches fewer still — that's Sencai's own build-out, not a limit anyone else imposes. Each integration page states plainly what's live for that provider today and what isn't yet. Where live management isn't there yet, provisioning, inventory, and the audit trail still are — you always see what exists and who touched it, even before every write path is live.

Patch, harden, and run the same runbook everywhere

A lightweight agent runs on any Linux server you point it at — a cloud instance, a bare-metal box in a colo, a machine under someone's desk. It monitors the host, tracks installed software, and applies patches, so the question 'what's running an outdated version, and where' has an answer that covers your whole fleet, not just the servers someone remembered to check. A separate agent does the same job inside Kubernetes clusters, so containerised infrastructure isn't a blind spot either. On top of that sits runbook automation: write the steps for a patch rollout or an incident response exactly once, gate it behind approval, and run it identically on every matching host instead of re-deriving the procedure by hand each time something breaks at 2 a.m. The runbook is the same whether it's executing against a managed instance or one you brought yourself — hardening a fleet shouldn't depend on which provider a given server happens to sit on.

Access that expires by default

Sign-in goes through your existing identity provider — Microsoft Entra ID or Google Workspace — with SCIM handling provisioning and deprovisioning automatically as people join and leave. Role-based access control decides what a signed-in user can see and touch day to day. For anything more sensitive, just-in-time elevation means nobody holds standing admin rights waiting to be misused: a person requests elevated access for a specific task, someone else approves it, and the access itself expires rather than needing to be manually revoked later. That approval is not a side note — it's recorded in the same audit trail as everything else that happens on the platform, so 'who approved this and for how long' is answered by the same query as 'who ran this.' See the full access-control feature set for the rest of what's configurable per organisation, including how SSO enforcement and JIT approval work together.

A ledger that can only grow, never be edited

Every action taken through Sencai — a provisioned instance, a changed firewall rule, an approved elevation, a destroyed resource — writes an entry to an append-only, hash-chained log. Each entry carries the hash of the one before it, so altering or deleting a past entry breaks the chain in a way that's detectable, not just against policy. That property is what turns 'who changed this, and when' from an investigation into a query: you're not reconstructing events from scattered logs and people's memories, you're reading a record that was built to be read that way from the start. It's also the backbone of how Sencai approaches regulatory evidence, NIS2 in particular — a framework built around being able to show what happened and how quickly you responded leans on exactly this kind of record. How far back you can see into the log depends on your plan, but nothing written into it is ever deleted.

Evidence for a security review, not a certificate we don't have

Sencai doesn't hold ISO 27001 or SOC 2, and it says so plainly rather than let a procurement questionnaire find out the hard way. What a security review actually asks for tends to be evidence, not a badge: an exportable audit trail, a record of processing activities, a published list of sub-processors, a clear statement of where your data resides, and a Data Processing Agreement that's published rather than sent on request. Sencai has all five, and Sencai Tech s.r.o. is a Czech company operating under EU law from Prague — for a team weighing NIS2 obligations, or a customer that needs data to stay under EU jurisdiction, that's a fact you can point to rather than a claim you have to unpack in a call. Read more on how this fits regulated industries and government requirements specifically, or look up NIS2 and related terms in the glossary.

Start with the inventory you already have

Connect a cloud account and Sencai maps what's running in minutes, with nothing to migrate and no card required. The free organisation plan covers five managed resources with no time limit, and paid plans with the full audit trail and access controls start at EUR 299 a month, with a 14-day trial that needs no card either.

Aloita ilmainen kokeiluPuhutaan