The outermost layer is the one that takes the hit. It has to recognize a hostile process while that process is running, on a machine that may be sitting in an empty operatory at two in the morning, and it has to put what it found in front of somebody who is awake. Six lines here, and each of them terminates at a staffed desk instead of a dashboard nobody was watching.
Checking files off a catalogue of known bad ones lost its usefulness once attackers began rebuilding their tools per target. What the SentinelOne agent tracks instead is conduct: what a program touched, what it launched, who it phoned, and whether the overall shape resembles somebody harvesting files, scrambling them, or wandering quietly across a practice network looking for the server. All of that reasoning happens on the machine, so a provider laptop on a home connection is no less defended than the desktop at reception.
Fluency then sets what the agents saw beside everything else in the picture: who signed in and from where, what arrived by mail, what crossed the network, and logs coming off equipment you already own. Give an engineer a finding that arrives with its surroundings and the decision takes minutes. Give them one stripped bare and it turns into an afternoon of digging, which is how a quiet Friday becomes a difficult Monday.
The first tier watches and advises: something happens, we work out what it was, and you are told what to do about it. The middle tier broadens what gets compared, so an unfamiliar sign in and a strange program on the billing desktop stop being two unrelated oddities living in two unrelated consoles. The top tier lets the platform pull the plug unaided, the version you want protecting whatever touches charts and payments.
Cluster nodes each carry a line of their own. Nothing about a node resembles a reception PC, the agent works differently there, and rolling nodes into a desktop count hands you an invoice that misdescribes your own estate. The number we want is nodes. Never pods.
Every figure below arrives from the billing system while this page opens. Whatever you add sits waiting in the panel while you keep reading.
Conduct based defense on every machine you enroll, read by staff who work each case from first look to whatever closes it. What reaches you is a conclusion with the reasoning attached, never a colored square waiting to be interpreted.
| Built on | SentinelOne, correlated by Fluency |
|---|---|
| Runs on | Windows, macOS, Linux |
| Response | Notice, advice, and hands on cleanup |
| Offline | Still works with no link back to anything |
| Desk | Fortify 24x7 staff, whatever hour it is |
| Counted in | Protected endpoints, monthly |
All the first tier does, plus logins, mail and network traffic read in one window alongside the machine. Most practice compromises begin in a mailbox and end on a desktop, and this tier is the one able to see both ends of that at once.
| Built on | SentinelOne with broader Fluency correlation |
|---|---|
| Reads | Machines, logins, mail, network |
| Response | Notice, advice, and hands on cleanup |
| History | Held longer for retrospective work |
| Suits | Practices already living inside a Microsoft tenant or a Google one |
| Counted in | Protected endpoints, monthly |
The broadened tier, with authority. Once a machine passes the threshold it is taken off the network and restored to how it was, while our engineer is still reading the file. That difference is worth most in the hours when the building stands empty.
| Built on | SentinelOne with automated action |
|---|---|
| Containment | Offending machine pulled off the network |
| Reversal | Puts back what the offending program altered, where supported |
| Oversight | Staff check every automated action after the event |
| Suits | Charting, imaging and billing desktops |
| Counted in | Protected endpoints, monthly |
Cover across containerized workloads, counted at node level so the invoice quotes a figure your platform engineer already knows by heart. Relevant to larger groups and to health technology companies running clusters of their own.
| Built on | SentinelOne for Kubernetes |
|---|---|
| Scope | How workloads behave on that node while running |
| Response | Notice, advice, and hands on cleanup |
| Desk | Fortify 24x7 staff, whatever hour it is |
| Counted in | Kubernetes nodes, monthly |
Node cover plus correlation, so what the cluster does is read beside logins and machine conduct rather than inside a console somebody must remember exists.
| Built on | SentinelOne for Kubernetes, correlated by Fluency |
|---|---|
| Reads | Node runtime, logins, machines, network |
| Response | Notice, advice, and hands on cleanup |
| History | Held longer for retrospective work |
| Counted in | Kubernetes nodes, monthly |
The node line with authority attached, for clusters carrying work nobody can leave misbehaving until a person logs in tomorrow.
| Built on | SentinelOne for Kubernetes with automated action |
|---|---|
| Containment | The offending workload is acted on directly |
| Oversight | Staff check every automated action after the event |
| Suits | Production clusters carrying patient facing workloads |
| Counted in | Kubernetes nodes, monthly |
Watching for trouble works as a control and fails as a promise. The outer edge of these six lines is written down below, so the rest of your security program can be planned around it.
Heads up: card statements show FORTIFY 24X7 - Patient Data Armor is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.