A Fortify 24x7 brand. Plating over the equipment that holds patient records.Client sign inAsk an engineer
Patient Data Armor
Plate 03 / Strike face

An agent sees the process start. A person decides what happens next.

The outermost layer is the one that takes the hit. It has to recognize a hostile process while that process is running, on a machine that may be sitting in an empty operatory at two in the morning, and it has to put what it found in front of somebody who is awake. Six lines here, and each of them terminates at a staffed desk instead of a dashboard nobody was watching.

SentinelOneFluencyEngineers on shift all night
6 lines / 3 response tiers / endpoints and cluster nodes
Lines here6
Built bySentinelOne + Fluency
Counted inEndpoints or nodes
DeskAwake at 3am

What the agent is really modelling

Checking files off a catalogue of known bad ones lost its usefulness once attackers began rebuilding their tools per target. What the SentinelOne agent tracks instead is conduct: what a program touched, what it launched, who it phoned, and whether the overall shape resembles somebody harvesting files, scrambling them, or wandering quietly across a practice network looking for the server. All of that reasoning happens on the machine, so a provider laptop on a home connection is no less defended than the desktop at reception.

Fluency then sets what the agents saw beside everything else in the picture: who signed in and from where, what arrived by mail, what crossed the network, and logs coming off equipment you already own. Give an engineer a finding that arrives with its surroundings and the decision takes minutes. Give them one stripped bare and it turns into an afternoon of digging, which is how a quiet Friday becomes a difficult Monday.

Give an engineer a finding that arrives with its surroundings and the decision takes minutes.

Picking a tier without buying too much

The first tier watches and advises: something happens, we work out what it was, and you are told what to do about it. The middle tier broadens what gets compared, so an unfamiliar sign in and a strange program on the billing desktop stop being two unrelated oddities living in two unrelated consoles. The top tier lets the platform pull the plug unaided, the version you want protecting whatever touches charts and payments.

Cluster nodes each carry a line of their own. Nothing about a node resembles a reception PC, the agent works differently there, and rolling nodes into a desktop count hands you an invoice that misdescribes your own estate. The number we want is nodes. Never pods.

Lines on this plate

Specifications and rates

Every figure below arrives from the billing system while this page opens. Whatever you add sits waiting in the panel while you keep reading.

Fortify-MDRSpecification

Managed Detection and Response

SentinelOne on the box, Fluency above it

Conduct based defense on every machine you enroll, read by staff who work each case from first look to whatever closes it. What reaches you is a conclusion with the reasoning attached, never a colored square waiting to be interpreted.

  • Works across Windows, macOS and Linux, and carries on once the link drops.
  • Fortify 24x7 staff work every case from beginning to close.
  • Conclusions and case history are readable in your portal at any hour.
Built onSentinelOne, correlated by Fluency
Runs onWindows, macOS, Linux
ResponseNotice, advice, and hands on cleanup
OfflineStill works with no link back to anything
DeskFortify 24x7 staff, whatever hour it is
Counted inProtected endpoints, monthly
Fetching the rateper protected endpoint
taken monthly, up front
QTY
Fortify-XDRSpecification

Extended Detection Across Layers

SentinelOne, broadened out by Fluency

All the first tier does, plus logins, mail and network traffic read in one window alongside the machine. Most practice compromises begin in a mailbox and end on a desktop, and this tier is the one able to see both ends of that at once.

  • Machine conduct set beside login history, mail traffic and network flow.
  • Findings that only exist once two unrelated sources are compared.
  • History kept longer, since certain cases only resolve looking backwards.
Built onSentinelOne with broader Fluency correlation
ReadsMachines, logins, mail, network
ResponseNotice, advice, and hands on cleanup
HistoryHeld longer for retrospective work
SuitsPractices already living inside a Microsoft tenant or a Google one
Counted inProtected endpoints, monthly
Fetching the rateper protected endpoint
taken monthly, up front
QTY
Fortify-XDR+Specification

Extended Detection with Response

SentinelOne, permitted to contain and to reverse

The broadened tier, with authority. Once a machine passes the threshold it is taken off the network and restored to how it was, while our engineer is still reading the file. That difference is worth most in the hours when the building stands empty.

  • A machine past the threshold is disconnected without waiting on anybody.
  • Changes the offending program made get put back, wherever the system allows that.
  • Anything the platform did alone is checked by staff later and written up.
Built onSentinelOne with automated action
ContainmentOffending machine pulled off the network
ReversalPuts back what the offending program altered, where supported
OversightStaff check every automated action after the event
SuitsCharting, imaging and billing desktops
Counted inProtected endpoints, monthly
Fetching the rateper protected endpoint
taken monthly, up front
QTY
Fortify-MDR-K8Specification

Managed Detection, Kubernetes Node

SentinelOne, watching container workloads

Cover across containerized workloads, counted at node level so the invoice quotes a figure your platform engineer already knows by heart. Relevant to larger groups and to health technology companies running clusters of their own.

  • A single agent on each node, covering whatever gets placed onto it.
  • The same staff, the same handling, the same case flow as the machine lines.
  • Watches how containers behave, rather than only inspecting images.
Built onSentinelOne for Kubernetes
ScopeHow workloads behave on that node while running
ResponseNotice, advice, and hands on cleanup
DeskFortify 24x7 staff, whatever hour it is
Counted inKubernetes nodes, monthly
Fetching the rateper Kubernetes node
taken monthly, up front
QTY
Fortify-XDR-K8Specification

Extended Detection, Kubernetes Node

SentinelOne on nodes, wired to the estate through Fluency

Node cover plus correlation, so what the cluster does is read beside logins and machine conduct rather than inside a console somebody must remember exists.

  • Whatever the node reports gets compared with the remainder of the estate inside Fluency.
  • Cases that run from a workload back to whichever account reached it.
  • History kept longer over cluster and machine sources together.
Built onSentinelOne for Kubernetes, correlated by Fluency
ReadsNode runtime, logins, machines, network
ResponseNotice, advice, and hands on cleanup
HistoryHeld longer for retrospective work
Counted inKubernetes nodes, monthly
Fetching the rateper Kubernetes node
taken monthly, up front
QTY
Fortify-XDR+K8Specification

Response Tier, Kubernetes Node

SentinelOne, shutting a workload down unaided

The node line with authority attached, for clusters carrying work nobody can leave misbehaving until a person logs in tomorrow.

  • A workload past the threshold gets stopped without waiting on anybody.
  • One file assembled out of cluster, login and machine evidence together.
  • Anything the platform did alone is checked by staff and sent to you.
Built onSentinelOne for Kubernetes with automated action
ContainmentThe offending workload is acted on directly
OversightStaff check every automated action after the event
SuitsProduction clusters carrying patient facing workloads
Counted inKubernetes nodes, monthly
Fetching the rateper Kubernetes node
taken monthly, up front
QTY
Material limits

Where the strike face gives out

Watching for trouble works as a control and fails as a promise. The outer edge of these six lines is written down below, so the rest of your security program can be planned around it.

  • Spotting something is not stopping it. An agent recognizing an intrusion is telling you one already began. What you are buying is how quickly the next thing happens. Nobody is selling a guarantee that nothing will begin, and a provider offering one is describing a hope.
  • Sealed clinical equipment usually takes no agent. Imaging modalities, chairside units, lab analysers and their relatives tend to be locked by whoever manufactured them, and putting software on one can end its support or its clearance. Those get fenced off and watched from the network side, which is a different job from the one done here.
  • A machine with no agent reports nothing. Equipment that was never enrolled emits no signal, features in no case file, and is covered by nothing on this sheet. Staff owned phones and home desktops sit outside unless you make a decision to bring them in.
  • Putting files back is not a backup. The top tier reverses changes made by an offending program on systems that permit it. It will not revive a dead disk, nor produce last quarter's version of a letter. Look at the deep store sheet for that.
  • Calling something a breach is your decision. You get the sequence, the evidence and a straight description of what was recorded. Whether that adds up to a reportable breach under HIPAA or your state statute is settled between your practice and your counsel, and we will not settle it for you.
BILLING

Heads up: card statements show FORTIFY 24X7 - Patient Data Armor is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.