CIS hardening
Compliance & Audit → CIS Hardening (/gravity/inventory/cis) shows a
CIS-style hardening score for every fleet-enrolled host in your
organization, based on Lynis scans run by the
Sencai fleet agent.
How scanning works
Section titled “How scanning works”Once a host is enrolled and Lynis is installed on it, the fleet agent runs a scan roughly once a day and reports the result back to Sencai. A host with no Lynis binary installed is simply skipped - it won’t show up here with an error, it just won’t have a score yet.
Reading a score
Section titled “Reading a score”Each host gets a hardening score from 0–100, color-coded:
| Score | Category | Meaning |
|---|---|---|
| ≥ 80 | Good | No immediate action needed |
| 60–79 | Warning | Worth reviewing |
| < 60 | Critical | Needs attention |
The fleet-wide average score and a count of hosts in each category appear at the top of the page. Use the filter bar to narrow the table to just Good, Warning, or Critical hosts.
Hosts with no score yet
Section titled “Hosts with no score yet”A host that hasn’t run a scan yet - because it was only just enrolled, or because Lynis isn’t installed on it - simply doesn’t appear with a score. If you’re expecting a host to show up here and it doesn’t, check that:
- The fleet agent is enrolled and reporting (see Fleet agent if it isn’t).
- Lynis is actually installed on that host.
Warnings and suggestions
Section titled “Warnings and suggestions”Each row also shows a warning count and a suggestion count from that host’s last scan. Expand a row to see up to the top 10 Lynis warnings for that host - each one carries Lynis’s own warning ID and message. There’s no built-in one-click fix here: hardening warnings are host-level configuration issues (file permissions, kernel parameters, service configuration, and similar) that your team resolves directly on the host, the same way you would with Lynis run standalone.
Re-scanning
Section titled “Re-scanning”Scans run automatically on a recurring schedule per host - there’s no manual “scan now” button on this screen. If you’ve just fixed a warning and want to confirm it cleared, the next scheduled scan will pick it up; use the Refresh button to reload the table once new results have landed.
What’s included at each plan tier
Section titled “What’s included at each plan tier”CIS scanning depth differs by organization plan:
- Starter includes baseline CIS scanning.
- Professional and Business add deeper Lynis coverage plus container image signing.
- Enterprise scope is custom to your agreement.
See Plans for the current tier breakdown, or sencai.space/pricing for pricing.
What’s next
Section titled “What’s next”- Fleet agent - install the agent that produces these scans
- Vulnerabilities - container image CVEs, a separate scan from host hardening
- NIS2 - hardening evidence feeds into compliance reporting