One sentinel over your entire surface.
Sentinelleai scans repositories, smart contracts, web surface, cloud accounts and hosts — deterministic scanners first, a multi-model AI panel after. One forfait per surface, priced against what each function actually does today, not the whole catalogue advertised as if it were finished.
Entered, analyzed, erased.
Nothing of your code accumulates here. Disk usage is bounded by concurrency, not by history.
A repository, an archive, or an address
An https git repository (never a private host), an uploaded .tar.gz/.zip archive guarded against zip-slip, or a deployed contract address — the verified source is pulled from the chain's own explorer, followed through any proxy to its implementation. A web or DNS target additionally needs proof of possession, a DNS TXT record or a well-known file, before it can be scanned at all.
/api/scan/repo · upload · contract · /targetsDeterministic scanners first, AI after
Semgrep and taint analysis, dependency and supply-chain checks, secrets, and six on-chain engines (EVM, Solana, Starknet, Move, CosmWasm, NEAR) run first and produce the findings on their own. The multi-model AI panel reviews after that, as a second pass — online protection stays deterministic; nothing in the inline path waits on a model call.
SAST · dependency · secrets · contract engines → AI panelFindings are kept, the source is not
A cloned repository or a staged upload lives in a temporary directory for the duration of the scan and is removed in a finally block regardless of how the scan ends, success or failure. What the database keeps afterward is the findings — severity, file, line, the reasoning — deduplicated and tracked scan to scan.
findings only · transient checkoutWhat one post watches.
13 forfaits, one per surface. Each sells only the functions marked in place below — anything still in observation is shown, never billed as delivered.
Code & Software Supply Chain
per organization, up to 10 repositories; $5 per repository beyond that
- Multi-language Rules
- OWASP Application Top 10
- OWASP API Top 10
- OWASP LLM Top 10
Application
per organization, up to 5 applications; $15 per application beyond that
- Web Vulnerability Scanning
- Liveness Verification
- Fuzzing
- Application Crawling
Surface & Network
per organization, up to 20 targets (domains, addresses); IDS sensor supplied by the customer
- Service Discovery
- TLS Configuration
- HTTP Headers
- DNS Posture
Cloud & Containers
per cloud account; $40 per additional account
- IaC Scanning
- Configuration Audit
- Drift Detection
- Container Hardening
Host & Ransomware
$39 per month minimum; integrity agent, decoys and containment included
- File Integrity
- Host Monitoring
- Ransomware Detection
- Automatic Containment
Identity & Data
per organization; exposed-credential monitoring included
- Authority Matrix
- Secrets & Keys
- Authentication Posture
- Session Security
Compliance & Governance
per organization; SOC 2 / ISO 27001 catalogue, risk register, audit evidence
- Policy as Code
- Audit Evidence
- Compliance Frameworks
- Risk Register
Operations & Response
per organization, 20 GB of logs per month included; $3 per GB beyond that; AI incident forensics available as an add-on
- Automated Response
- Log Collection & Correlation
- Detection Rules
- Threat Hunting
Offensive Validation
per organization, up to 3 targets; or $299 per one-off campaign
- Mutation Testing
- Symbolic Execution
- Vulnerability Reachability
- Exploit Chains
Smart Contract Audit
tiered and cumulative within a calendar month: 1 to 10 contracts $50, 11 to 20: $40, 21 to 30: $30, beyond that $20; the count resets each month; one contract = up to 20 KB of source
- Solidity Static Analysis
- Multi-model Panel
- Invariants & Properties
- Economic Security
Web3 Monitoring
per monitored protocol; continuous deployed-drift and on-chain monitoring
- Governance & Upgradability
- Scam Detection
- Wallet Security
- MEV & Ordering
AI & Agents
per organization; injection suites, MCP, guardrails, model provenance
- Static OWASP LLM Top 10
- Transcript Leakage
- Model Provenance
- Autonomous Agent Guardrails
Email & CEO Fraud
per organization; mailbox ingestion, BEC detection; the rest of the human factor follows once wired up
- Email Security
Sentinelleai Complete
every monthly plan at its base cap; contract audits billed per use
Sold only when it is actually in place.
Every function the catalogue could sell is tracked in one atlas of 147 entries, checked against the code that runs it. A forfait sells only the functions marked en place (in place); functions still partiel (partial) are shown as in observation, never billed as delivered; functions marked absent are not listed at all.
Forensics on demand.
A hosted forensic analyst is available for real incidents: small cases run on our always-on CPU server in the US; a mid-sized or larger incident bursts to a GPU rented in the EU for the duration. No hyperscaler and no Chinese-origin model sits in that path. Retention is short and the material is deleted afterward — this is a hosted service, so we do not promise your data never leaves your perimeter; an own-endpoint tier exists for teams that need exactly that instead.
Put one sentinel on your whole surface.
One forfait per surface, priced on what is delivered today.