Security platform · code to network, live

One sentinel over your entire surface.

Sentinelleai scans repositories, smart contracts, web surface, cloud accounts and hosts — deterministic scanners first, a multi-model AI panel after. One forfait per surface, priced against what each function actually does today, not the whole catalogue advertised as if it were finished.

Covers:Code auditContracts · EVM, Solana, Starknet, Move, CosmWasm, NEARCloud & IaCNetworkRansomwareExecutive fraudDetection & responseCompliance
The path of a scan

Entered, analyzed, erased.

Nothing of your code accumulates here. Disk usage is bounded by concurrency, not by history.

01 · Submit

A repository, an archive, or an address

An https git repository (never a private host), an uploaded .tar.gz/.zip archive guarded against zip-slip, or a deployed contract address — the verified source is pulled from the chain's own explorer, followed through any proxy to its implementation. A web or DNS target additionally needs proof of possession, a DNS TXT record or a well-known file, before it can be scanned at all.

/api/scan/repo · upload · contract · /targets
02 · Analyze

Deterministic scanners first, AI after

Semgrep and taint analysis, dependency and supply-chain checks, secrets, and six on-chain engines (EVM, Solana, Starknet, Move, CosmWasm, NEAR) run first and produce the findings on their own. The multi-model AI panel reviews after that, as a second pass — online protection stays deterministic; nothing in the inline path waits on a model call.

SAST · dependency · secrets · contract engines → AI panel
03 · Erase

Findings are kept, the source is not

A cloned repository or a staged upload lives in a temporary directory for the duration of the scan and is removed in a finally block regardless of how the scan ends, success or failure. What the database keeps afterward is the findings — severity, file, line, the reasoning — deduplicated and tracked scan to scan.

findings only · transient checkout
The platform

What one post watches.

13 forfaits, one per surface. Each sells only the functions marked in place below — anything still in observation is shown, never billed as delivered.

Code & Software Supply Chain

$79/ month

per organization, up to 10 repositories; $5 per repository beyond that

20 in place
  • Multi-language Rules
  • OWASP Application Top 10
  • OWASP API Top 10
  • OWASP LLM Top 10

Application

$99/ month

per organization, up to 5 applications; $15 per application beyond that

9 in place
  • Web Vulnerability Scanning
  • Liveness Verification
  • Fuzzing
  • Application Crawling

Surface & Network

$69/ month

per organization, up to 20 targets (domains, addresses); IDS sensor supplied by the customer

13 in place4 in observation
  • Service Discovery
  • TLS Configuration
  • HTTP Headers
  • DNS Posture

Cloud & Containers

$89/ month

per cloud account; $40 per additional account

9 in place
  • IaC Scanning
  • Configuration Audit
  • Drift Detection
  • Container Hardening

Host & Ransomware

$4per host / month

$39 per month minimum; integrity agent, decoys and containment included

9 in place
  • File Integrity
  • Host Monitoring
  • Ransomware Detection
  • Automatic Containment

Identity & Data

$99/ month

per organization; exposed-credential monitoring included

12 in place3 in observation
  • Authority Matrix
  • Secrets & Keys
  • Authentication Posture
  • Session Security

Compliance & Governance

$149/ month

per organization; SOC 2 / ISO 27001 catalogue, risk register, audit evidence

8 in place
  • Policy as Code
  • Audit Evidence
  • Compliance Frameworks
  • Risk Register

Operations & Response

$149/ month

per organization, 20 GB of logs per month included; $3 per GB beyond that; AI incident forensics available as an add-on

16 in place1 in observation
  • Automated Response
  • Log Collection & Correlation
  • Detection Rules
  • Threat Hunting

Offensive Validation

$199/ month

per organization, up to 3 targets; or $299 per one-off campaign

5 in place4 in observation
  • Mutation Testing
  • Symbolic Execution
  • Vulnerability Reachability
  • Exploit Chains

Smart Contract Audit

$50 → $20per contract, degressive

tiered and cumulative within a calendar month: 1 to 10 contracts $50, 11 to 20: $40, 21 to 30: $30, beyond that $20; the count resets each month; one contract = up to 20 KB of source

10 in place
  • Solidity Static Analysis
  • Multi-model Panel
  • Invariants & Properties
  • Economic Security

Web3 Monitoring

$39/ month

per monitored protocol; continuous deployed-drift and on-chain monitoring

5 in place
  • Governance & Upgradability
  • Scam Detection
  • Wallet Security
  • MEV & Ordering

AI & Agents

$49/ month

per organization; injection suites, MCP, guardrails, model provenance

5 in place2 in observation
  • Static OWASP LLM Top 10
  • Transcript Leakage
  • Model Provenance
  • Autonomous Agent Guardrails

Email & CEO Fraud

$29/ month

per organization; mailbox ingestion, BEC detection; the rest of the human factor follows once wired up

1 in place4 in observation
  • Email Security

Sentinelleai Complete

every monthly plan at its base cap; contract audits billed per use

$499
/ month
The atlas behind the price

Sold only when it is actually in place.

Every function the catalogue could sell is tracked in one atlas of 147 entries, checked against the code that runs it. A forfait sells only the functions marked en place (in place); functions still partiel (partial) are shown as in observation, never billed as delivered; functions marked absent are not listed at all.

122
In place — sold today
18
In observation — shown, not billed
7
Absent — not offered
For real incidents

Forensics on demand.

A hosted forensic analyst is available for real incidents: small cases run on our always-on CPU server in the US; a mid-sized or larger incident bursts to a GPU rented in the EU for the duration. No hyperscaler and no Chinese-origin model sits in that path. Retention is short and the material is deleted afterward — this is a hosted service, so we do not promise your data never leaves your perimeter; an own-endpoint tier exists for teams that need exactly that instead.

Put one sentinel on your whole surface.

One forfait per surface, priced on what is delivered today.