Project checks

Four hundred findings. Which deserve your day?

The other half of SENTINEL AI reads a project instead of a network: source code, libraries, passwords left behind, packaging and the published site. Then it decides which findings really need a person.

What is checked

Five places problems hide

Code

Source code

Dangerous constructs and common mistakes in the project's code.

Dependencies

Libraries

About 240,000 published vulnerabilities from the open OSV database for PyPI and npm. A local 4 MB file, checked offline. The age of the database is shown next to every answer.

Secrets

Passwords and keys

Credentials that ended up in code or configuration.

Packaging

Build and deployment

How the project is built and run.

Site

The published site

Only after a named person states they are entitled to test that address; the statement goes into the signed ledger. Only ordinary GET requests: nothing is submitted, injected or brute-forced.

The source can be a folder on the server, an archive, a repository address or a site address.

What matters

The layer above the checks

Any tool can run checks. The hard part is deciding which of four hundred findings deserve your day, and being able to say why. That uses the same arithmetic as attack detection.

Evidence, not a verdict

Each check produces evidence with a weight, never a verdict.

The project's context

This is test code, this value is the word “changeme”, this package is never imported, this library is only installed for development.

One cause, one task

Forty warnings about one outdated library are one decision, not forty.

An explanation for four readers

What it is, what it means and what to do, in six languages.

The same signed ledger

Including who started the check.

Report

A report you can send

One file: what was found, what it means and what to fix, in order of importance. It opens in any browser, saves as PDF, and goes to your team, a contractor or management.

Order

Important first

Tasks are ordered by score, not by the number of warnings.

Clarity

What to fix

Every task has an explanation and a concrete action.

Honesty

The database's age

An answer from a four-month-old database is a four-month-old answer, and the report says so.

Honestly

What the checks cannot do

  • They do not find more than specialised scanners

    Semgrep, CodeQL, Trivy or ZAP find raw issues just as well. The value is in deciding which findings matter.

  • They cannot see logic errors

    Wrong permissions and flaws in how the parts fit together are invisible to any scanner. A person still has to look.

  • A clean result is not a guarantee

    It means the checks found nothing, not that the project is safe. The console says so next to every result.

  • The site check only reads

    It finds what is visible from outside, not what would take an attack to prove.

Pilot

Test it on your own data

A pilot runs on one server inside your network. You see what the platform finds there, and how many alerts stop reaching your analysts.

Request a pilot →