Four hundred findings. Which deserve your day?
The other half of SENTINEL AI reads a project instead of a network: source code, libraries, passwords left behind, packaging and the published site. Then it decides which findings really need a person.
Five places problems hide
Source code
Dangerous constructs and common mistakes in the project's code.
Libraries
About 240,000 published vulnerabilities from the open OSV database for PyPI and npm. A local 4 MB file, checked offline. The age of the database is shown next to every answer.
Passwords and keys
Credentials that ended up in code or configuration.
Build and deployment
How the project is built and run.
The published site
Only after a named person states they are entitled to test that address; the statement goes into the signed ledger. Only ordinary GET requests: nothing is submitted, injected or brute-forced.
The source can be a folder on the server, an archive, a repository address or a site address.
The layer above the checks
Any tool can run checks. The hard part is deciding which of four hundred findings deserve your day, and being able to say why. That uses the same arithmetic as attack detection.
Warnings with a common cause become one task with an explanation.
Evidence, not a verdict
Each check produces evidence with a weight, never a verdict.
The project's context
This is test code, this value is the word “changeme”, this package is never imported, this library is only installed for development.
One cause, one task
Forty warnings about one outdated library are one decision, not forty.
An explanation for four readers
What it is, what it means and what to do, in six languages.
The same signed ledger
Including who started the check.
A report you can send
One file: what was found, what it means and what to fix, in order of importance. It opens in any browser, saves as PDF, and goes to your team, a contractor or management.
Important first
Tasks are ordered by score, not by the number of warnings.
What to fix
Every task has an explanation and a concrete action.
The database's age
An answer from a four-month-old database is a four-month-old answer, and the report says so.
What the checks cannot do
They do not find more than specialised scanners
Semgrep, CodeQL, Trivy or ZAP find raw issues just as well. The value is in deciding which findings matter.
They cannot see logic errors
Wrong permissions and flaws in how the parts fit together are invisible to any scanner. A person still has to look.
A clean result is not a guarantee
It means the checks found nothing, not that the project is safe. The console says so next to every result.
The site check only reads
It finds what is visible from outside, not what would take an attack to prove.
Test it on your own data
A pilot runs on one server inside your network. You see what the platform finds there, and how many alerts stop reaching your analysts.
Request a pilot →