Home · Security

Security Sentinel

What can actually be exploited, who owns it, and proof it closed.

Most scanners hand you five hundred findings and walk away. The reason nobody fixes them is not laziness: nothing says which ones can actually hurt you, and nothing ever confirms the fix worked.

  • Severity set by reachability, not pattern. Every finding is rated by how an attacker would actually get there — and by what the exploit would expose. A theoretical issue in a script never outranks a real hole in your auth.
  • Eight categories, read in context. Authentication, authorization, secrets, injection, data exposure, infrastructure, supply chain, and business logic — judged against what your product actually does.
  • Every finding has an owner and a date. Assign it, set a deadline, and watch what is overdue. Nothing sits in a queue that belongs to everybody and therefore nobody.
  • An honest way to say "not now". Defer with a reason and a review date instead of quietly closing it. The number you report stays truthful.
  • Prove the fix, on demand. Anyone can re-check a finding the moment they believe it is resolved — a fresh read of the current code.
  • Hand it straight to the engineer. Copy a scoped prompt with the finding, the evidence, and the surrounding context already in it.
  • Credit for staying clean. A developer who ships months without introducing a critical issue gets told so — coaching signal, never a public ranking.

$100 per month protects 25 repositories on every paid plan — and coverage is available read-only during your trial. Deep whole-repository sweeps run weekly; every protected change is checked as it lands. On Scale, verification workflows and compliance export close the loop for your auditors.

How we protect your code

Built like we expect your code to be built.

We ask for a lot of trust — read access to your source. Here is exactly how we honor it.

Your code never leaves AWS

Analysis runs on Amazon Bedrock inside our AWS environment. Diffs are stored encrypted (KMS) in S3, transit is TLS everywhere, and your code is never used to train any model.

We never push code

The GitHub App reads contents, pull requests, and metadata on repos you enable. The only write is an optional review comment on a pull request — never commits, never branches. Uninstalling revokes everything instantly.

Hard tenant isolation

Every row of your data is isolated with Postgres row-level security enforced at the database layer — not just application filters.

Auditable, not oracular

Every score traces to a stored model response and a quoted diff. When a number surprises you, click through to the exact evidence.

Certified foundations

Runs entirely on AWS infrastructure holding SOC 2, ISO 27001, and PCI DSS attestations. Payments are handled by Stripe — card data never touches our servers.

You stay in control

Hard monthly AI-spend caps you configure. Export or delete your data on request. A DPA is available for teams that need one.

See the queue on your trial

The trial includes a read-only view of Security Sentinel.

Start your 14-day free trial