Your attack surface
never stands still — and neither does Sentinel.
A one-time scan is a photograph. Sentinel is continuous: it monitors registered assets, detects real drift and suspicious behavior, and — when your plan and policy allow — helps contain a threat before it becomes an incident.
Monitor, detect, correlate, analyze, contain, verify
Signals come from Sentinel's own monitoring and from telemetry you forward from your own edge (nginx, and more sources over time). Related signals are correlated into an incident, analyzed — by AI when available, deterministically when it isn't — and, when policy allows, met with a scoped, time-boxed response: rate limiting, a challenge, or temporary containment. Every response is verified against a real observed effect before it's ever reported as active, and every one has an expiration and a rollback path.
Every containment action is scoped, time-boxed, and reversible — what a given plan and policy allow to run automatically (vs. require a human to approve) is configured, never assumed. Sentinel reports its real coverage honestly: monitoring-only isn't shown as protected.
What runs on its own depends on your plan and your policy
Detection and alerting are available on every plan. Rate limiting and challenge responses are available starting on Pro. Temporary containment and unattended automated response are Enterprise-only, and still require an explicit opt-in — nothing acts on your behalf by default. This isn't a firewall that blocks on its own; it's a policy-gated response layer you configure.
What you scanned last month isn't what's exposed today
A new port opens, a service gets redeployed, a forgotten admin panel comes back online — none of that shows up in a report from six weeks ago. Exposure changes continuously; monitoring has to as well.
A drift, caught
Yesterday, three open ports. Today, a fourth — unexpected. This is exactly the kind of change Sentinel is built to catch, shown here as a labeled example.
Baseline, change, drift, event, mission
Sentinel keeps a real history per asset and compares each new probe against it. A genuine change is classified as a drift event — and if you've configured a Mission for it, that event can trigger an automated response.
Sentinel compares each new probe against your asset's stored baseline. A real change — not noise — becomes a classified drift event, which can trigger a Mission.
What Sentinel actually does today
Your exposure is moving. Is your security?
Start free — see your real attack surface in minutes.
