Block the exploit
that actually worked.
Sentinel is not another signature list. It is configured from the findings a real penetration test proved against your systems — it knows the exact request that got in, because it is the one we sent.
One attempt. Blocked everywhere.
Most controls block at the box that saw the traffic, so an attacker simply moves to the next host and tries again. Sentinel runs as agents sharing one control plane, which means a source that burns a single exploit attempt loses your entire estate.
One exploit attempt · every protected host
AlertMonitor estate
BLOCKED ON 18 / 18 HOSTS
The attacker spent one exploit against one host and lost access to the whole estate. A firewall blocks at the box that saw the traffic; Sentinel blocks everywhere an agent is running, because the agents share one control plane.
How it decides
Blocking is only useful if you trust it, and trust comes from knowing what the decision rests on. Several independent signals have to agree before Sentinel acts.
Is this someone we know?
Known-good sources are checked first, before anything else is considered. The fastest way to break trust in a blocking tool is to block a customer, so that question gets asked before the scoring starts.
Does anyone else recognise it?
The source is corroborated against our own indicators and external reputation data including AbuseIPDB and VirusTotal. A hit raises confidence; it is never the sole basis for a decision.
Does the behaviour fit?
Geography and the site's normal traffic baseline are weighed in. Traffic from where your users actually are, behaving like your users actually behave, is treated very differently from traffic that is neither.
Your threshold, not ours
The confidence level required to act is set per website, and you set it. Run it in manual mode and Sentinel will recommend rather than act until you are comfortable with what it is seeing.
We publish the architecture, not the weights. The specific signal order and thresholds stay private for the obvious reason — a published scoring model is an evasion guide.
It answers the question you actually have
A blocking tool tells you it blocked something. Your team's next question is always the same, and it is never answered: did anything get through before it was stopped?
When Sentinel acts, it opens a forensic investigation across the estate to find out. If the attack succeeded anywhere, you get an alert with the evidence attached. If it did not, the case closes itself.
Why that matters more than the block
Every other tool in your stack generates work. Alerts pile up, nobody has time to work through them, and the genuine ones get buried in the noise of the ones that turned out to be nothing.
Sentinel is the rare thing that removes work instead of adding it. The detections that did not matter never reach a human at all, which is what makes the ones that do reach you worth reading.
You hold the controls
Nothing here is a black box you have to take on faith.
Five minutes to permanent
Block durations are yours to choose per site, from a brief cool-off to an indefinite ban, with one-click unblock whenever you want it lifted.
Per-site policy
Thresholds, durations and alert routing are configured per website and per server, because a marketing site and a payment application do not deserve the same trigger finger.
Monitor-only mode
Nothing has to block on day one. Run Sentinel in observation mode, watch what it would have done, and turn enforcement on when the evidence has convinced you.
Included for 90 days with every engagement
A penetration test report is an uncomfortable object to be holding: a written, evidenced list of ways into your business that will take your engineering team weeks and a release cycle to close. Between delivery and remediation you are not less exposed — you are exposed in writing.
So covering that window is part of the engagement rather than something we sell you afterwards, and it deliberately extends to desktops, firewalls and switches that were never in the test scope. Coverage runs until the finding is retested and closed.
After that you keep it at the normal rate, month to month, or you stop. No long-term contract on anything we sell — 30 days' notice is all we ask.
See engagement pricingQuestions about Sentinel
Find it, then hold the line
We test your systems properly, then protect what we proved was reachable until your team has closed it.