AI Security Platform
A complete walkthrough of every feature — from running your first audit to tracking remediation progress, exporting PDF reports, and monitoring your long-term security posture.
On This Page
Follow these steps to get maximum value from every audit.
Start by signing into your SentinelSAST account. Your dashboard at /dashboard shows a personal view of all your audits, total findings, critical issue counts, and a security trend chart across every scan you've run.
Click "New Audit" from the header or dashboard. Give your audit a descriptive title (e.g. "Payment Service v2.1" or "Login Page Security Check"). Then choose one of three input methods:
Copy and paste any source code directly. Best for targeted snippets, functions, or components.
Upload a file from your computer — JS, TS, PY, Java, PHP, Go, C/C++, Swift, Kotlin, SQL, Shell, and more.
Enter any public website URL. SentinelSAST fetches the live page and analyzes headers, libraries, forms, cookies, and client-side code.
For code and file uploads, pick the programming language to help the AI apply the most targeted security rules. URL scans detect language automatically. Click "Run Security Audit" — most scans complete in 30–60 seconds.
When you upload a dependency manifest file, SentinelSAST automatically performs Software Composition Analysis — identifying vulnerable third-party packages using your training data against known CVE databases.
Results are organized by severity: Critical, High, Medium, Low, and Info. Click any finding card to expand its full details — every finding includes:
SentinelSAST checks for missing or misconfigured HTTP security headers, unsafe code patterns, and client-side hardening opportunities. For URL scans this includes:
Each audit shows a Remediation Progress panel with an overall fix percentage, status breakdown, and per-severity progress bars. Manage each finding's status individually:
Default — needs attention
Being investigated
Not a real issue in context
Vulnerability resolved
Accepted risk
More context required
Confirmed fixed & closed
Dismissed, not tracked
Each finding has two collaboration tools: Private Notes for personal context (ticket links, risk notes, owner assignment) and Team Notes for shared discussion with timestamps and authorship.
Go to Report Settings (/report-settings) to set your company name, logo, and custom intro text. Then from any completed audit, click "PDF Report" to download a professional, stakeholder-ready document:
Your Dashboard (/dashboard) includes a Security Improvement Over Time chart that tracks your risk score and critical finding count across every completed audit — showing you whether your security posture is improving.
Evaluate any website's readiness for AI agents across 6 pillars and 28 checks
The Agent Readiness Scanner evaluates any public website URL against 28 checks across 6 categories. Enter a URL and receive a scored report (0–100) with per-check pass/fail status, risk levels, remediation guidance, and copy-paste code fixes tailored to your domain.
robots.txt, sitemap.xml, Link headers, DNS-AID — ensures AI agents can find and index your site correctly.
Markdown negotiation and alternate content formats — enables agents to ingest structured content efficiently.
AI-specific crawler rules (GPTBot, Claude-Bot), Web Bot Auth signing, and Content-Signal directives.
OAuth discovery, RFC 9728 protected resource metadata, MCP server card, agent skills index, and WebMCP registration.
x402 payment protocol, Machine Payment Protocol (MPP), Universal Commerce Protocol (UCP), and Agentic Commerce Protocol (ACP).
Content Security Policy, HSTS, Referrer Policy, Permissions Policy, clickjacking protection (X-Frame-Options / frame-ancestors), and privacy policy discoverability.
Each check includes a risk level, the intended result, the issue found, a recommendation, authoritative resource links, and a domain-specific code fix you can copy and deploy immediately.
How to Use
Self-assessment diagnostic across all 5 Trust Services Criteria — Type I & Type II
The SOC 2 Readiness Scanner evaluates your organization's observable controls across 25 checks mapped to the AICPA Trust Services Criteria. Enter your URL and organization name, choose Type I or Type II, and receive a scored gap report with evidence collection tools and AI-generated, pre-filled compliance document templates.
Organizational governance, risk assessment, monitoring, logical access, system operations, change management, and third-party risk.
Capacity management, backup & recovery procedures, and incident response plan discoverability.
Complete & accurate processing, error handling, output validation, and data integrity controls.
Data classification, encryption in transit & at rest, retention & disposal policies, and NDA requirements.
Privacy notice & consent, user data rights, cross-border transfer controls, third-party disclosure, and breach notification.
Each failed control includes auditor evidence requirements, an evidence upload tool (stored privately, visible only to you), and a one-click document template generator that pre-fills policies and procedures with your organization's context.
How to Use
Detect vulnerable third-party dependencies in your project
Upload any dependency manifest file and SentinelSAST automatically cross-references every listed package against known CVE databases. This identifies vulnerable open-source components before they reach production — one of the most common and overlooked attack vectors (OWASP A06:2021).
Each SCA Finding Includes
SentinelSAST checks for all of these headers on URL scans. Missing or misconfigured headers are reported as findings with remediation guidance.
Prevents XSS and data injection by whitelisting trusted content sources.
Forces HTTPS connections and prevents protocol downgrade attacks.
Blocks your page from being embedded in iframes — prevents clickjacking.
Stops browsers from MIME-sniffing the content type — prevents drive-by attacks.
Controls how much referrer information is included in requests — prevents data leakage.
Restricts which browser features your site can use (camera, location, mic, etc.).
Cookie Security Flags
SentinelSAST applies tailored security rules based on the language and platform being analyzed.
Supported
What We Check
Supported
What We Check
Supported
What We Check
Supported
What We Check
Supported
What We Check
Supported
What We Check
Run your first audit in under a minute. No configuration required.