Complete Platform Guide

How SentinelSAST Works

A complete walkthrough of every feature — from running your first audit to tracking remediation progress, exporting PDF reports, and monitoring your long-term security posture.

01–10 Complete Step-by-Step Walkthrough

Follow these steps to get maximum value from every audit.

01

Sign In & Go to Dashboard

Start by signing into your SentinelSAST account. Your dashboard at /dashboard shows a personal view of all your audits, total findings, critical issue counts, and a security trend chart across every scan you've run.

The "/" homepage shows platform capabilities and is public — your data is only visible on /dashboard
Your security trend chart appears after 2+ completed audits
02

Start a New Audit

Click "New Audit" from the header or dashboard. Give your audit a descriptive title (e.g. "Payment Service v2.1" or "Login Page Security Check"). Then choose one of three input methods:

Paste Code

Copy and paste any source code directly. Best for targeted snippets, functions, or components.

Upload File

Upload a file from your computer — JS, TS, PY, Java, PHP, Go, C/C++, Swift, Kotlin, SQL, Shell, and more.

Scan URL

Enter any public website URL. SentinelSAST fetches the live page and analyzes headers, libraries, forms, cookies, and client-side code.

03

Select Language & Run

For code and file uploads, pick the programming language to help the AI apply the most targeted security rules. URL scans detect language automatically. Click "Run Security Audit" — most scans complete in 30–60 seconds.

Language selection improves accuracy — pick the dominant language for mixed files
You can upload dependency manifests (package.json, requirements.txt) for SCA scanning
URL scans automatically detect frameworks, libraries, and security headers
04

Software Composition Analysis (SCA)

When you upload a dependency manifest file, SentinelSAST automatically performs Software Composition Analysis — identifying vulnerable third-party packages using your training data against known CVE databases.

  • Upload package.json, requirements.txt, Gemfile, go.mod, pom.xml, or build.gradle
  • Each vulnerable dependency is listed with CVE ID, CVSS score, affected version range
  • Findings are tagged OWASP A06:2021 – Vulnerable and Outdated Components
  • Remediation includes exact upgrade version and changelog reference
05

Review Your Findings

Results are organized by severity: Critical, High, Medium, Low, and Info. Click any finding card to expand its full details — every finding includes:

  • Plain-English description of the vulnerability and its real-world impact
  • The exact vulnerable code snippet with line number
  • OWASP Top 10 category and CWE identifier
  • Step-by-step remediation guidance
  • A safe, fixed version of the code
  • Links to relevant CVEs and security references
06

Secure Headers & Code Hardening

SentinelSAST checks for missing or misconfigured HTTP security headers, unsafe code patterns, and client-side hardening opportunities. For URL scans this includes:

  • Content-Security-Policy (CSP) — blocks XSS and code injection
  • Strict-Transport-Security (HSTS) — enforces HTTPS connections
  • X-Frame-Options / frame-ancestors — prevents clickjacking attacks
  • X-Content-Type-Options — stops MIME type sniffing attacks
  • Referrer-Policy — controls information leakage in headers
  • Permissions-Policy — restricts browser feature access
  • Cookie flags: Secure, HttpOnly, SameSite — prevents session hijacking
07

Track Remediation Progress

Each audit shows a Remediation Progress panel with an overall fix percentage, status breakdown, and per-severity progress bars. Manage each finding's status individually:

Open

Default — needs attention

Under Review

Being investigated

False Positive

Not a real issue in context

Fixed

Vulnerability resolved

Won't Fix

Accepted risk

Needs Info

More context required

Resolved

Confirmed fixed & closed

Ignored

Dismissed, not tracked

08

Add Private Notes & Team Comments

Each finding has two collaboration tools: Private Notes for personal context (ticket links, risk notes, owner assignment) and Team Notes for shared discussion with timestamps and authorship.

Private Notes are saved per-finding and persist across sessions
Team Notes are timestamped and visible to all collaborators on the account
You can change a finding's status directly when posting a team note
Link to Jira/GitHub tickets or document why something is a false positive
09

Customize & Export PDF Report

Go to Report Settings (/report-settings) to set your company name, logo, and custom intro text. Then from any completed audit, click "PDF Report" to download a professional, stakeholder-ready document:

  • Branded cover page with your logo and company name
  • Risk score indicator and severity summary chart
  • Executive summary suitable for non-technical stakeholders
  • Prioritized key recommendations for immediate action
  • Detected technologies and OWASP categories
  • Full detailed findings with vulnerable and fixed code blocks
10

Monitor Security Trends

Your Dashboard (/dashboard) includes a Security Improvement Over Time chart that tracks your risk score and critical finding count across every completed audit — showing you whether your security posture is improving.

The trend chart appears after you have 2+ completed audits
Run the same codebase through multiple audits over time to measure improvement
The risk score is 0–100 (100 = most dangerous) and is calculated per audit by the AI

Agent Readiness Scanner

Evaluate any website's readiness for AI agents across 6 pillars and 28 checks

The Agent Readiness Scanner evaluates any public website URL against 28 checks across 6 categories. Enter a URL and receive a scored report (0–100) with per-check pass/fail status, risk levels, remediation guidance, and copy-paste code fixes tailored to your domain.

🔍Discoverability

robots.txt, sitemap.xml, Link headers, DNS-AID — ensures AI agents can find and index your site correctly.

📄Content Accessibility

Markdown negotiation and alternate content formats — enables agents to ingest structured content efficiently.

🤖Bot Access Control

AI-specific crawler rules (GPTBot, Claude-Bot), Web Bot Auth signing, and Content-Signal directives.

🔐API, Auth, MCP & Skills

OAuth discovery, RFC 9728 protected resource metadata, MCP server card, agent skills index, and WebMCP registration.

💳Commerce

x402 payment protocol, Machine Payment Protocol (MPP), Universal Commerce Protocol (UCP), and Agentic Commerce Protocol (ACP).

🛡️Security & Privacy

Content Security Policy, HSTS, Referrer Policy, Permissions Policy, clickjacking protection (X-Frame-Options / frame-ancestors), and privacy policy discoverability.

Each check includes a risk level, the intended result, the issue found, a recommendation, authoritative resource links, and a domain-specific code fix you can copy and deploy immediately.

How to Use

  1. 01Navigate to Scans → Agent Readiness in the menu
  2. 02Enter any public website URL (e.g. https://yoursite.com)
  3. 03Click Scan — results arrive in ~30–60 seconds
  4. 04Expand each category to review individual checks
  5. 05Click any check card to see the full details, code fix, and resources
  6. 06Copy the tailored code fix and deploy it to improve your score
Scores and code fixes are AI-generated estimates. Always review recommendations before implementing them in production. See the disclaimer on the scan page for full liability information.

SOC 2 Readiness Scanner

Self-assessment diagnostic across all 5 Trust Services Criteria — Type I & Type II

The SOC 2 Readiness Scanner evaluates your organization's observable controls across 25 checks mapped to the AICPA Trust Services Criteria. Enter your URL and organization name, choose Type I or Type II, and receive a scored gap report with evidence collection tools and AI-generated, pre-filled compliance document templates.

🔒Security (CC1–CC9)

Organizational governance, risk assessment, monitoring, logical access, system operations, change management, and third-party risk.

⚡Availability (A1)

Capacity management, backup & recovery procedures, and incident response plan discoverability.

⚙️Processing Integrity (PI1)

Complete & accurate processing, error handling, output validation, and data integrity controls.

🔐Confidentiality (C1)

Data classification, encryption in transit & at rest, retention & disposal policies, and NDA requirements.

👁️Privacy (P1–P8)

Privacy notice & consent, user data rights, cross-border transfer controls, third-party disclosure, and breach notification.

Each failed control includes auditor evidence requirements, an evidence upload tool (stored privately, visible only to you), and a one-click document template generator that pre-fills policies and procedures with your organization's context.

How to Use

  1. 01Navigate to Scans → SOC 2 Readiness in the menu
  2. 02Enter your organization name, select Type I or Type II, and provide your URL
  3. 03Click Run Assessment — results arrive in ~30–60 seconds
  4. 04Review gap findings across all 5 Trust Services Criteria
  5. 05Switch to Evidence Collection to upload supporting documents per control
  6. 06Switch to Document Templates to generate pre-filled compliance policies
  7. 07Download templates as Markdown and finalize with your legal/compliance team
This tool provides a self-assessment only. A formal SOC 2 audit must be conducted by a licensed CPA firm. Templates are a starting point and must be reviewed by qualified legal and compliance professionals before use in any audit engagement.

Software Composition Analysis (SCA)

Detect vulnerable third-party dependencies in your project

Upload any dependency manifest file and SentinelSAST automatically cross-references every listed package against known CVE databases. This identifies vulnerable open-source components before they reach production — one of the most common and overlooked attack vectors (OWASP A06:2021).

package.json
requirements.txt
Gemfile
go.mod
pom.xml
build.gradle

Each SCA Finding Includes

Package name & installed version
CVE ID and CVSS severity score
Vulnerable version range
Recommended safe upgrade version
OWASP A06:2021 classification
Direct link to security advisory

Secure HTTP Headers Reference

SentinelSAST checks for all of these headers on URL scans. Missing or misconfigured headers are reported as findings with remediation guidance.

Content-Security-PolicyHigh

Prevents XSS and data injection by whitelisting trusted content sources.

Strict-Transport-SecurityHigh

Forces HTTPS connections and prevents protocol downgrade attacks.

X-Frame-OptionsMedium

Blocks your page from being embedded in iframes — prevents clickjacking.

X-Content-Type-OptionsMedium

Stops browsers from MIME-sniffing the content type — prevents drive-by attacks.

Referrer-PolicyLow

Controls how much referrer information is included in requests — prevents data leakage.

Permissions-PolicyLow

Restricts which browser features your site can use (camera, location, mic, etc.).

Cookie Security Flags

SecureCookie only sent over HTTPS connections
HttpOnlyBlocks JavaScript access — prevents XSS theft
SameSite=StrictPrevents cross-site request forgery (CSRF)

Languages & Coverage Matrix

SentinelSAST applies tailored security rules based on the language and platform being analyzed.

Web & Frontend

Supported

JavaScriptTypeScriptHTML / CSSJSON / YAMLReact / Vue / Angular

What We Check

  • XSS (Reflected, Stored, DOM)
  • Prototype pollution
  • Unsafe eval() / innerHTML
  • CORS misconfigurations
  • Exposed secrets in source
  • Missing security headers
  • Outdated vulnerable libraries

Backend Languages

Supported

PythonJavaC#PHPRubyGoRustBash / ShellSQL

What We Check

  • SQL Injection
  • Command Injection
  • Insecure deserialization
  • Broken access control
  • Authentication flaws
  • Cryptographic failures
  • Hardcoded credentials

Systems & Memory Safety

Supported

CC++

What We Check

  • Buffer overflows
  • Stack / heap overflows
  • Integer overflows
  • Use-after-free
  • Unsafe string functions (strcpy, gets)
  • Unchecked array bounds
  • Memory leaks

Mobile Applications

Supported

Swift (iOS)Kotlin (Android)Java (Android)React NativeFlutter / Dart

What We Check

  • Insecure local data storage
  • Hardcoded API keys & secrets
  • Improper certificate validation
  • Exported components / activities
  • Weak cryptography
  • Insecure IPC / Intents
  • Improper permissions

URL / Website Scan

Supported

Any public URLSingle-page appsREST APIsAdmin panels

What We Check

  • All HTTP security headers
  • Mixed content issues
  • Cookie security flags
  • CSRF token presence
  • Information disclosure in comments
  • SQL / XSS via form inputs
  • Vulnerable JS library versions

Dependency Manifests (SCA)

Supported

package.json (npm/yarn)requirements.txt (Python)Gemfile (Ruby)go.mod (Go)pom.xml (Maven)build.gradle (Gradle)

What We Check

  • Known CVE cross-reference
  • CVSS score per package
  • Vulnerable version ranges
  • Upgrade recommendations
  • OWASP A06:2021 mapping
  • Transitive dependency flags

Ready to scan your code?

Run your first audit in under a minute. No configuration required.

SentinelSASTby 386 LLC
🔐 End-to-End Encrypted
⚖️ GDPR & CCPA Compliant
🚫 Data Never Sold

© 2026 386 LLC. All rights reserved. SentinelSAST is a product of 386 LLC. Unauthorized reproduction, copying, or distribution of this platform or any portion thereof is strictly prohibited and constitutes a material breach of the Terms of Service.