Sentinel is Airgrid's platform for vulnerability assessment of websites, applications and infrastructure. Modular, fully logged, GDPR-compliant.
No credit card required · EU users only
Platform
Every aspect of Sentinel is designed for traceability, operational security and legal compliance.
Access to the platform is restricted and subject to identity verification.
Every scan generates an exportable report with severity ratings, evidence and remediation steps for each finding.
All platform activity is logged and retained in compliance with applicable regulations.
The platform is designed in accordance with EU Regulation 2016/679 and applicable national legislation.
EU Directive 2022/2555 (NIS2) requires organisations to identify and manage vulnerabilities in their systems. Sentinel supports this obligation by providing continuous vulnerability assessment, documented evidence and audit-ready reports — making a concrete contribution to your organisation's NIS2 compliance journey.
Technical capabilities
From a quick HTTP header check to a full RED Team pentest. Each module produces findings classified by severity.
HSTS, CSP, X-Frame-Options, CORS, cookie security, information disclosure.
Certificate, expiry, obsolete protocols, weak cipher suites, HTTP→HTTPS redirect.
CMS, framework, WAF, CDN, WordPress, analytics, technology fingerprinting.
.git/.env exposed, SQLi, reflected XSS, CSRF, open redirect, OWASP sensitive files.
A/MX/NS/TXT records, SPF/DKIM/DMARC, zone transfer, subdomain enumeration.
Top 1000 TCP ports via nmap, service detection, dangerous open ports.
OS fingerprinting, network firewall identification (make/model), associated CVEs.
Finds API keys, tokens and hardcoded credentials in public JavaScript files.
Subdomains pointing to unclaimed services: GitHub Pages, Heroku, S3 and more.
S3, GCS and Azure Blob buckets: checks for unauthorised public access.
Swagger, GraphQL, Spring Actuator, phpMyAdmin and exposed management panels.
Parameters and endpoints vulnerable to Server-Side Request Forgery and Open Redirect.
Rate limiting, lockout, CAPTCHA and default credentials on login forms.
crt.sh queries for historical and active subdomains in public TLS certificate logs.
Emails, internal IPs, sensitive comments, software versions and social profiles from source.
Plans & pricing
Monthly subscription, cancel anytime. All plans include secure access and activity logging.
Basic plan
Free
€ 0 / month
No card required
Professional plan
Web Sec PRO
€ 3,90 + VAT / month
VAT 22% · Monthly subscription
Advanced plan
Web Sec RED
€ 19,90 + VAT / month
VAT 22% · Monthly subscription
Authorised use only. Sentinel services are intended solely for systems for which the user holds explicit written authorisation. Unauthorised use may constitute criminal offences under applicable law. All activities are logged and retained. Airgrid S.r.l. accepts no liability for unlawful use.