Web Application Firewall · Security Monitoring

Watch from above.
Lock down the valley.

Sentinel watches over your websites: it inspects every request, stops attacks before they touch the server and shows you everything in real time. WAF OWASP CRS engine, agent fleet, geo-blocking, instant alerts. Self-hosted, made in Italy.

OWASP CRS v4 engine mTLS end-to-end Self-hosted core
0
blocked events · 24h
0
Active blocked IPs
0
permanent blocks
0
blocked web attacks · 24h
0
detected SSH attacks · 24h

Updating live data…

Sentinel in action

From a hostile request to an enforced block, without losing context.

A real operating flow of our Sentinel infrastructure. The published data is aggregated and anonymised: no IP address, domain or customer is exposed.

Real fleet data

  1. 01

    Detect

    The WAF and agent recognise the abnormal request, the SSH attempt or threshold breach.

  2. 02

    Lock

    The protection applies the policy on the affected server, stopping the hostile origin before it continues.

  3. 03

    Record and notify

    The event reaches the central console with the server, rule and reason; the alerts notify the team.

0blocked web attacks · 24h
0detected SSH attacks · 24h
Discover monitoring and alert →
Screenshot of security events in the Sentinel dashboard
Real Sentinel dashboard screen · Sensitive data obscured

Interactive tour

Three views, one protection workflow.

Explore real screenshots of the console: from the initial event to the block management, to the overall fleet view.

Security event log in the Sentinel dashboard
Centralised detectionType of event, date, server involved and technical details remain available in a single register.

Protection

One platform, every level covered.

From L7 filtering to the local firewall, and from antivirus scanning to alerts on your phone.

WAF OWASP CRS

Coraza powered by OWASP Core Rule Set v4: SQL injection, XSS, RCE, path traversal and anomaly scoring. Detection or blocking mode for each domain.

Real-time monitoring

Each event, block and anomaly in live dashboard. Fleet logs are aggregated centrally.

Agent Fleet

Manage dozens of servers from one panel. Updates canary Gradual and anti-brick.

Geo-blocking & JA4

Block entire countries and malicious TLS fingerprints. Verified bots such as Google and Bing are recognised and allowed through.

Instant alerts

Self-hosted push notifications (ntfy) and dedicated Android apps. You know right away when something is wrong.

Antivirus & FIM

ClamAV scanning and File Integrity Monitoring: detects malware and suspicious file changes.

L7 DDoS protection

Per-IP and global rate limiting with a JavaScript challenge: legitimate browsers pass while automated floods are stopped.

Server & SSH protection

Monitor access attempts and Nginx, Apache or custom logs; block hostile IPs directly on the local firewall.

Learn more →

Threat intelligence & DNSBL

Evaluate incoming IPs and check if your servers' public addresses are blacklisted.

Learn more →

Roles, 2FA & audit

Separate viewer, operator and admin, secure access with TOTP and record sensitive operations.

Learn more →

Privacy by design

The core is self-hosted, with mTLS between agent and server and at-rest encrypted secrets. External integrations are optional and declared.

How it works

Three components, one protection system.

01

The agent on your server

A lightweight reverse proxy puts the WAF in front of your sites. It inspects every request and blocks attacks locally, in milliseconds.

02

The central server

It collects events, synchronises rules and blocks over mTLS-protected gRPC, coordinates the fleet and retains the event history.

03

Your dashboard

See everything in real time, create rules, manage updates and receive alerts from any device.

Why Sentinel

Enterprise power, total control.

Made in Italy

Developed by G Tech Group. Support in Italian, no black box.

Self-hosted

The core runs on your servers without lock-ins. Only external integrations are optional and configurable.

Very light

Built with Go and Coraza without CGO: sub-millisecond latency and a minimal resource footprint.

Always updated

Server-synchronised rules and safe canary updates across the entire fleet.

Ready to secure your sites?

Tell us about your infrastructure: we verify compatibility and identify the most suitable annual plan.