First we check the environment, then we activate the protection.

Sentinel works at the level of servers, network and application traffic. Initial verification confirms systems, web servers, logs and modules available before any activation.

Linux with systemdNginx and ApacheTechnical verification included
Supported

Verified configuration.

Environments covered by the normal Sentinel installation and management process.

To be verified

It depends on the architecture.

The component is compatible, but traffic path, permissions or versions require verification.

Requires assessment

We need a dedicated evaluation.

Non-standard environments are analysed and quoted before promising coverage.

Suggested platforms

The most direct route is on Linux.

The agent is installed on each server and communicates with the central core via a secure connection.

Supported

Debian and Ubuntu

Installation managed on modern systems with systemd. The package and log paths are verified on the version actually in use.

  • Ubuntu 20.04 or later
  • Debian 10 or later
  • Architecture x86_64
To be verified

Rocky, AlmaLinux and RHEL family

The runtime is compatible; distribution, version, package manager and support status are checked before installation.

  • Rocky Linux 8+
  • AlmaLinux 8+
  • RHEL, CentOS and Fedora assessed case by case
Requires assessment

Windows and non-standard systems

Windows Server, systemd-free systems, ARM architectures and customised distributions require a specific confirmation of modules and operating modes.

  • No automatic compatibility assumption
  • Scope defined during assessment
  • Test before rollout

Web server and traffic

Nginx and Apache are the established path.

Sentinel can monitor Nginx and Apache logs and protect HTTP/HTTPS traffic via the WAF component provided by the agreed architecture.

  • Nginx: logs and integration into the traffic path.
  • Apache HTTP Server: logwatcher and configuration consistent with deployment.
  • Custom applications: watcher based on agreed files and patterns.
  • Existing Proxy or CDN: Verification of real IPs, trusted headers and the point of application of policies.
HTTPS traffic
Internet / CDNInput requests
→
Sentinel WAFanalysis and policy
→
Nginx / Apacheprotected application

Hosting panels

Plesk and cPanel: we assess the underlying infrastructure.

Sentinel is not an extension of the panel. It protects the server and hosted sites by respecting the configuration of the web stack.

To be verified

Plesk

Compatible when operating system, reverse proxy, web server and rules generated by Plesk allow safe integration. Panel updates are considered in the configuration.

To be verified

cPanel / WHM

Activation depends on distribution, Apache/Nginx combination and other components present. We do not install Sentinel without prior verification.

The commercial threshold remains per server. The panel used does not change the fee: number of sites and protected traffic determine the plan.

Firewall and host protection

The block happens where it is needed: on the server.

The agent needs privileges to read logs and apply network rules. The backend is chosen according to the machine's capabilities.

  • iptables: Classic Linux firewall backend.
  • ipset: Used when available for larger lists.
  • nftables: Available on compatible systems.
  • Windows Firewall: Coverage to be confirmed in the Windows project.
Management of blocks applied by Sentinel agents

Availability of modules

Being included in the plan does not remove technical requirements.

Each module is only enabled when the environment has the necessary dependencies and permissions.

ModuleMain requirementOutcome
WAF OWASP CRSHTTP/HTTPS traffic in the intended componentArchitectural verification
SSH protectionLinux, local authentication log and firewallSupported
Watcher Nginx / ApacheLog paths accessible to the agentSupported
File Integrity MonitoringReadable paths and storage for scan stateServer configuration
ClamAV AntivirusInstalled clamd daemon and reachable socketDependency required
Alerts and reportsConfigured channels and expected connectivitySupported

Preliminary verification

What we check before we confirm the activation.

01

System and architecture

Distribution, version, CPU, systemd, privileges and support cycle.

02

Web traffic

DNS, TLS, reverse proxy, CDN, exposed ports and real client address.

03

Logs and firewall

Routes, formats, rotation, block backend and whitelist required.

04

Modules and rollouts

Available functions, initial mode, test and controlled transition to blocking.

Frequently asked questions

Compatibility without grey areas.

Does Sentinel work with Plesk or cPanel?

Yes, when Linux servers, web servers and traffic path are compatible. A panel plugin is not required: we check the actual configuration.

Do I need to edit websites?

Normally not. The activation concerns servers, reverse proxy, log and policy; any exceptions are identified before installation.

Are all modules available on every system?

No. Operating system, web servers, firewalls, permissions and dependencies determine which modules can be activated.

Can I use Sentinel behind a CDN?

It is possible after verifying trusted headers, real IPs, TLS termination and point where the protection is applied correctly.

Does Sentinel support ARM servers?

They are not automatically considered compatible. Architecture, package and modules must be confirmed in a dedicated evaluation.

What happens if the server is not compatible?

We identify it before activation and propose, when possible, a technical adaptation or a different architecture. No module is promised without verification.

Let's check your environment.

Give us operating system, panel, web server, number of sites and monthly traffic: we confirm compatibility, modules and plan before activation.