Stop hostile traffic before it reaches applications.
WAF, volume control, reputation and geographic rules work on the server that hosts the site.
From L7 application filtering and the local firewall to antivirus and mobile alerts: everything Sentinel does to protect your sites is explained in detail.
WAF, volume control, reputation and geographic rules work on the server that hosts the site.
Events, logs, malware scans and file integrity converge into a centralised view.
Policies, agent status and gradual updates are managed from one console.
Web Application Firewall
The Coraza engine with OWASP Core Rule Set v4: inspect every HTTP request and stop SQL injection, XSS, RCE, path traversal and more, with anomaly scoring.

DDoS L7 & Bot protection
Per-IP and global rate limiting with token bucket, and a JavaScript challenge that separates real browsers from the bots: under attack, the real users pass while the flood is stopped.

Geo-blocking & Reputation
Block whole countries with local GeoIP database, manage blacklist/allowlisted IP addresses and evaluate the reputation IP source is all synchronized on the fleet.

Antivirus & File Integrity
Quick, full or custom scans with ClamAV optional hash lookup, plus File Integrity Monitoring on critical paths.

Real-time monitoring & alerts
Event dashboard, aggregated logs, incident timeline, geographical report and CSV export, with self-hosted push alerts via ntfy and optional email summaries.

Fleet Management & Updates
Manage the entire fleet from a single console, with anti-brick canary updates: the update starts on a subset and continues on the rest only if the canary remains healthy.

Host & Access Protection
The agent monitors authentication attempts and Nginx, Apache or custom application logs. At the configured threshold, it applies the block on the local firewall and records the event on the dashboard.

Threat intelligence & DNSBL
Feed, DNSBL and local history contribute to the source IP score. A separate check periodically checks whether your servers' public IPs are reported in DNS blacklists.

Panel Governance
Viewer, operator and admin also have separate permissions at API level. The login supports TOTP and anti-abuse protections; mutations are recorded in the audit log.

How it works
User traffic is processed locally. Hash lookups, DNSBL, feed and SMTP are optional integrations and are only used when configured.
A lightweight reverse proxy in Go applies WAF, rate-limit, JA4, antivirus and FIM. It inspects and blocks locally, in milliseconds.
It collects events and logs, synchronizes rules and blocks via gRPC mTLS, orchestrates the fleet and retains the event history.
Monitor everything in real time, create rules, manage updates, and receive alerts from any device.
We show you Sentinel live on your infrastructure and tailor it.