A request may seem normal and contain an attack.
Forms, URLs and APIs can transport malicious code to the database or application.
Sentinel inspects every HTTP request and response with the Coraza engine and the OWASP Core Rule Set v4: SQL injection, XSS, RCE, path traversal and more are recognised and stopped with anomaly scoring, before they reach your site.
Forms, URLs and APIs can transport malicious code to the database or application.
Compare each request against the OWASP rules and assign a score to the detected risk.
Start in detection mode, correct the false positives and enable blocking one domain at a time.
What is it?
The WAF runs as a reverse proxy on your server and inspects traffic locally, in milliseconds, without sending anything out of your infrastructure.
The Core Rule Set v4 is embedded in the agent, with more than 900 rules covering the main application attack classes. Rules are updated with the agent release channel.
Each rule adds a score; it only blocks when the threshold (inbound 5, outbound 4 by default) is exceeded, reducing false positives compared to the block on a single rule.
The inspection covers both the incoming request and outgoing response, also detecting exfiltration and revealing application errors.
Mode and tuning are configured per domain, with exact match resolution → wildcard → default: each site has its own policy.
How the Engine Works
Each request crosses the same deterministic pipeline, locally.
Before the application WAF, the agent applies network filters and reputation: obviously hostile traffic is discarded without consuming the CRS engine.
Method, header, URI and body are evaluated against CRS v4 and custom rules. Beyond body limits (2 MB) the fail-open applies, so as not to break legitimate uploads.
The accumulated scores compare with the threshold. In detection mode the event is recorded without interrupting traffic; in blocking mode the request receives a 403.
The response is also inspected (fail-open over 512 KB) for outbound anomalies: sensitive output data and revealing application errors are intercepted.
Detection vs Blocking
By default, the WAF works in detection: it records each event without interrupting traffic, so you can measure the real impact on your site. When false positives are under control, switch to blocking mode and requests exceeding the threshold receive a 403.

Custom & tuning rules
In addition to the Core Rule Set you can define custom regular-expression rules, synchronized by server every 60 seconds with atomic hot-reload: no restart, and if a rule is malformed comes isolated without dropping the rest of the engine.

Domain Configuration
Modes, thresholds, paranoia level and custom rules are applied per domain. Resolution follows order exact match → wildcard → default: the legacy site remains in detection while the new e-commerce already runs in block, all from the same agent.
Frequently asked questions
Not perceptibly: the inspection takes place locally in the agent in milliseconds. On the body beyond the limits (2 MB required, 512 KB response) fail-open applies, then uploads and heavy downloads are not retained.
No. The engine runs inside your infrastructure; only events and logs travel to the central server via gRPC mTLS. User traffic does not pass through third parties.
This is the reason for anomaly scoring and detection mode: look at the real impact before blocking, then do tuning by disabling individual CRS rules for IDs and putting trusted IPs in allowlists.
Yes. The custom regular-expression rules sync from the server every 60 seconds with atomic hot-reload. A malformed rule is isolated by itself, without dropping the rest of the WAF.
We use the OWASP Core Rule Set v4, embedded in the agent. Ruleset updates arrive through the release channel, distributed to the fleet with a canary rollout with anti-brick safeguards.
We'll show you Sentinel's WAF live on your infrastructure, and we'll run it domain by domain.