The application firewall that stops the attack before your app.

Sentinel inspects every HTTP request and response with the Coraza engine and the OWASP Core Rule Set v4: SQL injection, XSS, RCE, path traversal and more are recognised and stopped with anomaly scoring, before they reach your site.

OWASP CRS v4CorazaDetection or Block
The problem

A request may seem normal and contain an attack.

Forms, URLs and APIs can transport malicious code to the database or application.

What Sentinel does

Inspect traffic before it reaches the site.

Compare each request against the OWASP rules and assign a score to the detected risk.

The result

First look, then block with a tailor-made policy.

Start in detection mode, correct the false positives and enable blocking one domain at a time.

What is it?

A Web Application Firewall inside the agent.

The WAF runs as a reverse proxy on your server and inspects traffic locally, in milliseconds, without sending anything out of your infrastructure.

OWASP CRS v4

The Core Rule Set v4 is embedded in the agent, with more than 900 rules covering the main application attack classes. Rules are updated with the agent release channel.

Anomaly scoring

Each rule adds a score; it only blocks when the threshold (inbound 5, outbound 4 by default) is exceeded, reducing false positives compared to the block on a single rule.

Request and reply

The inspection covers both the incoming request and outgoing response, also detecting exfiltration and revealing application errors.

Per-domain

Mode and tuning are configured per domain, with exact match resolution → wildcard → default: each site has its own policy.

How the Engine Works

From the request to the decision, in four steps.

Each request crosses the same deterministic pipeline, locally.

01

Pre-filters L3

Before the application WAF, the agent applies network filters and reputation: obviously hostile traffic is discarded without consuming the CRS engine.

02

Request inspection

Method, header, URI and body are evaluated against CRS v4 and custom rules. Beyond body limits (2 MB) the fail-open applies, so as not to break legitimate uploads.

03

Decision and anomaly score

The accumulated scores compare with the threshold. In detection mode the event is recorded without interrupting traffic; in blocking mode the request receives a 403.

04

Response Inspection

The response is also inspected (fail-open over 512 KB) for outbound anomalies: sensitive output data and revealing application errors are intercepted.

Detection vs Blocking

Observe first, then block when you are ready.

By default, the WAF works in detection: it records each event without interrupting traffic, so you can measure the real impact on your site. When false positives are under control, switch to blocking mode and requests exceeding the threshold receive a 403.

  • Detection by default: no risk of blocking real users while evaluating.
  • Per-domain mode: one site in block, another in observation.
  • Anomaly scoring with configurable threshold, rather than blocking on a single rule.
Back to functionality →
Sentinel dashboard real screen

Custom & tuning rules

CRS as a base, your rules above.

In addition to the Core Rule Set you can define custom regular-expression rules, synchronized by server every 60 seconds with atomic hot-reload: no restart, and if a rule is malformed comes isolated without dropping the rest of the engine.

  • Paranoia level 1: raise or lower the aggressiveness of controls.
  • CRS tuning: Disable individual rules by ID when generating noise.
  • Whitelist IP and constraints on methods and allowed content types.
Request a demo →
Sentinel dashboard real screen

Domain Configuration

A different policy for each site, without compromise.

Modes, thresholds, paranoia level and custom rules are applied per domain. Resolution follows order exact match → wildcard → default: the legacy site remains in detection while the new e-commerce already runs in block, all from the same agent.

Frequently asked questions

What they usually ask about the WAF.

Does the WAF slow down websites?

Not perceptibly: the inspection takes place locally in the agent in milliseconds. On the body beyond the limits (2 MB required, 512 KB response) fail-open applies, then uploads and heavy downloads are not retained.

Is data sent elsewhere?

No. The engine runs inside your infrastructure; only events and logs travel to the central server via gRPC mTLS. User traffic does not pass through third parties.

Is there a risk of false positives?

This is the reason for anomaly scoring and detection mode: look at the real impact before blocking, then do tuning by disabling individual CRS rules for IDs and putting trusted IPs in allowlists.

Can I add my own rules?

Yes. The custom regular-expression rules sync from the server every 60 seconds with atomic hot-reload. A malformed rule is isolated by itself, without dropping the rest of the WAF.

Is the CRS up to date?

We use the OWASP Core Rule Set v4, embedded in the agent. Ruleset updates arrive through the release channel, distributed to the fleet with a canary rollout with anti-brick safeguards.

Do you want to see it in action?

We'll show you Sentinel's WAF live on your infrastructure, and we'll run it domain by domain.