Ship fast.
Don't get hacked.
Evidence-gated security for AI-built applications. Sentrail connects to GitHub, Supabase, and Vercel to verify what's secure, explain what's risky, and prepare fixes under your control.

AIAIcodingcodingisisfast.fast.SecuringSecuringititshouldn'tshouldn'tslowslowyouyoudown.down.SentrailSentrailisisthetheultimateultimatefirewallfirewallforforAI-generatedAI-generatedcode.code.
Your AI builds it. Sentrail secures it.
Real failures. Real attack paths. The controls that should have stopped them.
Lovable
Authenticated users with public-project links could access chat history and source code due to a backend regression that re-enabled previously removed access.
Core Directive: Security between AI agents and production.
Security that ships with your code.
Sentrail connects to your stack, runs evidence-backed checks, and prepares reviewed fixes before production.
Continuous Scanning
Detect security issues across your GitHub commits, Supabase RLS policies, package manifests, and Vercel environments 24/7.
Evidence-Gated Verdicts
Never report READY unless required evidence actually exists and is fresh. Four strict hierarchical verdict states with zero ambiguity.
AI Security Agent
Plain-language risk explanations, AST pattern verification, and deep contextual insights for every vulnerability detected.
Controlled Remediation
Prepare safe SQL and code fixes as draft pull requests. Non-destructive proposals with guaranteed human approval before any merge.
Developer-Native MCP
Bring 29 specialized security tools directly into Cursor and your CLI via official Model Context Protocol (MCP) streamable endpoints.
Seven checks.
One honest verdict.
Every launch verdict depends on fresh evidence from the checks Sentrail requires. No fake percentages or vanity scores. Click any check below to inspect its live verification rule.
Connectivity
Confirms the connectors an audit depends on are actually active, so no verdict is ever computed with a blind spot.
Database RLS
Reads every non-system table and its policy count to catch tables with Row Level Security off, and tables with RLS on but zero policies.
Supabase advisors
Pulls Supabase's own security and performance advisor lints — exposed views, definer functions, unsafe function search paths, auth configuration.
Code scan
Searches your connected repositories for service-role keys and other credentials sitting in client-reachable paths or public-prefixed env vars.
High-risk file review
Locates and reads the security-critical files — auth handling, middleware, webhooks, env plumbing, migrations — and reviews what they actually do.
Dependency audit
Resolves your package manifests and checks each dependency against the OSV vulnerability database for known advisories.
Deployment posture
Classifies deployment environment variables by risk and inspects deployment protection settings on the hosting side.
Zero Stale Evidence
If any connector is disconnected, a scan fails, or an audit expires, the verdict immediately downgrades to Insufficient Evidence.
Four Verdict States
Sentrail returns a precise state rather than an arbitrary numerical security score.
Every required check has fresh evidence and there are zero open critical or high findings.
Evidence is complete and nothing critical or high is open, but medium and low findings are waiting on a human decision.
Evidence is complete and at least one open critical or high finding stands between you and launch.
One or more required checks has never run, failed, or has gone stale — so no score is reported at all.
From code to confidence.
Under your control.
Sentrail can prepare a fix. Humans remain responsible for approval and merge.
Connect
Connect your GitHub, Supabase, and Vercel stack in minutes via official GitHub App & OAuth.
Collect Evidence
Gather fresh evidence from RLS policies, advisor lints, static AST scans, and package CVEs.
Analyze
Vulnerabilities are ranked by exploitability with full context, cutting out false-positive noise.
Human Approval
The AI agent generates precise SQL or code diff proposals. Sensitive actions park in an approval queue.
Draft PR
On your explicit approval, Sentrail opens a draft PR on a dedicated branch. No auto-merges, ever.
Verify
You merge through normal CI. Sentrail triggers an instant re-verification scan to confirm resolution.
Built for security.
Designed for developers.
We never modify your data without explicit human sign-off.
Draft PRs are opened on dedicated branches. You merge.
Run reviews directly in Cursor, Claude Code, or CI/CD.
Complete visibility across
your entire stack.
Sentrail brings your code, database, infra, and policies together so you get a single source of truth for your security.
Overview
Last scan 3m agoUnified Dashboard
All your security signals in one place. No more bouncing between three different consoles.
Real-Time Updates
Instant visibility into new vulnerabilities, advisor warnings, and branch policy shifts.
Actionable Insights
Prioritized findings with clear remediation steps, blast radius calculation, and diff generation.
Track What Matters
Monitor trends, measure risk over time, and prove readiness to stakeholders with zero friction.
Security doesn't stop
after launch.
Every commit, pull request, and deployment is inspected in real time. Secrets are fingerprinted and redacted before any findings reach an AI model.
Push / PR
Webhook trigger on monitored repo
Scanners
Gitleaks, OSV, and Semgrep AST
Redaction
Secrets scrubbed before LLM reasoning
Triage
Ranked by exploitability & context
Draft Fix
Human-approved draft PR created
Re-Verify
Automated scan confirms remediation
Gitleaks
High-entropy secrets, API keys, and service tokens matched across commits.
OSV-Scanner
Direct and transitive dependency CVE matching against the open-source advisory database.
Semgrep
Semantic pattern inspection to find SQL injections, insecure auth, and unsafe API calls.
AI proposes.
You stay in control.
Sentrail will never merge code or push destructive schema changes directly to your production database. Every fix is generated as a proposal and opened as a draft pull request.
main from sentrail/fix-rls-profilesConnect once.
Secure what actually ships.
Sentrail reads the essential security posture from the services behind your production application with least-privilege access.
GitHub
Deep repository inspections across branches, pull requests, and commit histories.
Supabase
Database posture, Row Level Security policies, and performance lints.
Vercel
Hosting environment variables risk classification and deployment protection.
More integrations in development
Cloudflare, AWS IAM, Linear, and Slack webhook alerts.
Security inside the tools
developers already use.
Connect Sentrail directly to Cursor, Claude Code, and your terminal through our official Model Context Protocol (MCP) server.
29 Security Tools for AI Agents
Allow your IDE coding agents to query launch verdicts, list open findings, check database policies, and draft remediation code without leaving your editor.
All 7 required security checks passed. Zero critical or high-risk findings. Safe to proceed with production deployment.
Built to inspect your security.
Not become another risk.
We practice defensive engineering so you can connect your stack with total peace of mind.
Read-Only by Default
We inspect your posture and code without mutating your production database or hosting environment.
Least Privilege
Scoped OAuth tokens and minimal GitHub permissions. Only read what's required for evidence generation.
Secret Redaction
Matched credentials and API tokens are fingerprinted and redacted before any findings reach an AI model.
Audit Trail
Check executions, finding transitions, and remediation approvals are durably recorded with timestamps and actors.
Human Approval Gated
Fix proposals require explicit human sign-off. Sensitive actions cannot bypass the review queue.
Data Minimization
Sentrail retains the evidence and audit history needed to explain results, while redacting sensitive values before model or telemetry processing.
Control Framework Mapping
Findings are cross-referenced with established industry security standards.
Application security verification requirements
Trust services criteria
Annex A controls
Requirement references
ECOSYSTEM COMPATIBILITY
Built for modern AI-native web stacks.
Start securing your stack.
Transparent plans with zero surprise charges. 14-day free trial on paid tiers. Cancel anytime.
Hacker
For solo founders shipping their first app.
Pro
For builders shipping weekly with Supabase.
Team
For teams with compliance requirements.
Security guides
Learn what to verify before you ship.
What people ask before connecting a project.
Straight answers about access, evidence, and who stays in control of a fix.

Ship fast.
Don't get hacked.
Connect your stack in two minutes and find out what you can actually prove is secure.
