Sovereign · self-hostable · validated

The self-hostable pen-tester that proves every finding.

SENTRY is an AI penetration tester that proves vulnerabilities with working exploits — not just scanner noise. Run it connected to a £0 multi-model reasoning engine, or fully air-gapped on local inference. UK/EU-hostable, and the only autonomous tester that also red-teams your secure-comms crypto. No US CLOUD Act exposure.

Self-hosted / air-gappedValidated exploitation + PoC£0 Fusion brainSecure-comms nativeMIT-licensed core

The leaders can't run where you need them.

XBOW, Horizon3 and Pentera are powerful — and cloud-only, US-operated, and priced for the enterprise. For a UK/EU government, defence or regulated buyer, "send our attack surface to a US SaaS" is a non-starter. SENTRY closes that gap.

Sovereign by default

Runs entirely in your environment — on-prem, air-gapped, UK/EU. Your targets, findings and traffic never leave the box. Swap the brain for local inference and nothing phones home at all.

Validated, not noisy

Every finding is reproduced with a working proof-of-concept and adversarially re-checked by an independent model before it's reported — cutting the 40–70% false positives raw scanners produce.

Your brain, your choice

Drive the attacks on a £0 multi-model reasoning layer in connected environments, or switch to fully local inference (Ollama) when you need air-gapped. Same engine, no per-test metering — so continuous, per-commit testing doesn't burn a budget.

SENTRY vs the incumbents

Honest comparison for the buyer who actually has to deploy it.

DimensionPharoah SENTRYXBOW · Horizon3 · Pentera
Self-hostable / air-gappedYes — your infraNo — cloud/SaaS only
UK/EU sovereign (no CLOUD Act)YesNo — US-operated
Validated exploitation + PoCYes, adversarially verifiedPartial / varies
Red-teams secure-comms cryptoYes — P-256 ECIES/AES-GCMNo
Resellable / embeddable coreYes — MIT deterministic engineNo — proprietary
PricingFrom £299/mo~$30–50K+/yr

Real, reproduced findings

On an authorized run against a staging secure-messaging relay, SENTRY confirmed these with working PoCs — 0 false-positive criticals, every auth gate and the crypto core independently verified as sound. And it isn't limited to our own stack: pointed at a third-party vulnerable API it did not author, the same engine found real SQL injection and a password-leaking endpoint — with every reported finding reproduced by an independent second request before it's filed.

Inbox-metadata BOLA

Unauthenticated read of a victim's inbox metadata — sender graph, timing, volume — leaked 40 envelopes. Content stayed encrypted; the metadata didn't.

Sender spoofing + replay

Forged sender identity accepted at the relay; identical message replayed 5× → 5 stored copies. No sender auth, no dedupe.

Retention / TTL bypass

A future-dated message evaded the 14-day purge → permanent storage. Client-controlled timestamp, unclamped.

How it works

Point it at your target — a staging environment or your own infra. A hard, in-code allowlist means it can only ever touch what you authorize; a kill-switch stops it instantly.
It runs the kill-chain — recon → enumerate → exploit → verify → report, driven by the multi-model brain, with deterministic scanners and bespoke crypto tests as its hands.
Every finding is proven — reproduced with a PoC and re-checked by an independent model, then written to your dashboard with severity, evidence and a fix.
Wire it into CI — a fast baseline on every deploy, a full run nightly. A verified critical can gate the release before it ships.

Pricing

Two tiers. The engine costs £0 to run, so the team tier can undercut per-test incumbents by an order of magnitude — while gov & regulated buyers get the sovereignty, assurance and support their procurement actually requires.

Team · self-hosted / CI
£299 / month
  • Full pen-test engine — deterministic suite + optional autonomous mode
  • Self-host on your own infra (Docker / air-gapped)
  • Validated exploitation + PoCs
  • Crypto + secure-comms test suite
  • CI mode + local dashboard
  • Community + email support
Enterprise & Government
Custom
  • Everything in Team, at estate scale
  • Sovereign / on-prem deployment + support
  • Fully-offline local-inference option
  • External-audit bundle (Cure53 / NCC pathway)
  • Procurement-ready assurance pack
  • Priority support + SLAs
Authorized testing only — built for defenders. SENTRY enforces an in-code host allowlist (your own infrastructure) and a kill-switch, and refuses any target you haven't authorized. Licence terms include an acceptable-use clause; you are responsible for operating it lawfully and only against systems you own or are contracted to test.

FAQ

Does anything leave our environment?

No. The engine, the target and the findings all run locally. The only optional outbound call is to the reasoning brain — and you can point that at a local model (Ollama) for a fully offline, air-gapped deployment with zero external calls.

How is this different from a vulnerability scanner?

Scanners flag potential issues and produce 40–70% false positives. SENTRY reproduces each finding with a working exploit and has an independent model try to refute it before it's reported — so what you get is validated and actionable.

Is it safe to run?

Yes. Scope is enforced in code, not in a prompt — a hard host allowlist restricts it to infrastructure you own, with a kill-switch. It sends only requests a correct server must reject; it never runs destructive payloads.

Can we embed or resell it?

SENTRY's deterministic engine — the probe suite, the P-256 crypto harness, the allowlist and the report engine — is 100% original Pharoah code, MIT-licensed, and embeddable/resellable today. The optional autonomous --agent mode is built on CAI, which carries a separate commercial-licence condition — so that mode needs its own licence (or a permissive replacement) before resale. Talk to us about OEM / partner terms.