CentroKey Sentinel
Find the weakness before they do.
A single platform for AI penetration testing, attack surface monitoring, cloud security and vulnerability management — built for lean security and IT teams, and the MSPs who serve them.
Authorised testing only · UK-hosted · no scan runs until you verify the target
The four questions
Every screen answers one of these
A vulnerability list nobody acts on is not security. Sentinel is built around the only four questions that change what you do on Monday.
What is exposed?
Continuous discovery of everything of yours that faces the internet — subdomains you forgot, an admin panel left open, a service that appeared last week, a certificate about to expire.
What is actually dangerous?
Not a wall of CVEs. Findings ranked by a risk score that weighs real exploitation, internet exposure, how critical the asset is and how confident we are — so the top of the list is genuinely the top.
How do I fix it?
Specific remediation for your stack: the package and version to move to, the header to set, the port to close. Written for the person who has to do it, not for an auditor.
Can I prove it is fixed?
Re-test on demand. A finding is only marked fixed when a scan confirms it is gone — and if it comes back, it is flagged as a regression, not filed as new.
The platform
Everything in one platform
Most teams stitch this together from four or five tools. Sentinel is one.
AI penetration testing
AI-driven testing that goes past a scan — safely validating whether a weakness is genuinely exploitable, chaining what a real attacker would reach first, with no destructive payloads.
Attack surface monitoring
DNS and subdomain discovery, TLS and certificate analysis, exposed services and technology fingerprinting — with changes highlighted week on week.
Cloud security
Connect AWS, Azure and Google Cloud. Sentinel discovers cloud assets automatically and checks them against CIS benchmarks and common misconfigurations.
Vulnerability management
Findings de-duplicated across scans so you track one issue over time, with occurrence history, ownership, SLA dates and comments.
Web application & API security
Authenticated application scanning, OWASP Top 10 coverage, security headers, session configuration, and schema-aware API assessment.
Network & infrastructure
External and internal scanning of your hosts, ports and services — so exposure inside the perimeter is caught too, not just what faces the web.
Rapid Response
When a serious new vulnerability breaks, Sentinel proactively checks your systems for it — often before it is in the news — and tells you if you are affected.
AI Security Analyst
Turns scanner output into a decision: what it means, the business impact, how likely it is a false positive, and exactly what to do about it.
Reports & compliance
Executive summaries for the board, technical detail for engineers, and evidence mapped to ISO 27001, SOC 2, Cyber Essentials and NIST CSF.
Rapid Response
Know within hours, not weeks.
The gap between a vulnerability going public and attackers using it is now measured in hours. When something serious drops, our team writes a check and Sentinel sweeps your whole estate for it — then tells you plainly whether you are exposed and what to do. You find out from us, not from an incident.
How Rapid Response works
- We track emerging, high-impact vulnerabilities
- A targeted check is written and pushed to the platform
- Your assets are swept automatically
- You get a clear "affected / not affected" answer
How it works
Live in minutes, testing continuously
Add your targets
Domains, IP ranges, cloud accounts, applications and APIs. Sentinel maps the full attack surface behind them automatically.
Prove you control them
Publish a DNS record or verification file. Until we have seen it, no active test can be dispatched — there is no override.
Sentinel tests continuously
Scheduled and on-change scanning, AI validation of what is exploitable, and alerts the moment something new appears.
Fix, then prove it
Follow the remediation for your stack, re-test on demand, and get a clean, auditable record that it is gone.
The difference
From "CVE-2026-1234, CVSS 9.8" to a decision
Most scanners hand you a severity number and leave the thinking to you.
A typical scanner says
CVE-2026-1234 detected. CVSS 9.8. Critical.
Now you work out whether it is reachable, whether it is real, whether it matters more than the other forty, and what to actually change.
Sentinel says
Critical — internet-facing authentication service
The affected service is publicly accessible and appears vulnerable to a known issue. Validation indicates the vulnerable condition is present. No destructive testing was performed.
Impact: an attacker may be able to
compromise the service.
Do this: upgrade package X to version Y, restrict public access until
patched, then run a remediation scan.
Confidence: high · Fix effort: low · Priority: fix now
Why Sentinel
A scan finds things. Sentinel tells you what to do.
| Typical scanner | CentroKey Sentinel | |
|---|---|---|
| Findings | A long list of CVEs | Ranked by real exploitability & exposure |
| Is it real? | You verify by hand | AI validation of what is actually exploitable |
| Fix guidance | Generic advisory text | Specific to your stack, written for the fixer |
| New threats | Wait for the next scan | Rapid Response sweeps within hours |
| Proof of fix | Re-scan everything | On-demand re-test & regression tracking |
| Authorisation | In the small print | Enforced — no scan until ownership is verified |
| Multi-client | One account per client | One console, whole MSP portfolio |
| Data | Often offshore | UK-hosted, encrypted, auditable log |
Authorised testing
We will not scan what you cannot prove you control
This is the part most tools gloss over. Security testing against a system you are not authorised to test is a criminal offence in the UK — so authorisation is built into the product, not into the small print.
Ownership is verified, not asserted
Publish a DNS record or a verification file we specify. Until we have seen it, an active scan cannot be dispatched — there is no override.
Scope is enforced at the network layer
Scanners receive a fixed list of addresses they may contact and are blocked from everything else, so a scan cannot wander onto a neighbour's system.
Non-destructive by design
No denial-of-service, no destructive payloads, no persistence, and no extraction of your data beyond the minimum evidence needed to show a finding is real.
Every action is logged, permanently
An immutable record of who authorised what, over what scope, and exactly what was run — available to you, and to your auditor.
Who it's for
Built for lean teams
In-house IT & security
One platform instead of five, with results ranked so a small team can act on what matters without a dedicated analyst.
Developers & engineering
Findings that name the package, version and header to change — in your issue tracker, not a PDF.
Leadership & compliance
A clear risk posture over time and audit-ready evidence for the frameworks your customers ask about.
MSPs & consultancies
Every client in one console, portfolio risk at a glance, and white-labelled reports under your own brand.
Honest about compliance
Evidence an assessor will accept — not a certificate we cannot give
Sentinel maps findings to the frameworks your customers ask about and produces evidence an assessor will accept. It does not — and no scanner can — certify you as compliant. Anyone who tells you otherwise is selling you something.
Pricing
Simple, per month
Priced by the number of assets you monitor. Launch pricing, ex VAT.
Starter
£49/mo
- 3 external assets
- Weekly scans
- Core reports
- 2 users
Business
£149/mo
- 10 external assets
- Daily scheduling
- Web application scanning
- AI summaries · 5 users
Pro
£399/mo
- 30 assets
- Web and API scanning
- 10 AI investigations/mo
- Compliance reports · unlimited users
MSP
£699/mo
- Multi-client portal
- 50+ assets
- White-labelled reports
- Central risk dashboard
One-off AI security assessment of a single web application also available — priced on scope.
Questions
The things buyers actually ask
Is this a real penetration test?
Sentinel performs automated, AI-driven penetration testing: it actively validates whether a weakness is exploitable, not just whether a version looks vulnerable. It runs continuously and catches far more, far more often, than an annual manual test. For the specific cases where a scheme requires a human CREST-style engagement, Sentinel gives that tester a running head start — it does not pretend to replace them.
What does it actually cover?
External and internal network scanning, web application and API testing, cloud misconfiguration checks across AWS, Azure and Google Cloud, continuous attack-surface discovery, and Rapid Response sweeps for emerging threats — managed as one prioritised list.
Is it safe to run against production?
Yes. Testing is non-destructive by design — no denial-of-service, no destructive payloads, no persistence. We extract only the minimum evidence needed to prove a finding is real.
Do I need authorisation to scan?
Always, and Sentinel enforces it. You must prove you control a target — by DNS record or verification file — before any active test can run. Scope is enforced at the network layer, so a scan cannot wander onto anyone else's systems.
How is this different from a vulnerability scanner?
A scanner produces a list. Sentinel ranks that list by real exploitability and exposure, uses AI to validate what actually matters, tells you exactly what to change for your stack, and confirms the fix on re-test. Less noise, more done.
Where is my data hosted?
In the United Kingdom, encrypted in transit and at rest, with an immutable audit log of every action taken on your account.
Can MSPs manage several clients?
Yes. One console covers your whole portfolio, with per-client scope, scheduling and users, a central risk dashboard, and white-labelled reports under your own brand.
Get started with Sentinel
Add your domain, verify you control it, and get your first scan. Priced by the assets you monitor — cancel any time, no long contract.
UK-hosted · authorised testing only · no scan runs until you verify the target