Check whether your live application is exposing data or secrets.
Run narrow, read-only checks for anonymous Supabase access signals, missing Row Level Security signals, and secrets bundled into browser JavaScript. Sentinel reports evidence without writing to your database or storing exposed row contents.
New to APIs? See where Sentinel fits and copy the setup prompt →
- Database
- Anonymous-read probe
- Bundles
- Secret patterns
- Data handling
- No exposed rows stored
Check your own deployed app, right now
Enter your site's URL - we run a real scan and show you exactly what's exposed.
Real scan of your real app - not a demo.
Real detection, not a checklist
Real Supabase RLS exposure detection
Finds your app's real Supabase URL and anon key the same way a browser would, then checks whether Row Level Security actually blocks anonymous reads - not an assumption, a real probe.
Exposed secret detection
Catches a Supabase service_role key, a live Stripe secret key, or an AWS access key that ended up bundled into client-side JS - any one of these is a critical, unambiguous bug.
Continuous monitoring, not a one-time check
A site that's clean today can regress on the next deploy. Sentinel tracks history and flags exactly what changed.
Never harvests your data
Read-only, single-row probes - Sentinel proves a table is exposed and reports its column names, never the actual row contents.
One price. Real monitoring, not a one-time check.
$49/month
- 1 monitored app, weekly scans
- Real RLS/exposed-secret detection
- Real, traceable findings - never fabricated
- No contract - cancel anytime
What this is - and isn't
Sentinel checks two specific, real, well-evidenced failure patterns: Supabase RLS/anon-key exposure and secrets bundled into client-side JS. It is not a general security audit, and a clean scan is never a guarantee your app has no other vulnerabilities. We will never claim otherwise.