3Stone Sentinel

Check whether your live application is exposing data or secrets.

Run narrow, read-only checks for anonymous Supabase access signals, missing Row Level Security signals, and secrets bundled into browser JavaScript. Sentinel reports evidence without writing to your database or storing exposed row contents.

New to APIs? See where Sentinel fits and copy the setup prompt →

Real, read-only probes - never writes or deletesNo credit card for the free scan$49/mo flat, cancel anytime
Exposure checkObserve without harvesting
Live
Database
Anonymous-read probe
Bundles
Secret patterns
Data handling
No exposed rows stored
Free Scan

Check your own deployed app, right now

Enter your site's URL - we run a real scan and show you exactly what's exposed.

What's Included

Real detection, not a checklist

Real Supabase RLS exposure detection

Finds your app's real Supabase URL and anon key the same way a browser would, then checks whether Row Level Security actually blocks anonymous reads - not an assumption, a real probe.

Exposed secret detection

Catches a Supabase service_role key, a live Stripe secret key, or an AWS access key that ended up bundled into client-side JS - any one of these is a critical, unambiguous bug.

Continuous monitoring, not a one-time check

A site that's clean today can regress on the next deploy. Sentinel tracks history and flags exactly what changed.

Never harvests your data

Read-only, single-row probes - Sentinel proves a table is exposed and reports its column names, never the actual row contents.

Pricing

One price. Real monitoring, not a one-time check.

$49/month

  • 1 monitored app, weekly scans
  • Real RLS/exposed-secret detection
  • Real, traceable findings - never fabricated
  • No contract - cancel anytime
Honest About Scope

What this is - and isn't

Sentinel checks two specific, real, well-evidenced failure patterns: Supabase RLS/anon-key exposure and secrets bundled into client-side JS. It is not a general security audit, and a clean scan is never a guarantee your app has no other vulnerabilities. We will never claim otherwise.