Ship AI features
without losing sleep

Point Sentrint at the repo behind the app you built with Claude, Gemini or any of the 16 LLM platforms it supports. Its security engine reads every line for four things: hardcoded secrets, database access rules, dependencies and code paths. An AI layer then drops the results that are not really exploitable and writes the fix. Back comes a score out of 100 with a grade, every finding written in plain English, and a fix prompt rewritten for whichever of those platforms built the app. Paste the fix, scan again, and the grade climbs.

Got questions? Ask Gourab Gourab Dasgupta, who answers Sentrint support

Catch what your AI coding agent left exposed before they make headlines. Get ranked findings, with one-click fix prompts tailored to your stack.

Or see a live demo first
Runs on Google Cloud Google for Startups Cloud Program
Single-useInstance DeletedYour clone Read-onlyRepo access
Read the commitments
Fix prompts written for
  • Cursor
  • Windsurf
  • GitHub Copilot
  • Cline
  • Replit
  • Claude Code
  • Lovable
  • Bolt
  • v0
  • Base44
  • DeepSeek
  • Claude
  • ChatGPT
  • Gemini

Why this matters

Standard AI requires your expertise to identify critical vulnerabilities. We at Sentrint help you to bridge the gap and ship secure product.

98%

of 1,072 vibe-coded apps carried at least one security flaw. Twenty-six were clean.

Symbiotic Security
11%

of indie apps ship their database keys in the browser. 20,052 launch URLs scanned.

SupaExplorer
1.5M

API tokens and 35,000 email addresses exposed by one weekend-built AI app.

Wiz Research

What our users are saying

Sentrint helped me detect several key security vulnerabilities in a vibe coded personal agent I had built for myself. The agent’s vulnerabilities had the potential to leak a lot of private and sensitive data, which were quickly resolved. I’m glad I found this product!!

4.7 / 5
Naman
Google, Software engineer

I am a non technical guy doing a project that has the potential to become a good product. I have little knowledge in cybersecurity and don’t have the funds to get a professional. I had mistakenly thought Claude can do things for me. I know better now thanks to a costly mistake. Apparently I have to know what issues to fix and then instruct AI to do it. This is where Sentrint became my go to. It has a lot of rules baked into the product that can check these issues for me. I’m satisfied and I would recommend Sentrint to all non tech people out there who is new to product building.

4.5 / 5
Verified Sentrint user Verified
UX Specialist

Easy to find code vulnerabilities, detect where code lacks and need further improvements.

4.5 / 5
Verified Sentrint user Verified
Data Scientist

01 · Dashboard

Point us at a repo. We grade every one you own.

37.6% more critical flaws after five rounds of letting an AI refine its own code. Shukla et al., 2025

One score for the portfolio, one for each repo. Scan again and a tile tells you what you fixed and what is new.

Score with a trend

Not a snapshot you have to remember to compare against last week.

Fixed versus new

Says whether the work you did actually worked.

The dashboard: a portfolio score of 38 out of 100, open findings, a fixed-versus-new tile reading 12 fixed and 1 new, and a score trend chart.
Dashboard · every repo, one score

02 · Report score

A grade with a score. And the arithmetic behind both.

44% of AI code-generation tasks introduced a known vulnerability. The syntax was right almost every time. Veracode, 2026

Code and packages are graded apart. Every count is shown, so you can check the score instead of trusting it.

Severity, counted

Critical, high, medium and low kept apart. Worst first.

Two grades, not one

Your code on its own. Your dependencies on theirs.

A report header showing grade D, 28 out of 100, with code and dependencies graded separately, and counts of 7 critical, 9 high, 7 medium and 2 low findings.
Report header · real scan, identity redacted

03 · Findings

In English. Not in CVE numbers.

88% of 10,616 publicly leaked AWS keys still authenticated when researchers re-tested them. Truffle Security, 2026

What it is, where it is, and what someone could do with it. Leaked keys get tested, so you know which one to rotate first.

Written for you

One line per flaw, with no jargon to go and look up.

Keys we tested

A dead key and a live key are not the same emergency.

Five critical findings, each with a rule name, an AI-reviewed tag, a redacted file path and a one-line plain English explanation of what the flaw does.
Findings, critical group open

04 · Fix prompt

Copy one prompt. Paste it where the code came from.

Written for Claude, Cursor, Lovable, ChatGPT and Gemini. Ordered by what is exploitable now, and told to change nothing else.

One per platform

Phrased for whichever assistant you use, 16 in all.

Nothing else touched

Every signature kept, no refactor, no check weakened.

A fix prompt panel with a tab per AI platform and a terminal block: 25 vulnerabilities, 19 critical first, and a section saying which leaked credentials only a human can rotate.
Fix prompt · copy, paste, rescan

05 · Badge

One line in your README. It reads the live grade.

Ship something worse and it says so on its own. It stops at C — below that it reads unrated.

Always current

Reads the grade at load. There is nothing to update by hand.

Honest by design

No D, no F. A bad grade is withheld, never dressed up.

Three passes over your code, only the first one decides

  1. 01 No AI

    The engine finds it

    • Fixed rules, over your code and your lockfiles
    • A rule matches or it does not
    • Nothing here can be talked into a finding
  2. 02 AI

    A second read cuts the noise

    • Every critical and high finding, read a second time
    • Cannot invent one. Cannot take one off your report
    • Decides what earns a place in the fix prompt, and says how many it held back
  3. 03 AI

    The fix gets written

    • One prompt, ordered worst first
    • Written for whichever tool built your app
    • Carries its own limits: change these lines, keep every signature
Where it runs

All three passes happen inside one single-use Google Cloud Run job, created for your scan and destroyed when it ends.

What happens to your code

  • Built to DPDP Act 2023

    India's data-protection law, and the one we answer to. Consent you can withdraw, a breach clock, and a named officer on the hook.

    How we meet it
  • Aligned with GDPR data rights

    Your access, correction and deletion rights, honoured wherever you live. We claim no certificate and no EU representative, only the substance.

    What aligned means
  • Payments PCI DSS via Dodo

    Card entry is handled entirely by our payment processor, Dodo. Those details never reach, and are never stored on, a Sentrint server.

    Where money goes

Subprocessor directory

  • Cloudflare DNS, CDN and the firewall in front
  • GitHub Sign-in, and reading the repo you pick
  • Upstash Queues the scan, holds the rate limits
  • Google Cloud Runs the app, the scan job and our mail
  • OpenRouter Carries the snippet to the model
  • Anthropic Writes the fix, zero-retention endpoints
  • Supabase Holds your account and your findings
  • Dodo Payments Takes payment as merchant of record
  • Sentry Crash reports, with identifiers off
  • PostHog Which pages get used, no email or IP

What it costs

35% off every paid plan, applied at checkout. No code to enter. Ends 30 September

Top-up

Buy a pack, scan when you need to. No subscription and no renewal date.

₹499$6 ₹324.35$3.90one time

6 scans in a pack.

Buy 6 scans
  • 6 deep scans, credits never expire
  • Every finding, ranked by what to fix first
  • Copy-paste fix prompt for 16 AI tools
  • Per-finding AI fix & false-positive review
  • Score, grade and a badge for your repo
  • One-time purchase, not a subscription
Most popular

Founder

For anyone shipping every week. Scan on every change instead of rationing them.

Yearly 2 months free
₹1,499$19 ₹974.35$12.35a month ₹14,990$190 ₹9,743.50$123.50 a year

Cancel any time, from Settings.

Billed once a year.

Subscribe Subscribe
  • 36 scans a month, everything in Top-up
  • 44% off top-up packs when you run out
  • CSV & JSON export of findings
  • Dependency inventory & CycloneDX SBOM
  • MCP server Soon
  • REST API Soon

Services

External exposure intelligence for people and organizations. Hands-on work, not automation or software. Every project is scoped on a call before a quote is provided.

from ₹12,000$150

₹4,000$50 a day, 3-day minimum.

Coming soon

  • Digital Footprint Assessment
  • Breach & Credential Exposure Assessment

Free plan One scan every calendar month, not every thirty days. Your GitHub account needs to be 30 days old to claim it. 1 scan per month

  • Score, grade and badge
  • Every finding, in full
  • The fix prompt
Free scan ₹0$0

Compare everything

Find out what your app is leaking

Listed with