Agentic Testari · security testing hub

Sentinel-Hub is the security testing hub inside Agentic Testari (not the domain).

Security that attacks with permission — and explains risk in plain language.

Agentic Testari is the platform. Sentinel-Hub is its security testing hub — agents built for attack and security testing. Attackers already use agentic browsers; we test with the same class of tool under permission. Starts with the public façade; deeper work only when you authorize it — development / staging only (never production).

What you walk away with

// three public depths + optional offensive L1: public surface (baseline) L2: public surface (full non-destructive) L3: deep public (max depth on public pages) not offensive · public only OFFENSIVE (list on page): only client request + signed service contract (RoE included) + environment the client chooses never self-started as sales outreach out: ranked report + fix + retest
RoEfirst
Rankseverity
Fixpath
Rules of engagement Public baseline Deep public (L3) · not offensive Remediation kit
Why now · agentic threat

Attackers won't stop at a human browser

The threat model changed. Adversaries no longer rely only on a person with Chrome — or scripts that merely drive a human browser. They run agentic browsers, autonomous agents, and coordinated swarms of agents: automated, scaled, and far more powerful.

Beyond the human browser

A human session is one pair of hands. An agentic browser reconnoiters, chains steps, and presses public surfaces and login edges at machine speed.

Agent attacks — and swarms

It is not only one agent. A swarm of agents can parallelize recon, probing, social engineering, and exploitation paths. Classic automation still helps attackers; agent swarms go further — more autonomy, more paths, more pressure on the façade customers and partners see.

Why Agentic Testari exists

Sentinel-Hub is built for this shift: authorized testing of what faces the internet, and deeper work only under RoE — with agent-class tooling, not checkbox theater.

Same class of tool. On defense.

We test with ParviSight — our agentic browser, the same class of tool attackers already use — under scope, permission, evidence, and ranked findings you can take to the board.

What we are preparing for

We are also preparing ourselves — and our clients — for attacks by a single agent or a swarm of agents: detection, defense, accountability (AWP + PayBot), and authorized counter-testing before production pays the price.

We're ahead: Sentinel-Hub finds vulnerabilities with ParviSight — agentic tooling of the same class attackers already use, including multi-agent pressure — under RoE, with permission. We train for agent and swarm attacks, not only human browsers.

Agent Witness Protocol · cryptographic proof

Don't trust the agent blindly — prove what it did

When an AI agent acts, a log line or a chat summary is not enough for real audit. AWP (Agent Witness Protocol) turns material agent actions into portable, cryptographically signed receipts you can verify offline — without trusting the server that produced them.

01 · ACT

Agent acts under policy

The agent (or human+agent path) performs a scoped action: recon step, probe, authorize, export. Policy / RoE can gate it first.

02 · HASH & SIGN

Cryptographic seal

Intent, authorization, and artifacts are hashed. A signed envelope (DSSE + in-toto style) binds the record. Inclusion in a Merkle log + checkpoint makes tampering visible.

03 · RECEIPT

Portable witness receipt

You get a JSON receipt (customer-keyed path). It travels with the engagement pack — not locked inside a vendor SIEM you must “just trust”.

04 · VERIFY

Offline verification

Anyone with the receipt can verify signature, structure, and inclusion offline. PASS means integrity-since-witness of the record — perfect for auditors who need evidence, not storytelling.

npx --yes agent-witness-protocol@0.2.1 -- awp verify receipt.json → RESULT: PASS (or FAIL naming the broken layer)

Honesty boundary: verify proves the witnessed record is consistent and unaltered since sealed. It does not magically invent actions that were never instrumented — that is why we instrument material steps.

Blind trust

“The agent said it scanned X.” Chat logs, screenshots, or a vendor dashboard you cannot independently check. If the log is edited or incomplete, you may never know. Bad for board, insurer, regulator, or incident review.

Cryptographic proof (AWP)

“Here is a signed receipt of what was authorized and recorded, with offline verify.” You know exactly what entered the ledger — and you can prove integrity without trusting us or living inside our stack. Built for audit.

PayBot pairs with AWP when value or policy gates matter (authorize / meter / prove-after). Sentinel engagements are designed so agent steps are accountable — not “trust me, the agent did it.”

Why Sentinel-Hub (security hub)

Public risk is only the front door. If we find cracks there, real attackers go next to login portals, customer apps, and internal systems. Sentinel-Hub — Agentic Testari's security testing hub with attack and security agents — covers both layers, with hard rules about where deep / offensive work is allowed.

01

Authorized, not cowboy

Authorized, not cowboy. We may demo public L1–L3 when selling. When you buy, you sign a service contract that includes RoE — even if we already ran a public test. Offensive modes only when you request and authorize them in that contract.

02

Public + behind the login

Baseline on what faces the internet. Optional deep work on login, app flows, and intranet-style surfaces that matter once a user is in.

03

Offensive only on request

Offensive testing is never self-started. It happens only when the client asks for it, with written OK, on the environment they designate — not as cold public outreach.

How it works

Start shallow. Go deeper only when you say so — and only where it is safe.

1. RoE & scope
Public only, or public + deep on named dev/staging. Written before probes.
2. Public baseline
DNS, mail auth, headers, public APIs, exposed gateways — what any stranger can see.
3. Decide depth
If the façade is weak, we map what that implies for login, apps, and internal-style systems.
4. Deep (optional)
Authorized testing on dev/staging: login, app logic, offensive paths if approved. Never prod destroy.
5. Report & fix
HIGH MED
Ranked findings + remediation + retest.

What a package includes

What you saw in early public assessments is the baseline — the necessary first pass. Sentinel-Hub (inside Agentic Testari) is built so the story does not stop at the marketing site.

BASELINE Public surface

The “preliminary” layer: everything facing the open internet without a customer login. Fast, non-destructive, and enough to show real brand / edge risk.

  • DNS, mail auth (SPF / DKIM / DMARC / CAA)
  • Security headers, TLS, CSP quality
  • Public APIs / CMS oversharing
  • Exposed identity gateways (when present)
  • Executive ranking + findings register
  • Priority remediation (customer-style)

DEEP Behind the front door

If the public layer is weak, attackers do not stop. Deep work asks: what happens on the login, the company app, and intranet-style systems your users actually use?

  • Authenticated / portal / SSO-style surfaces (in scope)
  • Business application flows your customers depend on
  • Internal-style or staff systems when authorized
  • Optional very deep & offensive testing
  • Only on development or staging you name
  • Never destructive / offensive against production

Why companies that care about security buy both

Public pages protect reputation. Login and product systems protect money, data, and trust. Sentinel shows what is visible from the street and — when you authorize it — how hard a serious attacker could push on a safe copy of your real system (dev/staging), so you fix before production pays the price.

Baseline = what any stranger can see. Deep = what we can prove on your dev environment, with your written OK — including offensive depth if you want the full story.

Hard rules (always)

  • Paid work: signed service contract with RoE for every package (L1–L3 and Offensive)
  • No offensive work without the client asking for it in writing
  • Offensive only on the environment the client designates
  • No confidential client details published without your OK
  • No “guaranteed zero risk after one pass” claims

What is RoE?

RoE = Rules of Engagement inside a signed service contract. We may run L1–L3 public assessments to show value when selling. When you purchase — even a light L1/L2/L3, and even if a public test was already done — you sign a Service Agreement that always includes RoE (Schedule A). That protects both sides for delivery, payment, and follow-on work. The deeper the purchase (especially Offensive), the more detailed the RoE. Offensive techniques only if the signed contract authorizes them before those methods run.

  • Sales L1–L3 public demo: we can run without your signature
  • Purchase of any package: signed service contract + RoE always — even if the public test already ran
  • Light purchase → short RoE; deep/Offensive → every target and method listed
  • Offensive never as cold outreach; methods default off until you authorize them in the contract

Engagements

Pulse (€2,500 one-time) = one public website, L3 Max, automated. Unlimited (€1,995/month paid yearly · €23,940/year) = unlimited use with your own AI API. Behind login / SaaS / CRM / intranet = planning + RoE + custom quote. Offensive is separate and quote-only.

Website Surface Pulse

L3 Max · Public website only · automated · Sentinel Hub
€2,500 VAT only when due. Extra-EU company (Brazil CNPJ or any other company register): usually no VAT. EU depends on country + VAT number. One-time / one public website.
  • In scope: public internet pages only (no login)
  • Depth: L3 Max — full force, non-destructive public surface
  • Out of scope: SaaS/CRM behind login, intranet, authenticated user abuse
  • Why this price: automated agent pipeline after you pay
  • Ranked findings + plain-language fix guide
  • HTML + PDF report delivery
  • Re-test after you fix — until HIGH/MEDIUM are clean
  • No CMS/login planning in this SKU (that is a quote)
Purchase Surface Pulse Or ask a question

Behind-login / SaaS / CRM / intranet

Quote · planning required · not automatic checkout
Quote / engagement · hours & scope
  • In scope only after plan: login, SaaS, CRM, intranet, authenticated abuse paths
  • Written RoE + scope lock (prod = never destructive without explicit OK)
  • Human/agent planning of the system and attack path before run
  • Price from hours + complexity — we quote after scoping (not a fixed band)
  • Ranked findings + business impact + fix guidance
  • Retest path agreed in the engagement plan
  • Agents/human estimate effort after we see what you want tested
  • Book a scoping call — we quote after we see the system
  • Offensive methods only if you request them in the RoE
Book Sentinel

Offensive (signed contract + RoE)

Client request · signed contract with RoE · environment you choose
Quote / program
  • ⚠️ These are OFFENSIVE — never cold outreach / never self-started
  • Only when you ask + signed service contract (RoE included)
  • Only on the environment you designate
  • Exploits & mutating PoCs (prove impact with your OK)
  • Authenticated testing (login / portal / SSO with test users you give)
  • Password spray, credential stuffing, brute force (if RoE allows)
  • Business logic abuse, IDOR/BOLA with auth sessions
  • Heavy fuzz / active attack paths (never uncontrolled DoS unless agreed)
  • Cloud / identity deep (Azure·Entra IAM) when authorized
  • Internal-style systems, APIs behind login, staff tools
  • Mobile binary / lab techniques when in scope
  • Full report + fix path + retest after patches
  • AWP + PayBotFin log every agent step for accountability
Request offensive (with signed RoE contract)

Who am I

So you know this is not a faceless scan vendor — it is built and led by someone who has spent a career finding what breaks in systems that cannot afford to break.

Renata Baldissara-Kunnela

Renata Baldissara-Kunnela

Founder · FriendlyAI Oy · Agentic Testari (Sentinel-Hub) · Finland

15+ years in enterprise QA and software testing — banking, insurance, and API-heavy platforms. ISTQB-minded craft: methodical, evidence-based, no theater.

Career path includes long enterprise testing work in Finland (including banking environments such as Handelsbanken / S-Pankki–class systems via Samlink, and API testing for insurance clients via Tieto/Tietoevry). Tools of the trade: exploratory & manual depth, REST/SOAP, Postman, Robot Framework + Python — plus agentic AI to scale what a senior tester already knows how to see.

Sentinel-Hub is the security testing hub of Agentic Testari — attack and security agents that turn that experience into product: authorized assessments, plain-language severity, and a fix path you can take to the board.

Finnish company · EU data mindset · Built by a practitioner, not a pure marketing shop.

Credibility, short

  • ✓ 15+ years enterprise QA
  • ✓ Banking & insurance systems
  • ✓ API / integration testing depth
  • ✓ Based in Finland (EU)
  • ✓ FriendlyAI Oy · Agentic Testari

Book a Sentinel assessment

Required: name, work email, public domain to test, and phone. In notes, say if you need a focused test or a broad vulnerability-gap review. We never run offensive/destructive work on production without written RoE.

Contact (anti-spam inbox): [email protected] · Use case

Fixed some gaps? Request a re-test

After each fix round, request a re-test. We re-run the same package and email a new HTML + PDF. The loop continues until all HIGH/MEDIUM vulnerability gaps are closed.