Sentinel-Hub is the security testing hub inside Agentic Testari (not the domain).
Agentic Testari is the platform. Sentinel-Hub is its security testing hub — agents built for attack and security testing. Attackers already use agentic browsers; we test with the same class of tool under permission. Starts with the public façade; deeper work only when you authorize it — development / staging only (never production).
The threat model changed. Adversaries no longer rely only on a person with Chrome — or scripts that merely drive a human browser. They run agentic browsers, autonomous agents, and coordinated swarms of agents: automated, scaled, and far more powerful.
A human session is one pair of hands. An agentic browser reconnoiters, chains steps, and presses public surfaces and login edges at machine speed.
It is not only one agent. A swarm of agents can parallelize recon, probing, social engineering, and exploitation paths. Classic automation still helps attackers; agent swarms go further — more autonomy, more paths, more pressure on the façade customers and partners see.
Sentinel-Hub is built for this shift: authorized testing of what faces the internet, and deeper work only under RoE — with agent-class tooling, not checkbox theater.
We test with ParviSight — our agentic browser, the same class of tool attackers already use — under scope, permission, evidence, and ranked findings you can take to the board.
We are also preparing ourselves — and our clients — for attacks by a single agent or a swarm of agents: detection, defense, accountability (AWP + PayBot), and authorized counter-testing before production pays the price.
We're ahead: Sentinel-Hub finds vulnerabilities with ParviSight — agentic tooling of the same class attackers already use, including multi-agent pressure — under RoE, with permission. We train for agent and swarm attacks, not only human browsers.
When an AI agent acts, a log line or a chat summary is not enough for real audit. AWP (Agent Witness Protocol) turns material agent actions into portable, cryptographically signed receipts you can verify offline — without trusting the server that produced them.
The agent (or human+agent path) performs a scoped action: recon step, probe, authorize, export. Policy / RoE can gate it first.
Intent, authorization, and artifacts are hashed. A signed envelope (DSSE + in-toto style) binds the record. Inclusion in a Merkle log + checkpoint makes tampering visible.
You get a JSON receipt (customer-keyed path). It travels with the engagement pack — not locked inside a vendor SIEM you must “just trust”.
Anyone with the receipt can verify signature, structure, and inclusion offline. PASS means integrity-since-witness of the record — perfect for auditors who need evidence, not storytelling.
Honesty boundary: verify proves the witnessed record is consistent and unaltered since sealed. It does not magically invent actions that were never instrumented — that is why we instrument material steps.
“The agent said it scanned X.” Chat logs, screenshots, or a vendor dashboard you cannot independently check. If the log is edited or incomplete, you may never know. Bad for board, insurer, regulator, or incident review.
“Here is a signed receipt of what was authorized and recorded, with offline verify.” You know exactly what entered the ledger — and you can prove integrity without trusting us or living inside our stack. Built for audit.
PayBot pairs with AWP when value or policy gates matter (authorize / meter / prove-after). Sentinel engagements are designed so agent steps are accountable — not “trust me, the agent did it.”
Public risk is only the front door. If we find cracks there, real attackers go next to login portals, customer apps, and internal systems. Sentinel-Hub — Agentic Testari's security testing hub with attack and security agents — covers both layers, with hard rules about where deep / offensive work is allowed.
Authorized, not cowboy. We may demo public L1–L3 when selling. When you buy, you sign a service contract that includes RoE — even if we already ran a public test. Offensive modes only when you request and authorize them in that contract.
Baseline on what faces the internet. Optional deep work on login, app flows, and intranet-style surfaces that matter once a user is in.
Offensive testing is never self-started. It happens only when the client asks for it, with written OK, on the environment they designate — not as cold public outreach.
Start shallow. Go deeper only when you say so — and only where it is safe.
What you saw in early public assessments is the baseline — the necessary first pass. Sentinel-Hub (inside Agentic Testari) is built so the story does not stop at the marketing site.
The “preliminary” layer: everything facing the open internet without a customer login. Fast, non-destructive, and enough to show real brand / edge risk.
If the public layer is weak, attackers do not stop. Deep work asks: what happens on the login, the company app, and intranet-style systems your users actually use?
Public pages protect reputation. Login and product systems protect money, data, and trust. Sentinel shows what is visible from the street and — when you authorize it — how hard a serious attacker could push on a safe copy of your real system (dev/staging), so you fix before production pays the price.
Baseline = what any stranger can see. Deep = what we can prove on your dev environment, with your written OK — including offensive depth if you want the full story.
RoE = Rules of Engagement inside a signed service contract. We may run L1–L3 public assessments to show value when selling. When you purchase — even a light L1/L2/L3, and even if a public test was already done — you sign a Service Agreement that always includes RoE (Schedule A). That protects both sides for delivery, payment, and follow-on work. The deeper the purchase (especially Offensive), the more detailed the RoE. Offensive techniques only if the signed contract authorizes them before those methods run.
Pulse (€2,500 one-time) = one public website, L3 Max, automated. Unlimited (€1,995/month paid yearly · €23,940/year + VAT) = unlimited use with your own AI API. Behind login / SaaS / CRM / intranet = planning + RoE + custom quote. Offensive is separate and quote-only.
So you know this is not a faceless scan vendor — it is built and led by someone who has spent a career finding what breaks in systems that cannot afford to break.
Founder · FriendlyAI Oy · Agentic Testari (Sentinel-Hub) · Finland
15+ years in enterprise QA and software testing — banking, insurance, and API-heavy platforms. ISTQB-minded craft: methodical, evidence-based, no theater.
Career path includes long enterprise testing work in Finland (including banking environments such as Handelsbanken / S-Pankki–class systems via Samlink, and API testing for insurance clients via Tieto/Tietoevry). Tools of the trade: exploratory & manual depth, REST/SOAP, Postman, Robot Framework + Python — plus agentic AI to scale what a senior tester already knows how to see.
Sentinel-Hub is the security testing hub of Agentic Testari — attack and security agents that turn that experience into product: authorized assessments, plain-language severity, and a fix path you can take to the board.
Finnish company · EU data mindset · Built by a practitioner, not a pure marketing shop.
Required: name, work email, public domain to test, and phone. In notes, say if you need a focused test or a broad vulnerability-gap review. We never run offensive/destructive work on production without written RoE.
Contact (anti-spam inbox): [email protected] · Use case
After each fix round, request a re-test. We re-run the same package and email a new HTML + PDF. The loop continues until all HIGH/MEDIUM vulnerability gaps are closed.