Skip to content
RTResilience TechGOVERNANCE · RISK · COMPLIANCE
Menu

Application Security Platform

SentinelCore

Finds

Find vulnerabilities in your code without sending it anywhere

SentinelCore runs application security testing entirely inside your own infrastructure. Source code, scan evidence and findings never leave your perimeter. For regulated enterprises, it is an alternative to hosted AppSec suites that does not require an internet connection.

Request a conversation

The scanning pipeline

Input

What gets scanned

  • Source code repositories
  • Running applications and APIs
  • The dependency tree

Scanning

Four independent engines

  • SAST — Python, JavaScript, Java, C#
  • DAST — API-first, scope-enforced
  • Browser DAST — Chromium, auth variance
  • SCA — NVD, OSV, GitHub Advisory

Correlation

From noise to signal

  • Deterministic fingerprinting removes duplicates
  • Explainable risk score
  • An evidence chain behind every score

Governance

Decision and audit

  • Approval workflow with a two-person rule
  • SLA tracking and emergency stop
  • Append-only audit record

Capabilities

Static analysis (SAST)

Dedicated frontends for Python, JavaScript, Java and C# feed a shared intermediate representation and rule engine, so one rule set produces consistent results across every language.

Dynamic scanning (DAST)

An API-first scanner whose scope enforcement is SSRF-safe — it cannot reach beyond the boundary you define. Supports bearer tokens, API keys, OAuth2 client-credentials, form login and Basic authentication.

Browser-driven DAST

A Chromium crawler that navigates like a real user and compares behaviour across authentication states, surfacing authorisation gaps that request-level scanning misses.

Dependency analysis and vulnerability intelligence

Ingests NVD, OSV and GitHub Security Advisory data. Updates are Ed25519-signed, so integrity is verifiable even in air-gapped installations.

Correlation and explainable risk scoring

Deterministic fingerprinting collapses duplicate findings from different scanners into one. Every risk score carries an evidence chain showing exactly how it was derived.

Governance controls

Approval workflows including a two-person rule, SLA tracking, emergency stop, retention lifecycle, role-based access control, scoped API keys and OIDC single sign-on.

The interface

Captured from a running installation. The scanned target is a deliberately vulnerable sample application built for security testing.

sentinelcore.resiliencetech.com.tr/risks
SentinelCore risk view showing 11 active risk clusters, a severity distribution and a list of critical findings with scores
Risk clusters. Findings from SAST, DAST and attack-surface analysis are correlated into a single score, and the reason behind that score — “3 critical and 6 high account for 82% of the active surface” — is stated on screen.
sentinelcore.resiliencetech.com.tr/findings
SentinelCore findings list showing SAST and hardcoded-secret findings, each located to a file and line number
The findings list. Static analysis and secret detection share one pipeline, and every finding is pinned to a file and line number, so developers are not left hunting for it.

Architecture

  • 21 independent Go services — control plane, scan orchestration, SAST/DAST/browser/correlation workers, auth broker, audit, notification, retention and SLA services
  • PostgreSQL 16 with row-level security for multi-tenant isolation
  • NATS JetStream for work queues and eventing
  • MinIO (S3-compatible) for evidence and artifact storage
  • OPA for policy evaluation
  • Next.js 16 and React 19 management interface

Deployment

Docker Compose for evaluation, Kubernetes and Helm for production. Air-gapped installations are supported.

The other half of the chain

SecureContext

Manage every finding through to closure

SecureContext explore →

Let's discuss what this means for your organisation

Tell us where you stand today and we will work out together where to begin. A first conversation, no commitment.