Understand risk. Act with evidence.
Security findings you can act on. Source code that stays yours.
DVSentry tests your repositories, web apps and APIs, cloud accounts and AI systems, correlates what it finds, and shows the evidence behind every risk.
- Production scanners run in isolated containers without network access
- Repository tokens are single-use unless you choose to keep them encrypted
- Web tests run only on domains you prove you own
Demo data — no repository connected
Sample security assessment
Security score81/ 100
3 illustrative risks requiring attention
- Why this risk
- Attack path
- Remediation
Evidence preview
Illustrative structure only. This sample is not cryptographically signed.
{"sample": true, "evidence": "normalized finding", "signature": "preview only"}
One connected view
Every layer you ship, assessed in one place.
- Code
- Vulnerable dependencies, code weaknesses, committed secrets and infrastructure as code, with a software bill of materials.
- Web & API
- Passive checks, TLS and header grading, bounded active probes and API schema tests on verified targets.
- Network
- Port discovery and safe OWASP canaries against the hosts you are authorized to test.
- Cloud
- Posture scans of AWS, Azure and Google Cloud accounts with Prowler, using a read-only identity, mapped to CIS, SOC 2 and ISO 27001.
- AI Security
- Prompt injection, data leakage, retrieval poisoning and agent tool misuse, mapped to the OWASP LLM Top 10.
- Resilience
- Controlled fault experiments on development targets, with approval, automatic abort and an emergency stop.
How it works
From connection to proof.
- Connect
A repository, application, cloud account or API.
- Test
Run the checks you are authorized to run.
- Prioritize
Deduplicated risks, ranked by exploitability and reachability.
- Fix
Remediation guidance your developers apply themselves.
- Prove
Export reports, SBOMs and signed evidence.
Privacy-first security
Your code deserves a clear boundary.
Repository scanning is designed to run without sending source code to third-party AI services. Optional AI integrations operate according to the configured provider and deployment policy.
- Isolated executionProduction scanner containers run as a non-root user with no network, a read-only filesystem and bounded resources.
- Controlled credentialsA repository token is used for one checkout by default. Keeping it for ten minutes, or in the encrypted vault, is your choice.
- Verified scopeWeb and network testing starts only after you prove domain ownership.
- Signed evidenceReports can be exported with a signature you can verify later.
Plans
Start free. Upgrade when your security program grows.
Every price and limit below comes from the DVSentry plan catalog.
Serious security, accessible by design.
DVSentry started from a simple idea: developers should not need to build and maintain an entire DevSecOps stack just to understand whether their software is secure.
Make your first connection.
Create an account, verify your email, then choose a repository assessment. Web testing requires ownership verification and explicit authorization.