48 checks across security, performance, SEO, accessibility and your legal pages. 18 of them run free — no account, no card.
Websites audited so far
Follows every anchor on the crawled pages and reports 404s, server errors and redirect chains.
Title, meta, OG, Twitter cards, canonical, robots.txt, sitemap, structured data, hreflang.
Capture console errors, unhandled rejections, and scan all network traffic for leaked secrets.
CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy — quality-graded.
Read-only probes on query params, form fields and headers. We compare responses; nothing is written to your database.
CSRF detection, weak password acceptance, username enumeration, brute-force lockout.
axe-core WCAG 2.1 AA — contrast, ARIA, focus order, tap targets, mobile viewport.
LCP, CLS, TBT, FCP, Speed Index — Core Web Vitals with actionable recommendations.
Findings stream back over SSE while the scan is still going, so you see each check land instead of watching a progress bar.
Network probes run in parallel; browser tests share a single Playwright instance.
Private IP ranges blocked. Scan IDs are UUIDs. Reports from scans run without an account are deleted after 24 hours.
Everything you'd want to know before running your first scan.
Every scan runs our own engine — Playwright, Lighthouse, and axe-core — making real requests against your site live. There is no third-party scanning API involved and no pre-written report; every finding comes from that specific run.
A one-page site is usually done in about a minute. Larger sites take longer, because every crawled page is tested individually rather than just the homepage. Each check runs on its own budget — 25 seconds, or 60 for the Lighthouse run — so one slow check cannot stall the rest of the scan.
The crawl discovers up to 12 pages via your sitemap and internal links, not just the URL you submit — so findings can point to any page across your site, not only the entry point.
No. A free scan runs instantly with no signup — just enter your URL and get your report.
Yes. Every check is non-destructive: no real exploit payloads that write data, no spamming your login forms, no creating accounts. We inspect responses and behavior rather than attacking your site.
Only scan sites you own or are explicitly authorized to test. SENTINEL AI is built for legitimate QA and security auditing, not for probing sites you don’t control.
It depends on how you scanned. Without an account, a report is deleted automatically after 24 hours. With a free account, we keep your 3 most recent reports for 30 days. Reports you unlock or run on Pro are kept until you delete them — you can remove any report yourself from your dashboard at any time.