Find the gaps in your firewall before attackers do.

SENTRY helps IT teams and CISOs find and fix firewall weaknesses. Start today with an expert-validated assessment. An on-premise version for your own infrastructure is coming soon.

Why SENTRY

Your firewall is only as strong as its rules. Do you know what they really allow?

Firewall configurations grow for years: temporary exceptions that stay forever, overly broad "any" rules, forgotten objects, missing segmentation. Each one is a door an attacker can use to move deeper into your network. Most teams don't have the time to review hundreds of rules by hand, so these gaps stay hidden until an incident or an audit finds them.

An attack chain across a segmented network mapped to MITRE ATT&CK tactics — initial access, execution, lateral movement, exfiltration — with network segmentation shown blocking lateral movement and a countermeasure per stage
01Hidden exposure

See your network as it really is.

SENTRY rebuilds your topology from the configuration file. You see which zones can reach each other, not just what the diagram says.

02Uncertain risk

Know which rules are dangerous and why.

Every weak or risky rule is tied to the exact line in your configuration and backed by CIS Benchmarks. Each finding is confirmed by a certified expert, so you get no guesswork and no AI hallucinations.

03Too much to fix

Fix what matters first.

Realistic MITRE ATT&CK attack paths show how an intruder could move through your network. Remediation steps are prioritised by real impact, so your team starts where it counts.

Firewall Configuration Assessment

From one configuration file to an audit-ready report, with no installation, no agents and no device access.

  1. 1

    Send a sanitised, encrypted export

    Rules, zones, objects and routes only. No accounts, passwords or keys. Transferred encrypted over a secure channel.

  2. 2

    Deterministic analysis

    Rule-based checks parse every rule, object and route. The results are repeatable and traceable to the exact line.

  3. 3

    AI-assisted risk analysis

    AI connects the findings into realistic attack paths and explains the business risk. It runs on-premise.

  4. 4

    Expert validation and report

    A certified security expert confirms every finding. You receive a PDF/DOCX report with severity-ranked fixes.

  5. 5

    Data deleted

    When the project is closed, all your data is permanently deleted, and we confirm it in writing.

What your assessment includes

Network reconstruction

Zones, interfaces, VLANs, NAT, routing and interzone connections rebuilt from configuration alone.

CIS Benchmark cited firewall rule assessment

Every gap cited to the specific benchmark section — ready for auditors and boards.

MITRE ATT&CK attack scenarios

Realistic attack paths derived from your actual weaknesses, with countermeasures per step.

Expert sign-off

A certified network security expert verifies every finding — never unreviewed machine output.

How you can use SENTRY

Managed service

Available now
  • Supported - FortiGate, PaloAlto
  • You send a sanitised, encrypted export
  • Analysis on HCSECURITY's secure servers in Latvia
  • Expert validation included
  • Data deleted after the project
Request an assessment

On-premise

Coming 2027
  • SENTRY runs inside your infrastructure
  • Your data never leaves your network
  • No internet dependency
  • Continuous, on-demand analysis
Join the early access list

SENTRY, module by module

One product that grows with your security programme. Firewall Configuration Assessment is available today — further modules follow on the same principles: secure, available, and context-aware.

Available now

Firewall Configuration Assessment

Available today. AI-powered assessment of your firewall configuration — topology reconstruction, a CIS-cited rule assessment, and MITRE ATT&CK attack paths.

Planned

Ask SENTRY

Talk to SENTRY in plain language — ask questions, explore your network security posture, and get the knowledge you need, explained in human terms.

Planned

Compliance-Driven Hardening

Findings mapped to CIS, NIS2, and ISO 27001 controls — ready for auditors, boards, and regulators.

Planned

Security Operations Assistance

AI that augments your IT and network security teams — triaging findings and prioritising what to fix first.