Sentris

Sentris

Repo-deep security scanner for AI-built Supabase apps

U
@urtiluca
Published on Sep 14, 2026
Visit site
1 PeerPush
🚀
Awarded
Just Launched
PeerPush

Details

Follow on
@urti_luca
Pricing
Freemium
Platforms
Web

Discovery signals

How AI and people discover Sentris on PeerPush

AI-readyAI-readyWhether this product carries the structured data - use cases, audiences, platforms - that lets AI match it to the right questions.
Structured

Described for AI to match

Described for AI with use cases, audiences, platforms and pricing so assistants can match it to the right questions.
Discoverable nowDiscoverable nowWhether this product is queryable through the PeerPush API and MCP right now.
Live

Via the PeerPush API and MCP

Queryable through the PeerPush API, MCP and semantic search from day one.

About Sentris

Sentris is a security scanner for Supabase apps built with AI — Lovable, Bolt, Cursor, Replit, v0, Claude Code. It connects to your GitHub repository and reads the code: migrations, route handlers, config, dependencies. That is the whole difference. Every other scanner in this category probes your live URL, which means it can only report what your server already hands a stranger. Sentris reads the SQL, so it reports the cause — "this table has no RLS policy, here is the line in the migration" — instead of the symptom in a response. WHAT IT FINDS 20 deterministic checks plus 5 AI checks, including: • Tables shipping without Row Level Security, and policies that grant using (true) • service_role, Stripe and AI-provider keys in your source or your client bundle • Committed .env files and private keys • Public storage buckets, and uploads with no size or type limit • API routes that take a caller-supplied id with no auth check • Mass assignment — routes writing the request body straight into a table • security definer functions that never check who called them • Passwords hashed with MD5/SHA, or compared with === • Sign-in, sign-up, reset and mail-sending endpoints with nothing counting the attempts • SQL and PostgREST filter injection, XSS sinks, missing security headers, insecure session cookies, vulnerable dependencies WHAT MAKES IT DIFFERENT Repo-deep, not URL-only. The findings that matter most in a Supabase app live in the SQL and the route handlers. A black-box scanner never sees either. The precision is published, not claimed. Zero false positives and zero misses across 38 planted findings in 11 repositories — the full table, the commit it was measured on and the command to reproduce it are at sentris.dev/precision. Nobody else in this category publishes theirs. The clean reference app must return zero findings before any new rule ships. Proof, not warnings. Every finding carries the file and line it came from, masked evidence, and a copy-paste fix. Each one is labelled confirmed or potential, so an inference never arrives dressed as a breach. It confirms instead of guessing. On a domain you have verified, Sentris asks your running system: it reads one row from a table the repo says has no RLS, or fetches one object from a bucket the repo says is public. One row, read-only, never exploited — and the evidence records the row count, never the row. It works where you already are. An MCP server for Claude Code, Cursor and Windsurf, so you scan and fix without leaving the editor. SARIF 2.1.0 export into the GitHub Security tab. A pull-request gate. An opt-in PR that adds the migration closing a finding — off by default for every repository. WHAT YOU GET BACK A scan finishes in under three minutes. Then it keeps running: nightly or weekly re-scans that email you only when a finding is new, never the same one twice. Fix something and re-scan to watch it close. A clean scan on a verified domain earns an embeddable trust badge that is recomputed on every request, so it can never show green for a scan that has since gone red. For context on the problem: across 2,144 AI-built Supabase repositories we scanned publicly on GitHub, 40.6% carried a critical exposure. HONEST LIMITS This is not a penetration test, not a certification, and it carries no warranty. It reports reproducible findings at a point in time. Server infrastructure, DDoS, TLS depth and business logic beyond access control are out of scope — and the report says so on its face rather than in a footnote. Your code is never cloned or stored; files are read during the scan and discarded when it ends. Secrets are masked before anything is written down. PRICING Starter $19/mo (1 app, weekly monitoring) · Pro $49/mo (5 apps, nightly) · Team $99/mo (unlimited, nightly). Annual is 20% off. Scanning is free and needs no login — the findings are what you subscribe for. There is no free plan and no trial, which is stated before you scan rather than after.

Screenshots

Screenshot 1 of Sentris

Reviews (0)

No reviews yet. Be the first to rate this product!

Comments (0)

No comments yet. Be the first to share your thoughts!