Security
Built for the risks of AI agents
Agents that browse for you open a new kind of attack: the web itself can talk to them. Sentinel is designed around that fact. Every step is checked before it runs.
Web pages that give the agent orders (prompt injection)
Researchers have shown agentic browsers following hidden text on a page: leaking one-time codes, buying on scam shops, opening your email.
What Sentinel does
Page text is wrapped as data and the agent is told it is never an instruction. Every page is scanned for text aimed at AI agents, including hidden text and comments. If found, the content is withheld from the agent and the step is marked red in your timeline.
An agent doing more than you meant
A general agent with your browser can click anything, anywhere.
What Sentinel does
Each agent has a skill tree. It can only use skills that are switched on, and risky skills stay locked until you unlock the skill above them. The check runs on our servers, so the AI cannot talk its way around it.
Agents acting without asking
An agent that never stops to ask can do a lot before you notice.
What Sentinel does
By default Sentinel agents act on your task without approval cards, including sending email, writing to connected apps and placing phone calls. You stay in control by stopping: Stop on each agent, Stop all, and a kill switch that also cancels scheduled and repeating calls. If you want a check first, set any skill to Ask; that approval is then tied to the exact step and the server refuses anything that does not match word for word.
Spending, sending and deleting
Irreversible actions do the most damage.
What Sentinel does
Your limits sit above every agent: no passwords or card details typed, no deletions, no downloads, sites you put off limits, a daily call limit, maximum call length and allowed countries. Emergency and premium-rate numbers are never dialled. Agents can send email and create records in apps you connect, and every such action is logged with exactly what was sent. The web agents cannot buy or log in to websites.
Secrets leaking into results
Agents read pages that may contain codes, keys or card numbers.
What Sentinel does
Card numbers, one-time codes, passwords and secret keys are hidden before anything is shown or stored.
Reaching into private networks
A fetched link could point at a router, a local service or a cloud metadata address.
What Sentinel does
Agents can only open public web pages. Local and private addresses are refused, redirects are re-checked, and files are never downloaded.
Not knowing what happened
Without a record, you cannot check or fix anything.
What Sentinel does
Every step is logged with the skill it used, the rule that decided it and whether a page tried to instruct the agent. You can export the log.
Our own red-team test suite
On 3 October 2026 our internal suite of 46 cases passed 46 of 46. It covers instructions hidden in white text, comments, alt text, invisible characters and encoded text, fake system messages, fake checkout and login forms, requests to reveal secrets, data sent out through web addresses, private-network and cloud metadata addresses, lookalike domains, emergency and premium-rate numbers, invented tools, the kill switch, and fake or missing approvals for phone calls when "Place calls" is set to Ask or Off (calls are allowed without approval by default). These cases check Sentinel's server-side rules directly.
On the same day, real Research and Investigation agents were each given all 18 of our public test pages on this site (16 attack pages and 2 normal pages): 36 of 36 runs passed. On every attack page the hidden instruction was caught and the page withheld, and no agent visited the attacker's address. Both fake forms were flagged and never filled in. Neither normal page was flagged. In a test, the agent's card showed Stopped 1.8 seconds after the kill switch was pressed. An earlier live test showed it cancels its pending approval, and both changes of the switch were written to the audit log.
These are our own tests, not an independent audit, and passing them does not mean every attack will be caught.
What we will not claim
No AI agent is unhackable, and detecting injected instructions is not perfect. That is exactly why Sentinel does not rely on the AI behaving well: skills, limits, the kill switch and any approvals you turn on are enforced in plain code outside the model, so a tricked agent still cannot do what you have not allowed. Sentinel has no independent security certification yet.
Try the agents →