Built to start free.
Priced to scale honestly.
Sentinel is in open beta. The free plan covers most production workloads while we move toward GA — and signing up during beta locks the Growth founding price for later. No credit card. No expiry. No artificial monthly cap. Custom enterprise contracts with contractual SLAs and a signed DPA are available now.
Use it in production. Many beta customers do.
Sign up — no card required- 1,000 requests / hour per API key
- 50,000 requests / hour per source IP (anti-abuse backstop)
- All detection signals — VPN, proxy, datacenter, Tor, antidetect, automation, emulator
- Device intelligence (visitor ID, tampering score)
- Webhooks (Slack / Discord / custom)
- Hosted MCP server — AI agents screen IPs on your key (docs)
- Dashboard, CSV export, Recent Activity, IP lookup
- 2FA, reviewable active-session list with per-device revocation
- Community support via [email protected]
Best-effort uptime targeting 99.9% measured at /status. No contractual SLA on the free plan during beta.
Sign up during open beta and this price is locked in. Billing starts only when beta ends — 30 days' notice, cancel anytime.
Lock the founding price- Everything in Free — same signals, same verdict engine, nothing detection-gated
- 5,000 requests / hour per API key — outgrowing it? Higher Growth limits are a quick email, no enterprise contract needed
- Priority email support — same-business-day response target
- Founding-price guarantee — €49/mo for as long as your subscription stays active
- No card today — we email 30 days before billing begins
Overage is never auto-billed: past your limit you get a 429 with Retry-After, never an invoice. Uptime target 99.9% measured at /status; contractual SLAs remain an enterprise feature.
Predictable pricing tied to volume + commitment, not a "Contact us" black hole.
Book a 15-min call or email [email protected]- Everything in the free plan
- Custom request volume — 100 K, 1 M, 10 M / month or higher
- Contractual uptime SLA with service credits (typical 99.95%) — published SLOs
- Signed DPA aligned to UK / EU GDPR Art. 28, with SCCs
- 30-day sub-processor change notice with right to object
- Dedicated support channel + named technical contact
- Vendor security questionnaire responses (SIG-Lite, CAIQ, bespoke)
- MSA available for procurement that can't accept click-through Terms
- Annual invoice billing — purchase orders and vendor onboarding welcome
- Volume webhook delivery + custom data residency on request
- Onboarding assistance + integration review
Procurement details, DPA & security docs →
Self-serve: DPA · Security whitepaper (PDF)
Sentinel is pre-audit for SOC 2 Type II. We do not currently hold SOC 2, ISO 27001, HIPAA BAAs, or PCI DSS attestation, and will not claim otherwise. Audit firm engagement and timeline shared on request under NDA.
What's included on each plan
No tier-locked detection signals. The expensive end of the platform is volume + commitment, not capability.
| Capability | Free (open beta) | Growth | Enterprise |
|---|---|---|---|
| Network detection (VPN, proxy, datacenter, Tor) | ✓ | ✓ | ✓ |
| Device intelligence (antidetect, automation, emulator, VM) | ✓ | ✓ | ✓ |
| Visitor ID + tampering score | ✓ | ✓ | ✓ |
| Webhooks | ✓ | ✓ | ✓ |
| Sub-40ms server-side median server decision | ✓ | ✓ | ✓ |
| Rate limit | 1,000 / hour per key | 5,000 / hour per key | Custom — typical 100K – 10M / month |
| Support | Email, best effort | Priority email — same business day | Dedicated channel + named contact |
| Contractual uptime SLA | Best-effort 99.9% | Best-effort 99.9% | Yes (typical 99.95%) |
| DPA (UK/EU GDPR Art. 28 + SCCs) | Self-serve (/dpa) | Self-serve (/dpa) | Self-serve (/dpa) + countersigned copy |
| 30-day sub-processor change notice | Public list | Public list | Direct notification |
| MSA / custom contract | Click-through Terms | Click-through Terms | Available |
| Vendor security questionnaire (SIG-Lite, CAIQ) | — | — | Completed responses |
| Custom data residency | — | — | On request |
Common questions
If we're missing something, email [email protected].
What happens when the free tier limit is hit?
You receive an HTTP 429 response with a Retry-After header indicating seconds until the limit resets. Your existing valid evaluations continue to be served — no broader account effects. The hour rolls forward; no monthly quota involved.
What counts as a request?
One server-side call to /v1/evaluate or /v1/lookup counts as one request. Loading the client SDK on your pages does not count — only your backend calls do. The deterministic test_* tokens are never billed, and the public sk_test_sandbox key for CI never touches your quota at all.
How does the Growth founding price work?
Everyone who signs up during open beta qualifies automatically. When beta ends we'll email at least 30 days before any billing starts; if you choose Growth, the €49/month founding price holds for as long as your subscription stays active. No card is collected until then, nothing is charged retroactively, and staying on the free plan remains an option.
Do overages get billed?
No. There is no metered overage billing on Free or Growth: past your hourly limit you get a 429 with Retry-After, never a surprise invoice. If you consistently hit the ceiling, that's the signal to talk about enterprise volume.
Will the free plan stay free?
Yes. The free plan is part of how we get developers started. We may revise the rate-limit numbers as the platform evolves, but we will give at least 30 days' notice via email and on the changelog before any change to commercial terms takes effect, and your existing free-tier traffic will not be retroactively charged.
Do you offer an enterprise SLA today?
Yes — for enterprise customers under a signed agreement. Typical terms: 99.95% monthly uptime, service credits if missed, 24-hour incident response, named technical contact. The free plan has best-effort uptime targeting 99.9% measured at /status, but no contractual SLA.
Is a Data Processing Agreement available?
Yes — self-serve. Our DPA is aligned to UK GDPR / EU GDPR Article 28, includes the applicable international-transfer terms and a current named sub-processor list, and is published at sntlhq.com/dpa, where it binds on acceptance with no signature required. A PDF is available for vendor files, and a countersigned copy from [email protected]. Our Cookie Policy separately describes providers used by the public website.
What compliance certifications do you hold today?
None. Sentinel is in open beta and is pre-audit for SOC 2 Type II. We do not currently hold SOC 2, ISO 27001, HIPAA BAAs, or PCI DSS attestation, and we will not claim otherwise. Roadmap detail (selected audit firm, scope, timeline) is shared with serious enterprise prospects under NDA.
Where is data hosted?
Application infrastructure runs on Railway; the primary database is Turso (managed libSQL). The full sub-processor list — with a dated change log and 30-day advance notice — is published at /sub-processors. Custom data residency arrangements (EU-only, US-only) are available for enterprise customers on request.
How do I report a security issue?
Email [email protected] with the subject prefix [SECURITY]. Full scope, response targets, and safe-harbour terms are documented at /responsible-disclosure.
Can I evaluate Sentinel before signing a contract?
That's exactly what the free plan is for — production-grade access, no card required, no expiry. Most enterprise prospects integrate on the free plan first, validate detection rates against their existing fraud signal, and negotiate the enterprise contract once the technical fit is proven. Evaluating at higher volume? The startup & enterprise evaluation program unlocks up to 1,000,000 evaluations per month, free, while you validate.
Ready when you are.
Production-grade access on the free plan — talk to us only when volume demands it.