Pricing

The tool is free. The judgement is what costs money.

Sentinel watches the MCP packages your agents depend on and tells you, with evidence, when one of them changes. It is Apache-2.0 and complete — every capability is in the public repository, there is no withheld tier, and that is permanent. What you can pay for is a person reading your system and telling you what they found.

Self-host

Freeforever

The whole thing. No withheld tier, no feature gate, no seat limit.

  • The analyzer and sentinel CLI
  • Evidence reports, schema-validated
  • sentinel diff between any two reports
  • The Watch monitor, single-tenant
  • A GitHub Actions monitor that needs no server at all
  • You deploy it. You hold the data.
Get it on GitHub

Node.js 22+. The GitHub Actions monitor is a fork and a list of package names — no worker, no database, no account anywhere. The Cloudflare version takes about an afternoon and runs on their free tier for ordinary packages.

Advisory

Scopedper engagement

A structural read of an agent system, its governance boundaries, and where the enforcement actually is.

  • Architecture and drift review
  • Adversarial issues register, in the format we publish
  • Written findings with severities and reproduction, not a slide deck
  • We state what we can assess before the engagement starts
Start an enquiry

Limited availability — this is a small lab and advisory work competes with building. What an engagement covers →

Sponsorship

Anyamount

If the tool is useful and you would like there to be more of it. This buys you nothing, deliberately.

  • No SLA, no support commitment, no feature obligation
  • No tier, no badge, no priority in the issue tracker
  • Funds extraction coverage, more of the MCP surface, wider corpora
  • One-off or recurring, entirely as you prefer
Support the work

Kept separate from the advisory work on purpose. Sponsorship that quietly bought influence over what gets built would make the published limitations worth less, and those are the whole point.

Straight answers

The questions worth asking before you pay for anything.

Is the free version crippled?

No, and there is no other version. The analyzer, the CLI, the diff engine and the Watch monitor are all in the public repository under Apache-2.0, and they always will be. There is nothing held back to sell you later.

Do you host it for me?

No. Sentinel is single-tenant by design — you deploy it, you hold the data, and nothing passes through us. The Cloudflare version takes an afternoon; the GitHub Actions version needs no server at all.

What is this actually for?

Catching the release where a package you already trusted becomes something else — a new install script, a widened schema, a rewritten tool description your model reads as an instruction. Sentinel cannot stop that release. It makes it visible, with evidence, before you upgrade.

Does Sentinel tell me a package is safe?

No, and it will not pretend to. It produces evidence about what an artifact declares; you set the policy. We publish exactly where extraction fails — including that across a pinned corpus of 50 real published MCP servers, 37 yield a usable tool inventory and only 12 can be resolved completely.

Does that third-of-servers figure limit the change detection?

Barely. A package turning hostile shows up in the artifact digest, the install scripts, the dependencies and the file inventory — all recorded completely, on every package, every time. The inference limit applies to naming tools, not to noticing that something moved.

What does it actually catch, reliably?

Change. Artifact digest, file inventory, dependencies, install scripts and entrypoints are recorded completely on every package. If something you approved has moved, you will know. Tool-surface extraction is inference and is stated as a lower bound.

Does it run the package?

Never. Analysis is entirely static — nothing is executed, imported, or started. That is a deliberate limit: a package can do things at runtime that no report mentions.

Do you see my code or credentials?

Neither. Sentinel inspects public npm artifacts by name and version. It never accepts credentials, and hosted monitoring only ever needs to know which public packages you care about.

Why should I trust a small lab with this?

You should not have to. The analyzer is open, the reports are schema-validated and reproducible from a digest, and the limitations are published in the repository rather than discovered later. Verify the tool rather than trusting us.

How this works

The software is finished. The reading is the service.

Sentinel is public, tested, and complete. You can run it today against every MCP package you depend on without talking to us, paying us, or creating an account anywhere.

What a person adds is judgement: which of those changes matters for your system, where your enforcement actually sits, and what to do before the next release lands. That is the engagement, and it is scoped per piece of work rather than sold by the month.

Either way