Skip to main content
Sentinel — Web Application Firewall and security monitoring by G Tech Group
WAF & Security Monitoring

Watch from above. Block downstream.

Sentinel is G Tech Group's self-hosted Web Application Firewall and security monitoring system: it stops attacks on the server, centralises fleet events and keeps data and control inside your infrastructure.

What is Sentinel

Managed, self-hosted web security

Not a licence to configure on your own: a security service managed by G Tech Group that runs on your infrastructure.

Sentinel puts a Web Application Firewall in front of your sites and a security agent on your server: it inspects every request, blocks attacks locally in milliseconds and watches logins, logs and files. The engine is Coraza with the OWASP Core Rule Set v4 — SQL injection, XSS, RCE, path traversal and anomaly scoring, in detection or blocking mode, configurable per domain.

Every event flows into a self-hosted central console: see in real time what happens on each server, create rules, manage updates and receive alerts. The core stays in your infrastructure, with mTLS between agent and server and secrets encrypted at rest: no black box, no lock-in.

How it works

Three parts, one defence

Local protection on the server, centralised control in the core and full visibility for the team, connected by an authenticated gRPC channel with mTLS.

The agent on your server

A lightweight reverse proxy (Go + Coraza) puts the WAF in front of your sites, inspects every request and applies rules and blocks locally, in under a millisecond. It also watches SSH, Nginx/Apache logs and file integrity.

The central core

It collects events, syncs rules and blocks over gRPC with mTLS, coordinates the whole fleet and keeps the history. It is not a mandatory hop for visitor traffic: if the core is offline, local protection keeps running.

Your dashboard

See everything in real time, create per-domain policies, manage canary updates and receive alerts, from any device, with roles, 2FA and audit logs.

The path of a request: 01 Arrival02 Assessment (OWASP CRS, rate-limit, geolocation, reputation and fingerprint) → 03 Action (forwarded, observed, throttled or blocked) according to that domain's policy.

The console

Sentinel in the field

Real screens from the console: from the initial event to block management, all the way to the full fleet overview.

Dashboard: fleet status and security activity in real time.
Dashboard: fleet status and security activity in real time.
Events: every request assessed by the WAF, with rule and reason.
Events: every request assessed by the WAF, with rule and reason.
OWASP CRS WAF rules, configurable per domain.
OWASP CRS WAF rules, configurable per domain.
Active blocks: hostile source, affected server and applied policy.
Active blocks: hostile source, affected server and applied policy.
Fleet: every protected server managed from a single panel.
Fleet: every protected server managed from a single panel.
Reports and history: aggregated events and trends over time.
Reports and history: aggregated events and trends over time.
Modules

Every layer covered

From the L7 application filter to the network firewall, from antivirus to alerts on your phone: one single platform.

OWASP CRS WAF

Coraza engine with Core Rule Set v4: SQLi, XSS, RCE, path traversal and anomaly scoring. Detection or blocking, configurable per domain.

Real-time monitoring

Every event, block and anomaly in a live dashboard. Fleet logs are aggregated centrally.

Agent fleet

Manage dozens of servers from a single panel, with gradual, anti-brick canary updates.

Geo-blocking & JA4

Block entire countries and malicious TLS fingerprints. Good bots (Google, Bing) are verified and let through.

Instant alerts

Self-hosted push notifications (ntfy) and a dedicated Android app: you know at once when something is wrong.

Antivirus & FIM

ClamAV scans and File Integrity Monitoring: detects malware and suspicious file changes.

L7 DDoS protection

Per-IP and global rate limiting with a JavaScript challenge: under attack, real browsers pass, floods do not.

Server & SSH protection

Monitors logins and Nginx, Apache or custom logs and blocks hostile IPs directly on the host firewall.

Threat intelligence & DNSBL

Scores incoming IPs by reputation and checks whether your servers' public addresses have ended up on blacklists.

Roles, 2FA & audit

Separate viewer, operator and admin, protect access with TOTP and log sensitive operations.

Privacy by design

Self-hosted core, mTLS between agent and server and secrets encrypted at rest. External integrations are optional and declared.

Plans & pricing

One plan per server

Managed security, not a licence to configure. Each plan protects a single server on an annual commitment. Pay for the year upfront and you pay 10 months instead of 12.

Sentinel Web 10

Managed protection for a compact web presence.

€49/month

+ VAT · annual commitment

  • Up to 10 websites
  • Up to 1 TB/month of protected traffic
  • Initial installation and configuration
  • All Sentinel modules
  • Standard management and support
Most chosen

Sentinel Web 30

More sites and more traffic, with coordinated management.

€69/month

+ VAT · annual commitment

  • Up to 30 websites
  • Up to 3 TB/month of protected traffic
  • Coordinated environment onboarding
  • Centralised policies and reports
  • Priority support

Sentinel Web Unlimited

Unlimited sites for agencies, hosting and many projects.

€99/month

+ VAT · annual commitment

  • Unlimited websites
  • Up to 10 TB/month of protected traffic
  • Planned agent rollout
  • Consolidated environment reports
  • Dedicated service management

Enterprise

Beyond 10 TB/month of traffic and non-standard environments: coverage and operating model built around the project.

Already a G Tech Group customer? Sentinel is included when you buy a server, a VPS or a hosting plan from us: protection is part of the service, with no separate licence, and site and traffic thresholds defined by the plan you choose.

Compatibility

We check the environment first, then activate

Sentinel works at the server, network and application-traffic level on Linux with systemd. The initial technical check is always included.

Supported

Debian and Ubuntu

Ubuntu 20.04+, Debian 10+, x86_64 architecture. Nginx and Apache web servers. Managed installation, with log paths verified against the version in use.

To be verified

Rocky, AlmaLinux, RHEL family

Runtime compatible; distribution, version, package manager and support status are checked before installation. RHEL, CentOS and Fedora case by case.

On project

Windows and non-standard systems

Windows Server, systems without systemd, ARM architectures and custom distributions require specific confirmation of modules and operating mode.

Solutions

The same defence, different priorities

A common base, with activation, policies and management adapted to the real scenario.

Web agencies

Many sites and different clients, a uniform defence and installation handled by us.

Hosting providers

Many sites per server, web and host protection governed as a single fleet.

E-commerce

Protect checkout, logins and files with a dedicated observation phase, without treating every customer as an attacker.

Companies

Your servers, your data: WAF, host protection, access control and audit in a self-hosted console.

MSPs & sysadmins

Agents, events, policies, blocks and updates for the whole fleet, centralised in one place.

Why Sentinel

Enterprise power, total control

Serious security, with no compromise on control of your data.

Made in Italy

Developed by G Tech Group. Support in Italian, no black box.

Self-hosted

The core runs on your servers, with no lock-in. External integrations are optional and configurable.

Extremely lightweight

Go + Coraza, CGO off. Sub-millisecond latency and a minimal footprint.

Always up to date

Rules synced from the server and safe canary updates across the whole fleet.

FAQ

Frequently asked questions

Answers to the most common questions about Sentinel.

Does Sentinel slow down my site?

No. The agent is written in Go with Coraza (CGO off) and works locally with sub-millisecond latency. The central core is not on the path of visitor traffic.

Does my data end up in a third-party cloud?

No. Sentinel's core is self-hosted and stays in your infrastructure, with mTLS between agent and server and secrets encrypted at rest. The only external integrations are optional and declared.

Do I have to configure it myself?

No. Sentinel is a managed service: we check the environment, prepare the deployment, observe traffic and activate the agreed policies. Management stays with G Tech Group.

Which systems does it run on?

Linux with systemd: Ubuntu 20.04+ and Debian 10+ on x86_64, with Nginx or Apache, are the verified path. Rocky, AlmaLinux and RHEL are assessed case by case; Windows and non-standard environments on project.

Does one plan cover multiple servers?

No: one plan protects a single server. For more servers you need one plan each; sites and traffic are counted separately on each server.

Is it included in G Tech Group services?

Yes. If you buy a server, a VPS or a hosting plan from us, Sentinel is already included, with site and traffic thresholds defined by the chosen plan.

Ready to secure your sites?

Tell us about your infrastructure: we check compatibility and identify the most suitable annual plan.