Hacker
$0/ free plan
Solo founders shipping their first app.
- 1 active project
- 5 database audits per month
- Basic secret checks and AI chat

Know what's safe to ship before it reaches production.
THE ANSWER, WITH THE EVIDENCE
See the checks behind the verdict and the next thing to address. Missing evidence is never a passing result.
The database check has not run. Review the known finding, then collect the missing evidence before deciding to ship.
A successful check can still report findings. Fresh does not mean risk-free.
Finding to review
A public-prefixed environment variable can be included in the browser bundle. The credential value is redacted.
Next action
Review the affected configuration, remove the exposure, and rotate the affected credential. Rerun the check to verify.
1 project. 5 database audits per month on the free plan.
FROM YOUR STACK TO YOUR NEXT STEP
Map a GitHub repository and Supabase project. Add Vercel when you want deployment evidence, too.
Run a review. Inspect the findings, their source, and which checks are fresh, missing, or failed.
Review a proposed change before applying it. Rerun the affected checks: a change alone is not a verified fix.
YOUR APP. YOUR DECISION.
Authorize provider access, then choose the repository or project Sentrail reviews.
Provider credentials are encrypted. Findings, redacted evidence, and audit receipts are retained to support the review.
Review changes before execution. Supported repository fixes use draft pull requests; you control the merge.
START SMALL. REVIEW BEFORE YOU SHIP.
Monthly prices in USD. Compare full limits and annual billing before choosing a paid plan.
$0/ free plan
Solo founders shipping their first app.
$29/ month
Builders shipping weekly with Supabase.
$99/ month
Teams with compliance requirements.
Need Growth or a custom agreement? Contact sales.
BEFORE YOU CONNECT
Know what you are connecting, what you get, and what a verdict does and does not mean.
Connect a GitHub repository and Supabase project for the core review. Vercel is optional for deployment evidence. Authorize each provider and map the resources you want to inspect; connecting an account alone does not complete a review.
The Hacker plan includes 1 active project, 5 database audits per month, basic secret checks, and AI chat. Paid plans add capabilities such as scan history and approval-gated remediation. Compare the full limits on the pricing page.
Security reviews inspect your connected resources. Changes use separate approval-gated workflows. Review a prepared proposal before submitting or executing it; supported repository changes use draft pull requests that you merge. Applying a change is not proof of resolution: rerun the affected checks.
No. A verdict describes the findings and evidence within the review's scope, not a guarantee of security. Missing, failed, or stale required evidence produces Insufficient Evidence. Inspect the coverage and findings before deciding to ship.
Sentrail is read-only by default and uses scoped tokens with least-privilege access. Repository contents are processed in an ephemeral scan workspace; Sentrail retains findings, redacted evidence, audit receipts, connection metadata, and encrypted provider credentials needed to operate your project. Matched credentials and API tokens are fingerprinted and redacted before findings reach a model.
Start with one project. Let the evidence guide your next step.