Agentic Testari · security testing hub

Sentinel-Hub is the security testing hub inside Agentic Testari (not the domain).

Security that attacks with permission — and explains risk in plain language.

Agentic Testari is the platform. Sentinel-Hub is its security testing hub — agents built for attack and security testing. Attackers already use agentic browsers; we test with the same class of tool under permission. Starts with the public façade; deeper work only when you authorize it — development / staging only (never production).

What you walk away with

// three public depths + optional offensive L1: public surface (baseline) L2: public surface (full non-destructive) L3: deep public (max depth on public pages) not offensive · public only OFFENSIVE (list on page): only client request + signed service contract (RoE included) + environment the client chooses never self-started as sales outreach out: ranked report + fix + retest
RoEfirst
Rankseverity
Fixpath
Rules of engagement Public baseline Deep public (L3) · not offensive Remediation kit
Why now · agentic threat

Attackers won't stop at a human browser

The threat model changed. Adversaries no longer rely only on a person with Chrome — or scripts that merely drive a human browser. They run agentic browsers: automated, scaled, and far more powerful.

Beyond the human browser

A human session is one pair of hands. An agentic browser reconnoiters, chains steps, and presses public surfaces and login edges at machine speed.

Not yesterday's scripts

Classic automation still helps attackers. Agentic browsers go further — more autonomy, more paths, more pressure on the exact façade your customers and partners see.

Why Agentic Testari exists

Sentinel-Hub is built for this shift: authorized testing of what faces the internet, and deeper work only under RoE — with agent-class tooling, not checkbox theater.

Same class of tool. On defense.

We test with ParviSight — our agentic browser, the same class of tool attackers already use — under scope, permission, evidence, and ranked findings you can take to the board.

We're ahead: Sentinel-Hub finds vulnerabilities with ParviSight — an agentic browser of the same class hackers already use — under RoE, with permission.

Why Sentinel-Hub (security hub)

Public risk is only the front door. If we find cracks there, real attackers go next to login portals, customer apps, and internal systems. Sentinel-Hub — Agentic Testari's security testing hub with attack and security agents — covers both layers, with hard rules about where deep / offensive work is allowed.

01

Authorized, not cowboy

Authorized, not cowboy. We may demo public L1–L3 when selling. When you buy, you sign a service contract that includes RoE — even if we already ran a public test. Offensive modes only when you request and authorize them in that contract.

02

Public + behind the login

Baseline on what faces the internet. Optional deep work on login, app flows, and intranet-style surfaces that matter once a user is in.

03

Offensive only on request

Offensive testing is never self-started. It happens only when the client asks for it, with written OK, on the environment they designate — not as cold public outreach.

How it works

Start shallow. Go deeper only when you say so — and only where it is safe.

1. RoE & scope
Public only, or public + deep on named dev/staging. Written before probes.
2. Public baseline
DNS, mail auth, headers, public APIs, exposed gateways — what any stranger can see.
3. Decide depth
If the façade is weak, we map what that implies for login, apps, and internal-style systems.
4. Deep (optional)
Authorized testing on dev/staging: login, app logic, offensive paths if approved. Never prod destroy.
5. Report & fix
HIGH MED
Ranked findings + remediation + retest.

What a package includes

What you saw in early public assessments is the baseline — the necessary first pass. Sentinel-Hub (inside Agentic Testari) is built so the story does not stop at the marketing site.

BASELINE Public surface

The “preliminary” layer: everything facing the open internet without a customer login. Fast, non-destructive, and enough to show real brand / edge risk.

  • DNS, mail auth (SPF / DKIM / DMARC / CAA)
  • Security headers, TLS, CSP quality
  • Public APIs / CMS oversharing
  • Exposed identity gateways (when present)
  • Executive ranking + findings register
  • Priority remediation (customer-style)

DEEP Behind the front door

If the public layer is weak, attackers do not stop. Deep work asks: what happens on the login, the company app, and intranet-style systems your users actually use?

  • Authenticated / portal / SSO-style surfaces (in scope)
  • Business application flows your customers depend on
  • Internal-style or staff systems when authorized
  • Optional very deep & offensive testing
  • Only on development or staging you name
  • Never destructive / offensive against production

Why companies that care about security buy both

Public pages protect reputation. Login and product systems protect money, data, and trust. Sentinel shows what is visible from the street and — when you authorize it — how hard a serious attacker could push on a safe copy of your real system (dev/staging), so you fix before production pays the price.

Baseline = what any stranger can see. Deep = what we can prove on your dev environment, with your written OK — including offensive depth if you want the full story.

Hard rules (always)

  • Paid work: signed service contract with RoE for every package (L1–L3 and Offensive)
  • No offensive work without the client asking for it in writing
  • Offensive only on the environment the client designates
  • No confidential client details published without your OK
  • No “guaranteed zero risk after one pass” claims

What is RoE?

RoE = Rules of Engagement inside a signed service contract. We may run L1–L3 public assessments to show value when selling. When you purchase — even a light L1/L2/L3, and even if a public test was already done — you sign a Service Agreement that always includes RoE (Schedule A). That protects both sides for delivery, payment, and follow-on work. The deeper the purchase (especially Offensive), the more detailed the RoE. Offensive techniques only if the signed contract authorizes them before those methods run.

  • Sales L1–L3 public demo: we can run without your signature
  • Purchase of any package: signed service contract + RoE always — even if the public test already ran
  • Light purchase → short RoE; deep/Offensive → every target and method listed
  • Offensive never as cold outreach; methods default off until you authorize them in the contract

Engagements

L1–L3 = public pages only, non-offensive (what we can run to show value and sell). Offensive techniques are listed separately — they require your request, a signed service contract that includes RoE, on the environment you choose.

Surface Pulse

L1 · Public baseline — fast
€1,190 + ALV (VAT) / target
  • DNS + mail auth snapshot
  • Security headers / TLS
  • Light public path probes
  • Top findings + severity ranking
  • 1-page executive summary
  • Full plain-language explanation of everything done
  • Fix / patch scripts & how-to guidance
  • Retest after your fixes + delivery of the new results
Ask for Pulse

Offensive (signed contract + RoE)

Client request · signed contract with RoE · environment you choose
Quote / program
  • ⚠️ These are OFFENSIVE — never cold outreach / never self-started
  • Only when you ask + signed service contract (RoE included)
  • Only on the environment you designate
  • Exploits & mutating PoCs (prove impact with your OK)
  • Authenticated testing (login / portal / SSO with test users you give)
  • Password spray, credential stuffing, brute force (if RoE allows)
  • Business logic abuse, IDOR/BOLA with auth sessions
  • Heavy fuzz / active attack paths (never uncontrolled DoS unless agreed)
  • Cloud / identity deep (Azure·Entra IAM) when authorized
  • Internal-style systems, APIs behind login, staff tools
  • Mobile binary / lab techniques when in scope
  • Full report + fix path + retest after patches
  • AWP + PayBotFin log every agent step for accountability
Request offensive (with signed RoE contract)

Who am I

So you know this is not a faceless scan vendor — it is built and led by someone who has spent a career finding what breaks in systems that cannot afford to break.

Renata Baldissara-Kunnela

Renata Baldissara-Kunnela

Founder · FriendlyAI Oy · Agentic Testari (Sentinel-Hub) · Finland

15+ years in enterprise QA and software testing — banking, insurance, and API-heavy platforms. ISTQB-minded craft: methodical, evidence-based, no theater.

Career path includes long enterprise testing work in Finland (including banking environments such as Handelsbanken / S-Pankki–class systems via Samlink, and API testing for insurance clients via Tieto/Tietoevry). Tools of the trade: exploratory & manual depth, REST/SOAP, Postman, Robot Framework + Python — plus agentic AI to scale what a senior tester already knows how to see.

Sentinel-Hub is the security testing hub of Agentic Testari — attack and security agents that turn that experience into product: authorized assessments, plain-language severity, and a fix path you can take to the board.

Finnish company · EU data mindset · Built by a practitioner, not a pure marketing shop.

Credibility, short

  • ✓ 15+ years enterprise QA
  • ✓ Banking & insurance systems
  • ✓ API / integration testing depth
  • ✓ Based in Finland (EU)
  • ✓ FriendlyAI Oy · Agentic Testari

Book a Sentinel assessment

Tell us the public domain, whether a deep phase on dev/staging is in play, and when you need the report. We never run offensive/destructive work on production.

Contact (anti-spam inbox): dev@friendlyai.fi · Use case