Sentinel · External Security Posture
Your attack surface, watched from the outside.
Sentinel watches your domains, email, and public web estate all the time, not just on audit day, and turns what it finds into work your team can actually close. Nothing to install, nothing touching your internal systems.

001 · Why This Matters
You cannot defend what you cannot see.
Most breaches start with something already public: an expired certificate, a domain that can be spoofed, a service that should never have been exposed. Your internal tooling does not see your surface the way an attacker does. Sentinel does.
002 · Coverage
What Sentinel watches.
Domain and subdomain exposure
Every domain and subdomain you present to the internet, mapped and reviewed, including the ones that no longer point where they should.
Email authentication and spoofing resistance
Whether the internet has any reason to trust mail claiming to come from you, and whether someone else could send it instead.
Transport and certificate health
Certificates, protocols, and encryption posture on everything you serve, reviewed before an expiry or a weak configuration becomes an incident.
Web-facing service and header hygiene
What your public services reveal about themselves, and whether the doors they leave open are doors you meant to open.
Forgotten and shadow assets
The staging site from three years ago, the trial subdomain someone left behind. The assets nobody remembers are the assets nobody watches.
003 · How the Engagement Runs
Assessment first. Then managed monitoring.
Stage One
Assessment
Fixed scope, fixed fee. A full read of your external posture and a ranked remediation plan, delivered as a plain-language report a board can follow and an engineer can act on. You keep the report whether or not you continue.
Stage Two
Managed monitoring
Ongoing watch on your surface, with alerting on meaningful change, periodic re-assessment, and remediation tracking. New exposure becomes a flagged item within the day, not a surprise at the next audit. Priced as a monthly retainer.
004 · Deliverables
What you receive.
A board-readable posture report
Where you stand, in plain language, ranked by what actually exposes you rather than by volume of findings.
A ranked remediation plan
A short, ordered list your team can action, each item written in business terms with the technical detail beneath it.
Evidence of risk reduction
On managed monitoring, the record that risk went down over time, so you can show the reduction rather than assert it.
A named point of contact
A person who knows your surface and answers, not a portal you have to chase.
005 · Who Runs It
Run by the team that builds the platforms.
Platform Engineering
Production-grade SaaS and internal platforms, built to survive the audit, not just the demo.
→Managed Microsoft 365
Your Microsoft environment owned and run to an audit-ready standard, every month.
→Compliance Systems
Software built to stand up to audit, with the evidence ready before the auditors arrive.
Start with the assessment.
Fixed scope, agreed before we begin, and the report is yours to keep either way.