SentriesAI
← SentriesAIAI DETECTION
AI-POWERED DETECTION

Catches what others miss.
In under two seconds.

Eight independent detection layers. A conviction engine that evaluates evidence — not points. Detects phishing, scams, brand impersonation, and social engineering across URLs, emails, messages, and images.

0.904
F1 Macro
3-class ML
10K+
Training samples
real scans
726K
Known threats
3 intel feeds
66
Brands matched
visual fingerprints
<2s
Analysis time
full pipeline
SCROLL TO SEE HOW
THE PROBLEM

Phishing doesn't wait.

Every 11 seconds, a new phishing site goes live. Every minute, someone's credentials are harvested. Blocklist-based protection always arrives too late — by the time a URL is reported, 100 more victims have clicked.

11sNEW SITE
THE APPROACH

Not point-scoring. Conviction.

Traditional scanners add up weak signals until something crosses a threshold. Login form (+12), urgency words (+8), security keywords (+10) — and suddenly your real bank page is flagged. We built something smarter: structural evidence over content noise.

POINT SCORING (OLD WAY)
Has login form+12
Urgency keywords+8
Security-related text+10
Total (your real bank!)30 · FALSE POSITIVE
CONVICTION (OUR WAY)
Structural: form submits to same domainclean
Domain: 14 years old, SPF+DMARCtrusted
Visual: matches official brandverified
VerdictSAFE · rule: established_domain
THE ARCHITECTURE

Eight independent layers.

Each layer evaluates the URL from a different angle — threat intel, domain history, content structure, visual identity, community feedback, ML classification, LLM reasoning. Independent signals, combined by a conviction engine that evaluates evidence quality.

01
Input & Chain Expansion
02
Threat Intelligence
03
Domain Intelligence
04
Content Analysis
05
Visual Brand Match
06
Collective Intelligence
07
XGBoost ML Model
08
Claude LLM Reasoning
→ CONVICTION ENGINE
THE RESULT

Structural signals win.

A credential form submitting to a different domain. A visual clone on a three-day-old typosquat. A punycode domain impersonating your bank. These are structural facts. No amount of content wording can override them — and no amount of content wording can condemn an established bank's real login page.

STRUCTURAL SIGNALS · ALWAYS WIN
Credential form submitting to different domain
Visual clone on typosquat domain
Punycode bank impersonation
Hidden login field extracting credentials
CONTENT SIGNALS · CAN'T OVERRIDE TRUST
Urgency keywords
Security-related text
Authority language
ML score alone
INTERACTIVE DEMO

Watch the pipeline work.

Click any URL below to see how our eight layers analyze it — in real-time.

ANALYZING → google.com
Threat Intel
waiting
Domain Intel
waiting
Content
waiting
Visual Match
waiting
ML Model
waiting
LLM
waiting
Conviction
waiting
VERDICT
—
Score: — / 100
CONVICTION RULE
awaiting analysis
CAPABILITIES

Everything we detect.

Comprehensive threat coverage across every channel you communicate on.

Phishing detection

Fake login pages, credential harvesting forms, typosquat domains. Caught by structural analysis — not just keywords.

Scam & fraud detection

Crypto giveaways, CEO/BEC fraud, fake marketplaces, lottery scams, romance scams. Each with a dedicated attack archetype.

Brand impersonation

66 brands fingerprinted — banks, government, social media, couriers. Favicon hash + color palette + structure match.

Multi-language

Urgency, OTP harvesting, and social engineering patterns in 20+ languages. Built for the real world, not just English.

Every format

URL, email, message, image OCR — all through the same 8-layer pipeline. No weak links between channels.

Explainable verdicts

Every verdict comes with the conviction rule that fired, which layers contributed, and specific reasons.

Sub-2-second analysis

Fast path under 200ms for known threats. Full pipeline with ML and LLM takes 1-3 seconds.

Zero false positive design

Established domains can't be flagged by content alone. Only structural evidence can override domain trust.

HOW WE COMPARE

Against the rest.

ProviderBlocklistMLVisual matchLLMMulti-langExplainPrice
Google Safe Browsing✓—————Free
Barracuda Sentinel✓✓——partialpartial€24/user/mo
Proofpoint Essentials✓✓——partial—€30/user/mo
SentriesAI✓✓✓✓✓✓Free plan + €9/mo

Based on publicly available vendor information as of Q2 2026.

REAL ATTACKS · REAL CATCHES

Case studies.

Three real attacks our engine caught. Which layers fired, and why.

APRIL 2026
BRD Phishing Campaign
brd-secure-verify.cc
CAUGHT BY
Visual Brand Match (Layer 6) + Domain Intel (Layer 4)

Brand-new domain (3 days old), no email authentication, high-risk .cc TLD, 97% visual match with BRD's real login page. Our visual fingerprint engine caught it before it appeared on any blocklist.

MARCH 2026
Crypto Giveaway Scam
get-crypto-free.xyz/claim
CAUGHT BY
LLM Reasoning (Layer 8b) + ML Model (Layer 8a)

No brand impersonation, no login form — this scam uses wallet-connect flows. Our LLM classified it as a 'crypto giveaway' archetype and the ML model flagged structural indicators (short age, high-entropy domain, urgency keywords).

APRIL 2026
CEO/BEC Wire Transfer Fraud
Email from ceo@c-e-o-company.com
CAUGHT BY
Message Pipeline + Domain Analysis

Lookalike domain (c-e-o-company.com vs ceo-company.com). Email header mismatch. Urgent wire transfer request with unusual beneficiary. Attack archetype: BEC/CEO fraud. The message pipeline caught structural email authentication failures.

FREQUENTLY ASKED

Questions, answered.

Try it yourself.

Free plan includes 10 URL scans and 3 image scans per day. No credit card needed.

Get started freeTechnical deep-dive →