01 // Dashboard
You sign in, and see the status immediately.
The home view shows the current state. Number of active monitors, recent alerts, and whether anything needs attention today.
M
Mustvedt Sentinel
yourcompany.com
⌕
Search or jump…
⌘K
Main menu
- ◇Overview
- 🔔Alerts
- ⚡Tools
- 📡Monitoring
- 🎣Phishing radar
- 📊Reports
- 🤖AI analysis
Security scans
Account
- 👥Team
- 💳Subscription
- ⚙Settings
Good morning, Anne
Last sign-in: yesterday · 3 new alerts to review
⚠
SSL expires in 18 daysyourcompany.com, auto-renews if Let's Encrypt is active
🚨
Breach found — post@yourcompany.com
New hit in Collection #5 (May 2026). Exposed: password hash, IP address, username. Change the password now if still in use.
Real-time statusYou see what needs action immediately — no searching.
Bilingual interfaceThe dashboard is available in Norwegian and English. Set your preference on first login.
Team access on PLUSSInvite up to 10 colleagues with their own logins. Businesses can pay by invoice instead of card.
Light and dark modeSwitch with one click. Setting is remembered per device.
02 // 18 tools in one place
Twelve free. Six exclusive PLUSS tools.
Everything you need to check a link, a password, an email, a domain, or a file. Results are kept in history so you can look them up later.
mustvedt.net/sentinel/#/tools
M
Mustvedt Sentinel
yourcompany.com
⌕
Search or jump…
⌘K
Main menu
- ◇Overview
- 🔔Alerts
- ⚡Tools
- 📡Monitoring
- 🎣Phishing radar
- 📊Reports
- 🤖AI analysis
Security scans
Account
- 👥Team
- 💳Subscription
- ⚙Settings
Tools
12 free · 6 exclusive PLUSS tools
Free tier gets 12 tools10 scans per day, no card. You can test everything in under five minutes.
PLUSS unlocks Nmap, Nikto, testssl.sh, gobuster, OSINT recon, and nucleiIndustry-standard security tools, run from our server — no installation needed.
03 // A scan in practice
Paste a link. Get an answer in seconds.
Example: URLSCAN checks reputation, certificate, redirects, known threat databases, and which trackers load. Results are presented in plain language — not a JSON dump.
mustvedt.net/sentinel/#/tools/urlscan
M
Mustvedt Sentinel
yourcompany.com
⌕
URLSCAN
⌘K
Main menu
- ◇Overview
- 🔔Alerts
- ⚡Tools
- 📡Monitoring
- 🎣Phishing radar
- 📊Reports
- 🤖AI analysis
Security scans
Account
- 👥Team
- 💳Subscription
- ⚙Settings
🔗 URLSCAN
https://secure-banking-login.online/auth — scanned 2 seconds ago
🚨
High risk — likely phishingDomain is 4 days old. Mimics a major bank brand but is not registered to any known bank.
- Domain age4 daysCritical
- SSL certificateLet's Encrypt, validOK
- Threat databasesHit in ThreatFoxMatch
- Redirects2 hops before login pageSuspicious
- Trackers0 foundClean
Plain-language resultsTechnical details are explained in plain language so you understand what a verdict means.
Download as PDFShare the report with a colleague or keep it as documentation. Available on PLUSS.
HistoryEverything you’ve scanned is kept for 7 days (free) or 30 days (PLUSS).
Also: free browser extensionInstall it and it warns about risky links as you browse — before you click.
04 // Monitoring around the clock
You register what you own. We keep watch.
Domains, emails, and dark web are checked every night. If a certificate is about to expire, a new leak surfaces, or something changes — you get notified by email and in the dashboard.
mustvedt.net/sentinel/#/monitoring
M
Mustvedt Sentinel
yourcompany.com
⌕
Search or jump…
⌘K
Main menu
- ◇Overview
- 🔔Alerts
- ⚡Tools
- 📡Monitoring
- 🎣Phishing radar
- 📊Reports
- 🤖AI analysis
Security scans
Account
- 👥Team
- 💳Subscription
- ⚙Settings
Monitoring
Last checked: last night at 03:00 · next check in 14 h 22 min
- yourcompany.comSSL · 18 d leftSoon
- www.yourcompany.comDNS response 24 ms · 200 OKOK
- mail.yourcompany.comDMARC: no p=rejectTip
- shop.yourcompany.comNew subdomain detected yesterdayInfo
- example.comAll systems OK · 100% uptimeOK
- post@yourcompany.comCollection #5 · May 2026Leaked
- board@yourcompany.comLinkedIn 2021 · 700M rowsLeaked
- billing@yourcompany.comNo hits in 13B rowsClean
Daily check at 03:00All domains and emails are processed. You wake up to either a clean report or an alert.
Real-time certificate monitoringWe check Certificate Transparency logs every hour. Alert within 1 hour if a new SSL cert is issued for your domain — often the earliest sign of a subdomain takeover. SSL expiry is also notified 30, 14, and 3 days out.
Live breach feed with instant re-checkWe poll HIBP every hour for new breaches. When a new leak goes public, all your emails are re-checked immediately — not the next morning. 13 billion rows.
JavaScript supply-chain scanningSHA hashes of external scripts on your pages are stored. If one changes without notice, you get an alert immediately — so Magecart attacks and compromised dependencies are caught before your customer is hit.
05 // Phishing radar
We catch brand impersonations before your customers do.
The radar searches daily for new domains that look like yours. Typosquatting, homoglyphs, SEO spoofing. Each hit is scored by risk, so you know what’s urgent.
mustvedt.net/sentinel/#/radar
M
Mustvedt Sentinel
yourcompany.com
⌕
Search or jump…
⌘K
Main menu
- ◇Overview
- 🔔Alerts
- ⚡Tools
- 📡Monitoring
- 🎣Phishing radar
- 📊Reports
- 🤖AI analysis
Security scans
Account
- 👥Team
- 💳Subscription
- ⚙Settings
Phishing radar
Watching: yourcompany.com · example.com · 187 new hits last 30 days
yourcornpany.com
Typosquat · rn→m
High riskRegistered yesterday · DNS active · MX pointing to Mailgun · A-record on 185.107.56.42
yоurcompany.com
Homoglyph · IDN
High riskCyrillic «о» (U+043E) instead of «o» · certificate issued 2 days ago
yourcompany-secure.com
Hyphen-variant
MediumRegistered 4 days ago · no MX · parked at Sedo
login-yourcompany.support
Subdomain trick
MediumLogin-themed · Cloudflare proxy hides IP · no active service yet
example-inc.com
Hyphen-variant
LowInactive · no DNS records · monitored for change
We catch five types of look-alike domainsTypos of your brand, lookalike characters from other languages, variants on other TLDs, hyphen tricks, and unexpected subdomains.
Daily search for new registrationsWe monitor public certificate databases and look for hundreds of variants of your brand the moment they’re registered.
Behaviour-based risk scoringActive MX records, A-records, and login themes score high. Parked domains are flagged as medium and watched.
Takedown assistance includedWhen a domain goes live with phishing content, we help you report it to the registrar, hosting provider, and Google Safe Browsing.
06 // AI analysis & reports
Ask in plain language. Get answers in plain language.
The AI module interprets your findings and suggests actions. The Reports module pulls everything into a monthly report you can download, send to the board, or archive as documentation.
mustvedt.net/sentinel/#/ai
M
Mustvedt Sentinel
yourcompany.com
⌕
Search or jump…
⌘K
Main menu
- ◇Overview
- 🔔Alerts
- ⚡Tools
- 📡Monitoring
- 🎣Phishing radar
- 📊Reports
- 🤖AI analysis
Security scans
Account
- 👥Team
- 💳Subscription
- ⚙Settings
🤖 AI analysis
Ask about any scan or alert. Answers are based on your own data.
Security score, this week
67 / 100
What’s my biggest risk right now?
Your biggest risk is
post@yourcompany.com. The address was exposed in Collection #5 yesterday (password hash, IP, username). If the same password is used elsewhere, an attacker already has what they need for credential stuffing.
Source: MAILSCAN · 2026-05-06 03:14
Suggestion from Claude
Three things I’d prioritise now:
- Change the password on post@yourcompany.com and enable 2FA on every service it’s used on
- Set up DMARC with p=reject — yourcornpany.com already has active MX and can be used for spoofing
- Consider defensively registering yourcornpany.com and yоurcompany.com (~€18/yr per domain)
Suggested questions
What does DMARC p=reject mean in practice?
Which domains look most like mine?
Is the security score better than last month?
Write a security update for the board
Latest reports
AI on your own data, if you want itThe model only sees what you’ve scanned. Nothing is shared with third parties beyond the Anthropic API call, and you can turn it off entirely.
Pen-Test reports get extra agent-validationIf you order a Pen-Test & Recon, pentest-ai orchestrates LLM-driven probes that validate findings and surface chained vulnerabilities the standalone tools don’t see.
Security score that follows the trendWeight: domains 30%, email 40%, phishing exposure 30%. You see movement week over week — not just a snapshot.
Spør på vanlig norsk«Hva er nytt siden i fjor?», «Hvilket varsel betyr mest?», «Skriv et notat til styret om GDPR-status.»
Monthly reportGenerated on the 1st of every month. Includes all scans, alerts, uptime stats, and an AI-written summary.
07 // Pen-Test & recon
Need a deeper dive? Order a signed report.
The platform above runs continuously. If you’d rather have a one-off security analysis — signed PDF in three business days — that’s Pen-Test & Recon. Launch price right now €179 (normally €449).
Sentinel Pen-Test & Recon
yourcompany.com
B+
Health score 86 / 100
Solid, with three actions that should be prioritised
Top 3 actions
- Enable DMARC with p=rejectThe email domain can currently be spoofed without notice. A strict policy provides immediate protection.
- Close port 8080 from the internetTomcat admin UI exposed. Should only be reachable via VPN or IP allow-list.
- Upgrade vulnerable jQuery versionv1.11.1 has a known XSS CVE. Move to 3.7.1 or remove from the page.
30 check points + 10 recon toolsDNS, TLS, email auth, headers, dark web, leaks. Tools: Nmap, Nikto, testssl, gobuster, nuclei, theHarvester, subfinder, amass, crt.sh, and WAF detection.
Agent-driven deep analysispentest-ai orchestrates LLM-driven probes that validate findings with safe proof-of-concepts and surface chained vulnerabilities standalone tools don’t see.
Signed report from 8 pagesExecutive summary, prioritized action plan, health score A+ to F. Readable without IT expertise, or sent straight to your developer.
3-business-day delivery14 days of email follow-up included. Card payment. 100% refund if not delivered within 5 business days.