Hex Security is now ParameterWe're at Black Hat USA 2026

Parameter

Backed by Y Combinator

Review every PRbefore it's merged.

Sentinel reviews each pull request the moment it opens and flags exploitable vulnerabilities as inline comments. Works with GitHub, GitLab, and Bitbucket Cloud.

Built by the team that secured:

Apple
Google
Microsoft
U.S. Department of Defense
T-Mobile
Henkel
Epic Games
AT&T
Yahoo

[ how it works ]

01

Connect

Connect GitHub, GitLab, or Bitbucket Cloud and choose the repositories you want reviewed. Sentinel picks up every new pull request from there.

02

Analyze

Sentinel reads the diff, the surrounding code, and the execution paths it touches to find vulnerabilities an attacker could exploit.

03

Review

Sentinel posts each finding as an inline comment on the pull request. Developer replies feed back into future reviews and cut false positives.

[ coverage ]

Focused on the vulnerabilitiesthat matter most

Sentinel focuses on exploitable application security issues that put your systems and data at risk, not code style or best practices.

Authentication bypass

Broken access control

IDOR (Insecure Direct Object Reference)

Business logic flaws

Injection vulnerabilities

Server-Side Request Forgery (SSRF)

Leaked secrets

Unsafe handling of user input

[ why parameter ]

The signal.Not the noise.

Most tools dump every advisory in your tree and call it coverage. Parameter raises only what an attacker can reach, and ships the fix with it.

Understands your code

Sentinel follows execution paths beyond the diff to catch vulnerabilities that only appear in the context of your application.

Comments where it matters

Findings land directly on the pull request, so developers can fix issues without leaving their workflow.

Improves with every review

Feedback from your developers becomes reusable Rules that teach Sentinel your codebase and improve its next review.

[ at scale ]

Over 10,000 PRs reviewedevery day

Sentinel follows every finding from first comment to fix. Here's the last 30 days across the repositories it watches.

Resolution activity

Last 30 days

7d

30d

90d

PRs reviewed

312,940

Vulnerabilities caught

9,417

Found

Resolved

[ FAQ ]

Frequently asked questions

Start testing today.

A URL and credentials is all it takes.

First findings land within 24 hours.