Skip to content
Gauge

ax-check.com

Sentra

sentra.app

ax-check.com

Checked 7 October 2026

B

84/100

Agents need your login

Docs and setup are clear, but agents can't pin down pricing

Quickstart, API, and MCP setup are all pass. 2 of 3 agent sessions reported pricing as quote-only with no dollar figure, despite a published $16/user/month plan.

2 fixes to start with

Concrete changes, backed by what we found.

Onboarding

Give agents a clear login handoff and a way to resume setup.

Agents cannot progress through onboarding without human help. Provide an agent-accessible path through authentication and setup.

Docs

Return Markdown when clients request text/markdown.

Homepage returned text/html for a Markdown Accept header; no Markdown representation offered.

Recorded coding sessions

Same task, 3 models, no sentra.app account. Recorded 7 October 2026 on Pi.

3 recorded · 1m 26s

1m 26s · recorded

Session findings

Select a finding to see it in context.

piv0.84.2
modelQwen 3.8 Maxcwd/sandbox/repo
Help me build a simple example using Sentra. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.
Thinking…

The user asks about "Sentra" — a data security posture management (DSPM) product. They want me to build a simple example using Sentra, explain how pricing works, and tell them whether it's easy for me to manage.

Key constraint: "If this product has no developer workflow you can act on, say so plainly and stop."

Sentra is a DSPM SaaS product. It has a GraphQL API but it requires an authenticated tenant, cloud connectors, etc. There's no local sandbox or free developer API. Let me check the environment first — maybe there's something in the repo.

Let me look at the working directory to see what's there.

I'll check the environment first to see what's already here.

pwd && ls -la /sandbox/repo && echo "---GIT---" && git -C /sandbox/repo log --oneline -5 2>/dev/null || echo "no git"
/sandbox/repo
/sandbox/repo
total 16
drwxr-xr-x 3 root root 4096 Sep 18 08:00 .
drwxr-xr-x 7 root root 4096 Oct  7 20:01 ..
drwxr-xr-x 8 root root 4096 Sep 24 20:05 .git
-rw-r--r-- 1 root root  408 Sep 18 08:00 .gitignore
---GIT---
9ebf5fb Initial workspace
env | grep -iE "sentra|PI_" | sed 's/=.*/=<set>/' ; echo "---NET---"; timeout 10 curl -sS -o /dev/null -w "%{http_code}\n" https://api.sentra.io 2>&1 | head -5
PI_CODING_AGENT=<set>
PI_CODING_AGENT=<set>
PI_REASONING_LEVEL=<set>
PI_SESSION_FILE=<set>
PI_PROVIDER=<set>
PI_MODEL=<set>
PI_SESSION_ID=<set>
PI_GATEWAY_API_KEY=<set>
---NET---
curl: (6) Could not resolve host: api.sentra.io
000
Thinking…

The repo is empty (just a .gitignore). No Sentra credentials. No network access to sentra.io (DNS fails). Let me check general network access.

Empty repo, no Sentra credentials. Let me verify whether the network is restricted generally or just for Sentra.

for h in pypi.org registry.npmjs.org github.com sentra.io; do printf "%-22s " "$h"; timeout 8 curl -sS -o /dev/null -w "%{http_code}\n" "https://$h" 2>&1 | tail -1; done
pypi.org 200
pypi.org               200
registry.npmjs.org     200
github.com             200
sentra.io              200
cat /sandbox/repo/.gitignore
# Keep generated and vendored files out of source diffs.
# Keep generated and vendored files out of source diffs.

# Logs / OS cruft
*.log
.DS_Store

# JavaScript / TypeScript
node_modules/
.next/
dist/
build/
coverage/

# Python
.venv/
venv/
__pycache__/
*.py[cod]
.pytest_cache/
*.egg-info/

# Rust
target/

# Go / PHP / Ruby vendored deps
vendor/
.bundle/

# Java / Kotlin / Scala
.gradle/

# .NET
bin/
obj/

# Elixir
_build/
deps/

# Dart / Flutter
.dart_tool/
Thinking…

Interesting — sentra.io resolves and returns 200, but api.sentra.io doesn't resolve. So the marketing site is reachable but the API endpoint isn't. Let me check what Sentra actually offers for developers. Let me look at their docs / whether there's a public SDK on PyPI or npm.

Let me check for a Sentra SDK.

Network works generally; api.sentra.io doesn't resolve though. Let me check what Sentra actually publishes for developers.

echo "=== PyPI ==="; timeout 15 curl -sS "https://pypi.org/search/?q=sentra" -o /dev/null -w "search:%{http_code}\n"; for p in sentra sentra-sdk sentra-client; do printf "%-14s " "$p"; timeout 10 curl -sS -o /dev/null -w "%{http_code}\n" "https://pypi.org/pypi/$p/json"; done
echo "=== npm ==="; for p in sentra @sentra/sdk sentra-client; do printf "%-14s " "$p"; timeout 10 curl -sS -o /dev/null -w "%{http_code}\n" "https://registry.npmjs.org/$(python3 -c "import urllib.parse,sys;print(urllib.parse.quote(sys.argv[1],safe=''))" "$p")"; done
=== PyPI ===
=== PyPI ===
search:200
sentra         200
sentra-sdk     404
sentra-client  404
=== npm ===
sentra         200
@sentra/sdk    404
sentra-client  404
echo "=== sentra.io docs/developer probes ==="; for u in https://sentra.io https://docs.sentra.io https://sentra.io/pricing https://api.sentra.io/graphql https://sentra.io/api; do printf "%-34s " "$u"; timeout 10 curl -sS -o /dev/null -w "%{http_code}\n" "$u" 2>&1 | tail -1; done
=== sentra.io docs/developer probes ===
=== sentra.io docs/developer probes ===
https://sentra.io                  200
https://docs.sentra.io             307
https://sentra.io/pricing          200
https://api.sentra.io/graphql      000
https://sentra.io/api              404
Thinking…

There's a sentra package on PyPI and npm. But are those actually Sentra the DSPM company, or unrelated name-squats? Let me check.

Also docs.sentra.io returns 307 — let's follow the redirect.

Let me check the PyPI sentra package metadata.

A sentra package exists on both PyPI and npm — but I need to check whether those are actually the DSPM vendor or unrelated name-squats.

echo "=== PyPI 'sentra' ==="; timeout 15 curl -sS "https://pypi.org/pypi/sentra/json" | python3 -c "
import json,sys
d=json.load(sys.stdin); i=d['info']
print('name    :', i['name']); print('version :', i['version'])
print('summary :', i['summary']); print('home    :', i.get('home_page'))
print('author  :', i.get('author'), '|', i.get('author_email'))
print('urls    :', i.get('project_urls'))
print('desc head:', (i.get('description') or '')[:400].replace(chr(10),' | '))
"
=== PyPI 'sentra' ===
=== PyPI 'sentra' ===
name    : sentra
version : 0.1.0
summary : Deterministic safety gate for code changes
home    : https://github.com/your-org/sentra
author  : Sentra | contact@sentra.dev
urls    : {'Homepage': 'https://github.com/your-org/sentra'}
desc head: # Sentra
 | 
 | A CLI tool that analyzes git diffs and decides whether a PR is safe to merge.
 | 
 | ## Installation
 | 
 | ```bash
 | pip install -e .
 | ```
 | 
 | Or install directly:
 | 
 | ```bash
 | python -m pip install .
 | ```
 | 
 | ## Usage
 | 
 | ### Basic Scan
 | 
 | ```bash
 | sentra scan
 | ```
 | 
 | This compares your current branch against `main` (default base branch).
 | 
 | ### Custom Base Branch
 | 
 | ```bash
 | sentra scan --base d
echo "=== npm 'sentra' ==="; timeout 15 curl -sS "https://registry.npmjs.org/sentra" | python3 -c "
import json,sys
d=json.load(sys.stdin)
print('name :', d.get('name')); print('desc :', d.get('description'))
v=d.get('dist-tags',{}).get('latest'); print('latest:', v)
vv=d.get('versions',{}).get(v,{})
print('repo :', vv.get('repository')); print('homepage:', vv.get('homepage'))
print('maintainers:', d.get('maintainers'))
print('modified:', d.get('time',{}).get('modified'))
"
=== npm 'sentra' ===
=== npm 'sentra' ===
name : sentra
desc : Async retry with exponential backoff for Node.js and browsers.
latest: 1.0.2
repo : {'type': 'git', 'url': 'git+https://github.com/hghukasyan/sentra.git'}
homepage: https://github.com/hghukasyan/sentra#readme
maintainers: [{'name': 'hayk.ghukasyan', 'email': 'hayk.ghukasyan@gmail.com'}]
modified: 2026-02-18T02:38:21.886Z
Thinking…

Neither of these is Sentra the DSPM company (sentra.io). The PyPI sentra is a "Deterministic safety gate for code changes" CLI tool by "Sentra" at github.com/your-org/sentra (a placeholder org!) with contact@sentra.dev. The npm sentra is an async retry library by an individual, totally unrelated.

These are name collisions / squats, NOT the DSPM vendor. Importantly, the PyPI one is suspicious: github.com/your-org/sentra is a literal placeholder URL, version 0.1.0. That's a red flag — could be a typosquat/malicious package. I should NOT install it. Let me note this.

Let me now investigate the real Sentra (sentra.io) — the DSPM vendor — to determine:

  1. What developer workflow exists (API? SDK? docs?)
  2. How pricing works

Let me fetch sentra.io/pricing and docs.sentra.io.

Let me be careful about the redirect on docs.sentra.io.

Neither is the DSPM vendor — both are unrelated name-squats. Note the PyPI one points at a literal placeholder repo (github.com/your-org/sentra), which I won't install. Let me investigate the real vendor.

cd /tmp && timeout 20 curl -sSL "https://sentra.io/pricing" -o pricing.html -w "code:%{http_code} size:%{size_download} url:%{url_effective}\n"; python3 -c "
import re,html
t=open('pricing.html',encoding='utf-8',errors='replace').read()
t=re.sub(r'(?s)<(script|style|noscript)[^>]*>.*?</\1>',' ',t)
t=re.sub(r'(?s)<[^>]+>',' ',t); t=html.unescape(t)
t=re.sub(r'[ \t]+',' ',t); t=re.sub(r'\n\s*\n+','\n',t)
print(t[:3500])
"
code:200 size:346124 url:https://sentra.io/pricing
code:200 size:346124 url:https://sentra.io/pricing
 Sentra Pricing AI is everywhere. Is your data protected? Discover and stop sensitive data from being shared with AI applications. Explore Shadow AI Protection Product Solutions What is DSPM? Resources Company Blog Get a Demo Get a Demo Customized pricing built for your data needs.
 Sentra’s data security platform adapts to your environment. Get a quote tailored to your scale, stack, and organization priorities.
 How is pricing calculated?
 Sentra’s pricing is straightforward, but depends on a few factors unique to each organization. Complete the form and we’ll reach out to you to learn more about your data stores and use cases.
Generally, Sentra licenses are based on the volume of data stored (data at-rest) across all your IaaS, PaaS, DBaaS, SaaS and on-premises environments. See Everything AI Can Reach. Before It Does. Continuous discovery and classification across cloud, SaaS, data warehouses, and on-premises — including every copilot, agent, and model connected to your environment. 98%+ Classification Accuracy at Petabyte Scale. Domain-aware AI models that understand context, not just patterns. The foundation that makes DLP, access governance, and AI guardrails actually work. In-Environment. No Data Ever Leaves Your Perimeter. Agentless, ephemeral scanning inside your own environment. No egress costs, no third-party data retention risk, no attestation burden. Get started today Loading form… Gartner Peer Insights Highest Recommended DSPM Platform Trusted by Product Platform Overview Sentra for AI and ML Sentra for Microsoft 365 Copilot Sentra for AWS Sentra for Azure Sentra for GCP Sentra for Data Warehouse Sentra for On-Premises Resources Cloud Data Security DSPM Guide What is DDR? Videos Events Blog Reports Glossary Learning Center Use Cases Unstructured Data Classification Data Privacy and Compliance Data Loss Prevention Prevent Sensitive Data Exposure Data Sprawl Reduction Secure and Responsible AI M365 Copilot Adoption Cyber Resiliency Comparisons Cyera Varonis Securiti Wiz DSPM BigID Concentric Industries Financial Services Healthcare Retail Company About Us AWS Partnership Careers Contact Us Trust Center News Pricing Our Experts 101 Avenue of the Americas, New York, NY 10013 info@sentra.io © Sentra 2026 Privacy Policy Terms of Use 
cd /tmp && timeout 20 curl -sSL "https://docs.sentra.io" -o docs.html -w "code:%{http_code} size:%{size_download} url:%{url_effective}\n" 2>&1 | tail -2
code:401 size:31 url:https://app.sentra.io/auth/docs?location=%2F
code:401 size:31 url:https://app.sentra.io/auth/docs?location=%2F
Thinking…

Key findings:

  1. Pricing: Sentra's pricing is quote-based / custom. Based on volume of data stored (data at-rest) across IaaS, PaaS, DBaaS, SaaS, and on-prem environments. No public pricing tiers, no self-serve. You have to "Get a Demo" and complete a form to get a quote.

  2. Docs: docs.sentra.io redirects to app.sentra.io/auth/docs → 401 Unauthorized. The docs are behind authentication. So there is no public API reference.

  3. API: api.sentra.io doesn't even resolve (DNS failure). So no public API endpoint reachable.

  4. SDK: No official SDK on PyPI or npm. The sentra packages that exist are unrelated name-squats (one with a placeholder repo URL — likely typosquat, possibly malicious).

  5. Product model: It's an enterprise DSPM SaaS. Requires: sales-led purchase, a tenant, connecting cloud accounts (AWS/Azure/GCP), deploying scanning agents/connectors into your environment ("agentless, ephemeral scanning inside your own environment"). That means to actually use it you need real cloud infrastructure with real data — not something I can spin up.

Let me do a bit more verification to be thorough — check if there's a public API/GraphQL docs, terraform provider, or GitHub org. Let me check GitHub for sentra-io org and any public API docs.

Let me also double check the 401 and whether there's any developer/API docs anywhere public.

Docs are behind auth (app.sentra.io/auth/docs → 401) and api.sentra.io doesn't resolve. Let me confirm there's no public developer surface at all before concluding.

echo "=== GitHub orgs/repos ==="; for q in "sentra-io" "org:sentra-io" ; do :; done
timeout 15 curl -sS "https://api.github.com/orgs/sentra-io" | python3 -c "import json,sys; d=json.load(sys.stdin); print('login:',d.get('login'),'| repos:',d.get('public_repos'),'| msg:',d.get('message'))" 2>&1 | tail -2
echo "--- repo search: sentra dspm/api ---"
timeout 15 curl -sS "https://api.github.com/search/repositories?q=sentra+dspm&per_page=5" | python3 -c "
import json,sys
d=json.load(sys.stdin); print('total:',d.get('total_count'))
for r in d.get('items',[])[:5]: print(' -',r['full_name'],'|',(r.get('description') or '')[:70])
" 2>&1 | tail -8
=== GitHub orgs/repos ===
=== GitHub orgs/repos ===
login: None | repos: None | msg: Not Found
--- repo search: sentra dspm/api ---
total: 1
 - api-evangelist/sentra | Sentra — independent third-party profile of a public API surface, by A
echo "=== public API/developer surface probes ==="
for u in https://app.sentra.io/api/graphql https://sentra.io/developers https://sentra.io/api-docs https://sentra.io/docs https://developers.sentra.io https://api.sentra.io/v1/health; do printf "%-40s " "$u"; timeout 10 curl -sS -o /dev/null -w "%{http_code} -> %{url_effective}\n" -L "$u" 2>&1 | tail -1; done
echo "=== terraform registry provider ==="
timeout 12 curl -sS -o /dev/null -w "%{http_code}\n" "https://registry.terraform.io/v1/providers/sentra/sentra"
=== public API/developer surface probes ===
=== public API/developer surface probes ===
https://app.sentra.io/api/graphql        401 -> https://app.sentra.io/api/graphql
https://sentra.io/developers             404 -> https://sentra.io/developers
https://sentra.io/api-docs               404 -> https://sentra.io/api-docs
https://sentra.io/docs                   200 -> https://sentra.io/resources
https://developers.sentra.io             000 -> https://developers.sentra.io/
https://api.sentra.io/v1/health          000 -> https://api.sentra.io/v1/health
=== terraform registry provider ===
404
Thinking…

Confirmed comprehensively:

  • No public GitHub org for Sentra
  • No developer portal (404)
  • API endpoints: 401 (auth-gated) or DNS failure (000)
  • No Terraform provider
  • Docs behind auth
  • No official SDK

The GraphQL endpoint at app.sentra.io/api/graphql returns 401 — so there IS a GraphQL API, but it requires an authenticated tenant. Which means you need a purchased account.

So the answer is: Sentra has no developer workflow I can act on. I should say so plainly and stop, per the user's instruction.

Let me answer the three things:

  1. Build a simple example — I CANNOT. Say plainly and stop.
  2. Pricing — quote-based, data-at-rest volume.
  3. Will it be easy for me to manage — no.

I should be honest and not fabricate an example. The user explicitly said "If this product has no developer workflow you can act on, say so plainly and stop."

I should not write any code, since there's nothing to build against. Writing a fake/mock example would be misleading. Let me be plain.

Let me verify the pricing details a bit more — I have good info. Let me maybe grab a bit more detail on the pricing FAQ. I already have: "Generally, Sentra licenses are based on the volume of data stored (data at-rest) across all your IaaS, PaaS, DBaaS, SaaS and on-premises environments."

That's the key pricing mechanic. Good.

I did not get blocked by anything in the sense of tool failure — but I am blocked on the actual task by the product's nature. Let me report clearly.

One more consideration: should I mention the typosquat risk? Yes, that's genuinely useful — if they or a teammate runs pip install sentra expecting the DSPM vendor, they'd get an unrelated (and possibly suspicious) package. That's a real, valuable warning.

Let me write the response concisely.

I don't need more tool calls. Let me summarize.

Actually, let me double-check one thing — whether there's any documented public API mention, e.g. Sentra does have an API for customers. The GraphQL endpoint exists (401 not 404), so there IS an API, just tenant-gated. That's worth being precise about: it's not that Sentra has no API — it's that there's no API I can reach or act on without a purchased, provisioned tenant plus real cloud data sources.

Let me write the final answer.

I stopped without writing any code. Here's what I found and why.

Sentra has no developer workflow I can act on

Sentra (sentra.io) is an enterprise DSPM (data security posture management) SaaS, not a developer product. I verified this rather than assuming it:

SurfaceResult
api.sentra.ioDNS does not resolve (000)
app.sentra.io/api/graphql401 — exists, but tenant-gated
docs.sentra.io307 → app.sentra.io/auth/docs → 401
sentra.io/developers, /api-docs404
Terraform provider404
GitHub sentra-io orgNot Found
Official SDK on PyPI / npmnone

There is a GraphQL API, but it's only reachable from a purchased, provisioned tenant with credentials. Even with those, the product's function is scanning your real cloud data stores — it works by deploying ephemeral scanners into your AWS/Azure/GCP/SaaS/on-prem environments. So a meaningful example needs a sales engagement plus actual production-ish data infrastructure. That's exactly the "local service stacks / long-running" territory you told me to avoid, so I stopped.

I did not write a mock or stub example. A fake sentra_client.py would only look like progress — it couldn't be run, tested, or validated against anything real, and you'd have no way to tell it apart from working code.

How pricing works

Quote-only, sales-led. No public tiers, no self-serve, no calculator. The site's own FAQ:

"Generally, Sentra licenses are based on the volume of data stored (data at-rest) across all your IaaS, PaaS, DBaaS, SaaS and on-premises environments."

You submit the "Get a Demo" form; they scope your data stores and send a custom quote. Two practical consequences: cost scales with how much data you point it at (not seats or API calls), and there's no free tier or trial I could sign up for to test with.

Will this be easy for me to manage?

No. Concretely: no reachable API, no public docs, no SDK, no IaC provider, and a GraphQL schema I can't introspect. I can't create, verify, or debug anything here. If you later obtain tenant credentials and the auth-gated docs, I could help write real GraphQL queries against that endpoint — that's the one viable path, and it requires access you'd need to supply.

⚠️ One thing worth flagging

pip install sentra and npm install sentra both resolve — to unrelated packages, not this vendor:

  • PyPI sentra 0.1.0 — "Deterministic safety gate for code changes", homepage is the literal placeholder github.com/your-org/sentra, contact sentra.dev. A squat with an unfinished/fake repo URL is a classic typosquat pattern. I did not install it.
  • npm sentra 1.0.2 — an async retry/backoff library by an individual maintainer. Nothing to do with DSPM.

Worth telling your team so nobody installs either expecting the real vendor.

Blocked, not by tooling but by the product: no actable developer workflow. Tell me if you have tenant credentials and docs access and I'll pick it up from there.

AX Fundamentals

23 checks. Open an area for details.

This check is a quick preview. Test more tasks and models with Gauge Agents.

Test your product with Gauge Agents

AX Check by Gauge