One protection layer in front of your applications
WAF, DDoS protection, load balancing, DNS and certificate management in a single console. Runs on-premise, in an air-gapped environment, or as SaaS.
What it does
Web application firewall
Built on the ModSecurity engine and the OWASP Core Rule Set. Detects SQL injection, XSS, remote code execution, file inclusion and bot traffic. Four sensitivity levels let each organisation set its own false-positive balance.
Learning mode
Rules run but traffic is not interrupted. You see which rule matches which request in real traffic, weed out false positives, and switch to blocking when ready.
Layered DDoS protection
Connection and request-rate limits at L3-L4; behavioural analysis at the application layer. Protection level is set per pool.
Load balancing
Round robin, least connections, source IP and URI-based distribution. Active health checks, backup origin and planned maintenance mode.
Authoritative DNS + DNS firewall
Full record management, zone import, external secondary via TSIG. Category-based DNS filtering.
Certificate management
Central store with PEM and PFX support, ACME-compatible automated issuance, TLS 1.0–1.3 selection, HSTS, HTTP/2 and chain validation.
How it works
Sentra has three layers: management, edge nodes and logging. Traffic passes only through the edge nodes; protection continues even if the management layer is unavailable.
Management
Policies, pools and certificates are configured here and distributed to the edge nodes. Every change is written to the audit trail and can be rolled back.
Edge nodes
The layer that terminates, inspects and forwards traffic to the origin. Scaled horizontally; if one node fails, traffic keeps flowing through the others.
Logging
Event and access records are collected centrally; they feed the analytics and produce the data that steers Penetra's scanning.
Matched to your constraints
See it with your own traffic
Walk through the Sentra console and Penetra's output in a demo environment; we will size the deployment model and capacity against your own traffic profile.