Skip to main content
Glama

Was ist Sentrik?

Sentrik ist eine CLI + Dashboard, die Codierungsstandards, Compliance-Regeln und Sicherheitsrichtlinien bei jedem Commit durchsetzt. Entwickelt für Teams, die KI-Codierungsagenten (Claude Code, Cursor, Copilot) einsetzen, bei denen Code schneller generiert wird, als Menschen ihn überprüfen können.

Das Problem: KI-Agenten schreiben Code, der funktioniert, aber gegen Sicherheitsrichtlinien, Compliance-Anforderungen oder Architekturstandards verstoßen kann. Niemand bemerkt es bis zum Audit.

Die Lösung: Sentrik scannt jede Änderung gegen regulatorische Standards (OWASP, SOC 2, HIPAA, PCI-DSS, FDA IEC 62304 und mehr), blockiert PRs, die durchfallen, und erzeugt auditfähige Nachweise.

Related MCP server: DevStandards MCP Server

Installation

pip install sentrik

Die Installation gibt dir sofort die kostenlose Stufe – 6 Standardpakete, 193 Regeln, ohne Lizenzschlüssel oder Anmeldung. Kostenpflichtige Stufen werden mit einem Lizenzschlüssel von hello@sentrik.dev aktiviert.

Schnellstart

# 1. Initialize your project (auto-detects language, frameworks, CI)
sentrik init

# 2. Scan your code
sentrik scan

# 3. Enforce the gate in CI (exit 1 on failure)
sentrik gate

# 4. Launch the dashboard
sentrik dashboard

Kostenlose Stufe (für immer, ohne Kreditkarte)

Sentrik enthält 6 Standardpakete mit 193 Regeln kostenlos:

Paket

Regeln

Was es erkennt

OWASP Top 10

69

SQL-Injection, XSS, Authentifizierungsfehler, SSRF und mehr

SOC 2

30

Trust-Services-Kriterien für Sicherheit & Verfügbarkeit

Python-Sicherheit

18

eval/exec, pickle, subprocess, Django/Flask-Schwachstellen

Go-Sicherheit

15

Injection, Krypto-Missbrauch, unsafe, Nebenläufigkeitsfehler

Supply-Chain-Sicherheit

26

SLSA, SBOM, Abhängigkeitsintegrität, KI-Tool-Lieferkette

C/C++-Codierungsstandards

35

Moderne C/C++-Sicherheits- und Schutzpraktiken

Plus integrierte Befehle auf jeder Stufe:

  • sentrik scan / sentrik gate – Scannen und durchsetzen

  • sentrik vulns – Schwachstellenscan für Abhängigkeiten (CVEs)

  • sentrik sbom – Software-Stückliste (Bill of Materials)

  • sentrik secrets – Erkennung hartcodierter Geheimnisse

  • sentrik dashboard – Web-UI mit Ergebnissen, Diagrammen und Berichten

  • sentrik threat-model – STRIDE-Bedrohungsanalyse

  • sentrik quality-score – Codequalitätsbewertung (0–100)

Kostenpflichtige Stufen

Kostenlos

Team

Organisation

Standardpakete

6 (193 Regeln)

18 (475 Regeln)

24 (595 Regeln)

OWASP, SOC 2, Supply Chain, C/C++

Ja

Ja

Ja

HIPAA, PCI-DSS, ISO 27001, GDPR

Ja

Ja

FDA IEC 62304, NIST, CMMC, Cloud IaC

Ja

Ja

MISRA-C, DO-178C, ISO 26262

Ja

Schwachstellenscan

Ja

Ja

Ja

Dashboard

Ja

Ja

Ja

Arbeitsabgleich (Work Items)

Ja

Ja

Benutzerdefinierte Regelpakete

5

25

100

Paralleles Scannen

Ja

Governance- & Audit-Log

Ja

Kostenpflichtige Stufen sind erhältlich über hello@sentrik.dev – siehe sentrik.dev/pricing.

CI/CD-Integration

GitHub Actions (Marketplace)

# .github/workflows/sentrik.yml
name: Sentrik Gate
on: [pull_request]
jobs:
  gate:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0
      - uses: maxgerhardson/sentrik-community@v1

Das war's – eine Zeile. Die Action erkennt automatisch den PR-Kontext, führt die Prüfung aus, lädt SARIF in GitHub Code Scanning hoch und hängt den Ergebnisbericht als Artefakt an.

Mit Optionen:

      - uses: maxgerhardson/sentrik-community@v1
        with:
          packs: "owasp-top-10,soc2,supply-chain-security"
          fail-on: "critical,high"
          license-key: ${{ secrets.SENTRIK_LICENSE_KEY }}

Mit Ausgaben (Outputs):

      - uses: maxgerhardson/sentrik-community@v1
        id: sentrik
      - run: echo "Found ${{ steps.sentrik.outputs.findings-count }} findings"
        if: always()

GitLab CI

sentrik:
  image: maxgerhardson/sentrik:latest
  script:
    - sentrik gate --git-range "origin/main...HEAD"
  rules:
    - if: $CI_PIPELINE_SOURCE == "merge_request_event"

Azure Pipelines

- script: |
    pip install sentrik
    sentrik gate --git-range "origin/main...HEAD"
  displayName: Sentrik Gate

KI-Agenten-Integration

Sentrik funktioniert als MCP-Server für KI-Codierungsagenten:

# Start MCP server for Claude Code, Cursor, VS Code
sentrik mcp-server

Der MCP-Server gibt KI-Agenten Echtzeitzugriff auf Compliance-Regeln, Scan-Ergebnisse und Sanierungsanleitungen – damit sie von Anfang an konformen Code schreiben.

Beispielkonfigurationen

Starter (Web-App)

# .sentrik/config.yaml
standards_packs:
  - owasp-top-10
  - supply-chain-security
gate:
  fail_on:
    - critical
    - high

Gesundheitswesen / Medizinprodukte

standards_packs:
  - owasp-top-10
  - hipaa
  - fda-iec-62304
  - supply-chain-security
gate:
  fail_on:
    - critical
    - high
    - medium

Fintech

standards_packs:
  - owasp-top-10
  - pci-dss
  - soc2
  - supply-chain-security
gate:
  fail_on:
    - critical
    - high

Behörden / Verteidigung

standards_packs:
  - owasp-top-10
  - nist-800-53
  - cmmc
  - supply-chain-security
gate:
  fail_on:
    - critical
    - high
    - medium

Community

  • Diskussionen – Fragen stellen, Tipps teilen, zeigen, was du gebaut hast

  • Issues – Fehler melden oder Funktionen anfragen

  • Dokumentation – Vollständige CLI-Referenz, Konfigurationsanleitung, API-Dokumentation

Support

Kanal

Für

GitHub Discussions

Fragen, Ideen, Community-Hilfe

support@sentrik.dev

Direkter Support (kostenpflichtige Stufen)

sales@sentrik.dev

Preise und Lizenzierung

Lizenz

Proprietär. Kostenlose Stufe für immer verfügbar, ohne Kreditkarte.

F
license - not found
Not graded
quality - not tested
B
maintenance

Maintenance

UpdatingMaintainers
UpdatingResponse time
3wRelease cycle
6Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    A
    quality
    D
    maintenance
    Provides real-time policy enforcement for AI coding agents by intercepting and validating their actions against organizational standards like naming conventions, security policies, and compliance rules before execution. Prevents violations through immediate feedback and auto-correction suggestions.
    5
  • A
    license
    Not graded
    quality
    C
    maintenance
    Transforms static coding standards into a queryable live data store for AI agents, delivering task-specific rules and fix guidance on demand. This optimizes context window usage through progressive disclosure, ensuring agents apply relevant governance without loading massive documentation.
    2
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Integrates authoritative security compliance frameworks (ISO 27001, NIST 800-53, OWASP ASVS, NIST SSDF) into AI-assisted development, offering control lookups, cross-framework mappings, build-time guardrails, and automated audit evidence generation.
    169
    3
    MIT

View all related MCP servers

Related MCP Connectors

  • Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.

  • Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.

  • Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/maxgerhardson/sentrik-community'

If you have feedback or need assistance with the MCP directory API, please join our Discord server