
jSentinel — Secure software & AI, end to end.
Open-source Java security, security & AI-security consulting, AI systems built secure by design, and developer training — independently built in the EU.
What we do
Open Source
jSentinel for Java — EUPL-licensed, mutation-tested security for Core Java, REST & Vaadin. More projects to come.
Security Consulting
Application & Java security: jSentinel integration, security reviews, bootstrap hardening, custom SPIs, architecture — a direct line to the author.
AI-Security
Secure RAG & LLM systems: threat modeling, prompt-injection & data-exfiltration defenses, retrieval & tool guardrails, evaluations.
jSentinel AI
Building AI, secure by design: AI advisory, AI apps, corporate LLMs, RAG systems & personal assistants — self-hosted or EU-cloud, your data stays yours.
Academy
Secure Coding in Java and AI-Security for Developers — hands-on training, on-site, live-online, or on-demand.
Support & Maintenance
Commercial SLAs for the open-source libraries — response times, security patches, version maintenance, written assurances.
The open-source core — jSentinel for Java
A framework-neutral security library for the JVM — one decision model, three adapters, no Spring or Jakarta required. The foundation the rest of jSentinel stands on, held to a hard, measurable bar.
Framework-Neutral Core
jSentinel-core has zero Vaadin/Servlet/REST dependencies. Authentication, authorization, audit, sessions, multi-tenancy, Policy API — all via Java SPI.
One Annotation Set, Three Adapters
The same @RequiresRole / @RequiresPermission protect Vaadin views, REST handlers, and plain Java services (SecuredProxy.wrap(…)).
Mutation-Tested
Tests that actually catch bugs — 87–97 % mutation coverage on the mature modules, with site-native PIT reports per module.
AI-Ready Integration
Integrate jSentinel into a Vaadin, REST or Standalone app from a single prompt — ten Claude Code skills. The docs ship an llms.txt map, too.
Built on evidence, not claims
Security software you can verify — every claim backed by an artifact.
Mutation-Tested
Line coverage says code ran; mutation testing proves the tests caught the change. The mature modules carry 87–97 %.
Standards-Mapped
OWASP ASVS V2, NIST SP 800-63B and a full 40-CWE traceability matrix — not a marketing checkbox, a mapped table.
Supply-Chain Ready
CycloneDX SBOM in the build, reproducible builds, EUPL 1.2. The provenance an enterprise review actually asks for.
🇪🇺 Made in the EU
Independent, EU-based maintenance. No third-party CDNs or trackers on this site — privacy by default.
Ship it — securely.
Adopt the open-source core yourself, bring us in to secure your app or AI system, or train your team. Pick the path that fits.
Java & application security, jSentinel integration, audits, and AI-security for RAG / LLM systems — hands-on, with the author.
- Free 30-min scoping call
- Fixed-scope or retainer
- Secure RAG & guardrails
Hands-on, lab-driven courses: Secure Coding in Java and AI-Security for Developers — on-site, live-online or on-demand.
- Tailored to your stack
- Teams or individuals
- English or German
Fund the roadmap so the next features ship faster. The core stays EUPL 1.2 — individuals via GitHub Sponsors, companies via tiers.
- From $5/month
- Corporate tiers
- Project stays EUPL 1.2