From Endpoint Activity to Actionable Intelligence
How Sentinel captures endpoint telemetry in native Rust, protects offline buffers, isolates multi-tenant records, and delivers high-fidelity security and workforce insights without host instability.
Distributed Telemetry & Ingestion Pipeline
The 4-Step Intelligence Pipeline
Collect, Normalize, Analyze, and Respond
Every telemetry event follows a strictly governed, privacy-bounded workflow.
Collect
The Sentinel endpoint agent is built in native Rust and runs as a standard Windows Service. Operating strictly in user space, it hooks into OS event APIs to capture process execution, window context, active applications, and USB peripherals without blue-screen risks. A lightweight Manifest V3 companion extension captures browser tab and upload metadata across Chrome and Edge.
Zero keystroke recording, zero password capture, and zero clipboard text reading. Off-hours and personal domains can be excluded via policy.
sentinel-agent.exe (Windows Service) + Manifest V3 Browser Native Companion
Performance Verification
Engineered for Speed, Tested Under Load
Empirically validated resource usage under sustained enterprise desktop conditions.
Measured across enterprise desktop workloads with 50+ background processes
Native Rust binary uses a fraction of traditional electron or Java endpoint agents
Runs as standard Windows Service; zero kernel driver panics or BSOD risk
Compressed JSON batches over TLS 1.3 prevent bandwidth choking on remote links
Encrypted local SQLite queue stores telemetry through extended flight and field travel
Device tokens and registration keys secured in Windows Credential Manager
Deployment Architecture
Flexible Deployment Models
Choose between fully managed multi-tenant cloud or isolated customer-managed on-premise infrastructure.
Managed Cloud Control Plane
Zero Infrastructure Overhead
Sentinel manages telemetry ingestion scaling, TimescaleDB retention partitions, automated security patching, and platform updates while enforcing strict organization-level data segregation.
- Automatic updates & managed database scaling
- Silent GPO / Intune MSI deployment bundles
- TLS 1.3 ingestion with isolated tenant databases
Self-Hosted / Air-Gapped
100% Data Sovereignty & Isolation
Deploy the complete Sentinel control plane, Spring Boot services, and TimescaleDB instances directly inside your own private cloud VPC or air-gapped on-premise data center.
- Zero outbound internet dependencies required
- Compatible with isolated enterprise PKI authorities
- Full control over database retention & audit archives
Test the Architecture in Your Sandbox
Deploy Sentinel on test Windows workstations, inspect the local SQLite queue, and verify user-mode non-kernel execution.