Enterprise Security & Architecture

Built for Enterprise Security. Designed for Employee Privacy.

Sentinel provides deep endpoint visibility and data protection built upon verified technical controls: a native Rust Windows agent, TLS 1.3 transport, strict multi-tenant isolation, and a metadata-only privacy contract.

Native Rust Agent<1% CPU average overhead
Transport SecurityStrict TLS 1.3 enforced
Storage ProtectionAES-256 at rest + DPAPI
Privacy ContractMetadata only · Zero keystrokes
Pillar 01

Platform Architecture & Telemetry Pipeline

Designed as a distributed, high-throughput pipeline connecting lightweight native agents to an isolated enterprise control plane.

Native Rust Endpoint Agent

The Sentinel agent is implemented in native Rust and runs as a standard Windows Service. By operating strictly in user mode rather than kernel space, the agent eliminates blue-screen risks while maintaining a minimal operational footprint (<1% CPU average under sustained enterprise desktop workloads).

TLS 1.3 Telemetry Ingestion

All communication between endpoint agents, browser extensions, and backend ingestion services is strictly secured via TLS 1.3 with optional certificate pinning to eliminate adversary-in-the-middle risks.

Resilient Local Buffering

Endpoints store telemetry in an encrypted local SQLite database (events.db) when traveling or offline. Batched payloads upload automatically upon reconnecting, ensuring continuous audit visibility without gaps.

Multi-Tenant Data Isolation

Backend persistence in PostgreSQL with TimescaleDB applies organization-level tenancy filters to every query, ensuring strict cryptographic and logical boundaries between customer environments.

Pillar 02

Endpoint Security & Tamper Resistance

Built-in protections to ensure continuous agent operation, credential security, and integrity across managed fleets.

Windows DPAPI & Credential Manager

The agent stores device tokens, registration state, and rotating API keys inside the native Windows Credential Manager and Windows DPAPI encrypted storage, preventing unauthorized extraction by unprivileged users.

Self-Defense Service Protection

The Windows Service configuration enforces administrative ACLs to prevent non-administrative users or unauthorized local scripts from terminating, disabling, or modifying agent binaries.

Verified Cryptographic Updates

Agent binary updates distribute with SHA-256 integrity checksum verification and digital signature checks before self-updating through the central supervisor.

Non-Kernel Stability

Because Sentinel uses standard Windows event APIs and non-kernel system hooks, host stability is protected from kernel-level crashes or conflicting driver panics.

Pillar 03

Data Protection & Encryption Standards

Rigorous cryptographic protection for enterprise activity telemetry across storage, transit, and lifecycle phases.

Encryption in Transit (TLS 1.3)

Every API request, agent heartbeat, and browser telemetry batch is encrypted in flight using modern TLS 1.3 cipher suites.

Encryption at Rest (AES-256)

Telemetry events, audit logs, and configuration states are encrypted at rest using industry-standard volume-level AES-256 storage.

Append-Only Audit Logs

Administrative actions, policy changes, user role updates, and data exports are logged in an immutable, append-only security audit trail.

Data Retention Controls

Granular retention schedules allow organizations to automatically purge high-frequency telemetry while preserving aggregated audit summaries according to compliance policies.

Pillar 04

Access Control & Authentication

Role-based access boundaries ensuring the principle of least privilege across all administrative and analytical workflows.

Granular Role-Based Access Control (RBAC)

Pre-configured roles enforce separation of duties: SUPER_ADMIN (system governance), ORG_ADMIN (tenant administration), ANALYST (investigation and policy workflows), and VIEWER (read-only dashboards).

Enterprise SSO & SAML / OIDC Ready

Integrate directly with enterprise identity providers including Okta, Microsoft Entra ID (Azure AD), and Google Workspace for centralized access lifecycle management.

Multi-Factor Authentication Enforcement

Mandatory TOTP / hardware key MFA requirements for all console administrative sessions, protecting access to sensitive telemetry.

Session Revocation & Timeout

Inactivity timeouts and instantaneous administrative session invalidation guard against orphaned console sessions.

Pillar 05

Privacy Boundaries & Ethical Oversight

Engineering guarantees that protect legitimate workforce trust while delivering required enterprise visibility.

Metadata-Only Contract

Sentinel collects operational metadata (application names, file hashes, timestamps, URLs, process trees). It does NOT record raw keystrokes, personal passwords, or clipboard text.

Selective Category Masking

Administrators can configure privacy redaction zones that exclude non-work categories (e.g., personal banking, healthcare portals) from detailed activity records.

Visible Agent Operation

Sentinel is built for corporate-owned devices and governed BYOD with explicit organizational awareness, avoiding covert rootkit behaviors.

Role-Gated Audit Access

Access to granular user-level activity requires explicit ANALYST or ORG_ADMIN entitlements, preventing unauthorized internal browsing.

Vulnerability Reporting & Responsible Disclosure

We prioritize the security of our platform and customer data. If you believe you have discovered a vulnerability or security flaw in any Sentinel component or agent binary, please contact our security team directly:

We acknowledge receipt within 48 business hours and coordinate remediation before public disclosure.

Evaluate Sentinel in Your Test Environment

Test the silent native MSI installer, review local encryption keys, and verify the metadata-only ingestion pipeline firsthand.