Observe. Verify. Respond.
Sentinel finds the AI running inside your network and the sensitive data sitting exposed outside it. Then it turns what it finds into proof your controls are working. All of it on infrastructure you own.
Three questions, answered together
Sentinel is one package built from three products. Each answers a different question, and because they write to the same record, the answers hold together.
What AI is actually running on our network?
RDR finds every AI agent and puts you in charge of what each can do.
See moreCan we prove our controls were working?
FEN turns every check into a sealed record, counted across every framework.
See moreWhat can someone outside already see and reach?
RVN maps your exposure from the outside and labels the data nobody classified.
See moreEvery AI agent, including the ones nobody registered
AI agents arrive bundled in licensed software, built in-house, or stood up one afternoon and never written down. RDR watches processes as they start rather than scanning on a timer, inspecting each one for provider keys, model runtimes and tool configurations, so the ones nobody wrote down appear alongside the ones you approved.
Each agent you approve carries its own credential, a list of what it may reach, a daily budget and a rate limit. Every request is checked against that list. An agent cleared to use a model is not automatically cleared to use every tool behind it.
- A named list of every agent running
- Limits on what each one may do
- A record of every call it makes
We can see inside 469 of the 492 programs running on 3 machines.
The other 23 are identified by name and network activity only. An agent running under a renamed program could hide among them.
COMPLIANCE LIBRARY
One check, counted against every framework it fits
FEN checks your environment on a schedule and seals each result as it is produced. Because the frameworks you owe overlap heavily, one passing check is counted against every one of them that asks for it.
The work happens once instead of once per framework, and the evidence is already there when somebody asks for it. Your security plan stays current because it rebuilds from what is true today rather than what was written last year.
- Evidence sealed as it is produced
- Frameworks mapped for you, not by you
- The audit pack, ready before it is asked for
What an outsider can reach, before they reach it
RVN looks at your estate from the outside, then works inward with credentials you grant to label the data nobody classified. It reads and never writes.
Every finding carries the proof that it is real. A handful of sample rows come back with the sensitive parts hidden, enough to reproduce the exposure without exposing it twice. Nothing is changed, and nothing outside the systems you name is ever touched.
- Internet-facing systems and leaked logins
- Unclassified personal data, financial and health records
- Proof attached to every finding, sensitive parts hidden
POA&M
Six capabilities across the package
Each one is useful on its own. Running them together means every finding, refusal and check lands in the same evidence trail.
Shadow AI discovery
Every agent surfaced, whether or not anyone registered it.
Policy on every call
Each agent limited to what you decide it may do.
Continuous evidence
Checks run on a schedule against your live environment.
One check, many frameworks
A passing check counted everywhere it applies.
The outside-in view
Your estate as somebody outside would find it.
A sealed record
Every result linked to the one before, so tampering shows.
Evidence that stands on its own
A regulator, a customer, your board. Whoever is asking can confirm the record themselves, because the export carries the method for checking it. Every action in order, every finding with the rule it answers, and the policy in force, proven unedited.
Common questions
How do you know which frameworks we owe?
Onboarding asks about obligations in business terms rather than framework names. Do you handle health data, take card payments, hold federal contracts. Those answers resolve to a framework set through a curated rules table, and every recommendation arrives with its written rationale, so you can challenge it rather than take it.
What happens if the scoping is wrong or missing?
It runs the full sweep and says so. A system that quietly narrows scope on failure produces a flattering score at the exact moment it should produce a loud one. Complete evidence is always defensible, so a control ruled not applicable needs written justification, and unjustified exclusions are rejected when the pack loads rather than flagged for later.
Is a blocked action recorded as thoroughly as an allowed one?
Yes. Enforcement systems often log what they permitted and drop what they stopped, which loses exactly the evidence that shows the control was working. A refused attempt is a positive result and lands in the chain like everything else.
Can you catch an agent that reads a file and then sends it somewhere?
Yes, and this is where single-call rules run out. Reading a file is permitted. Calling a model is permitted. Doing both in quick succession is the shape of exfiltration, so a data access followed by external egress by the same identity inside a short window is recorded as a finding with both calls attached. We do not label it exfiltration, because a nightly job that reads a table and summarizes it looks identical, and a system that cries wolf teaches people to ignore it.
What about machines you cannot see?
They go to the top of the list, not the bottom. Rank hosts by what was found and every unmonitored machine scores zero and looks healthy. A host we cannot currently observe is ranked above every host we can, and the console says it cannot see it rather than showing a number.
Can Sentinel run air-gapped?
Yes, and the bar is set deliberately high. No license check, no telemetry, no update fetch, no content delivery network reference in the console, and no reliance on a hosted model endpoint for any feature that changes the result. AI assistance runs against models on your own hardware, which is what keeps disconnected operation whole rather than diminished.
Will this get us certified?
No software can. An accredited third-party assessment organization grants the certification. Sentinel produces the evidence and the artifacts they will ask for, generated from live data. Controls that cannot be automated stay attestation-backed and human-owned, and the job there is to make the attestation dated, attributed and chained rather than to pretend it was measured.
Does this replace the security tools we already run?
No. Sentinel is the evidence, mapping and enforcement layer over what you already have. Where you run a vulnerability scanner or a SIEM, it works alongside them and turns what they surface into a record that holds up.
See what is already running
Sentinel records everything and blocks nothing until you say otherwise. A first look costs only the install.