Security

Security & trust model.

Sentinel Telemetry sits close to your source code and your credentials. We designed it so your security team can verify every claim here themselves. It is fully self-hosted AI monitoring and observability — nothing phones home.

Data stays on your infrastructure Agent logs are read read-only by the stl spoke on loopback, which reports to ST Hub inside your infrastructure. No data is ever sent to a vendor cloud — there is no phone-home. YOUR INFRASTRUCTURE agent logs on the machine stl spoke 127.0.0.1 loopback ST Hub your servers read-only vendor cloud no phone-home

Read-only on agent data · loopback by default · nothing leaves your walls.

Runs on your infrastructure

On-premises or your own cloud — Docker, Helm, or Terraform. No vendor-hosted SaaS. No data processor agreement to negotiate.

No phone-home

Licensing is an offline signed file. The product makes no unsolicited outbound calls and is fully functional air-gapped.

Read-only on agent data

Session logs are read read-only; in containerized deployments this is enforced by the kernel via read-only mounts.

Loopback by default

The local dashboard binds to 127.0.0.1. Nothing leaves a machine without explicit configuration.

Fail-open

No hook, gateway, or scanner may ever hang or block an agent if our software is down, slow, or wrong. This is a hard release gate, tested against four failure modes.

Transparent monitoring

Any reporting level active on a machine is always visible to the employee on their own dashboard. No stealth mode exists — by construction.

Source-available

Licensed customers get full source to read, audit, and build. Nothing is a black box next to your credentials.

Sensitive values masked

Secrets and PII are masked in every alert, log, and stored finding. The DLP system never becomes the leak.

Compliance posture.

Sentinel Telemetry supports GDPR-conscious deployment: data minimization, retention controls, source-side redaction, RBAC, and works-council/DPIA-ready transparency. Lawful basis and employee notification are the deploying organization's responsibility — we provide the controls that make a compliant deployment practical.

Deployment options.

Runs anywhere you do On-prem AWS Google Cloud Azure
OptionDeliveryBest for
On-prem Docker Compose Single-host installs and fast pilots on hardware you own.
Kubernetes Helm Production clusters with your existing ops tooling.
Client cloud VPC Terraform Your own AWS/GCP/Azure account — your keys, your region.
Air-gapped Offline bundle Isolated networks. Fully functional with no internet access.

Have your security team put us to the test.

Every claim on this page is verifiable in source.