AI Defense Plane

Licensed plugin

Sentinel — defensive AI co-designed with the transport

AegisWire Sentinel is a security-native decision system — not a chatbot bolted onto a dashboard, not generic anomaly detection. It knows what a healthy AegisWire session looks like across transport, trust, policy, device posture, DNS, and residency, because it is built for AegisWire’s own architecture. It fuses that telemetry into one risk fabric, then produces only deterministic, bounded, auditable actions. Sentinel is a separately licensed plugin with its own subscription, enabled per tenant, off until activated.

Full CNSA 2.0 suite (US NSA) · UK NCSC-aligned — every customer, every packet

Not commodity UEBA

Co-designed with AegisWire

Commodity “AI security” learns from network data in the abstract. Sentinel is built for AegisWire’s transport, trust, policy, posture, DNS, and residency architecture — so it knows the difference between a healthy session and a suspicious one.

Native to the transport

Sentinel fuses client, gateway, path, posture, policy, DNS, and trust-domain telemetry into one risk fabric. It understands what a secure AegisWire session should be, instead of guessing from raw packets.

Risk with uncertainty

Every decision carries calibrated risk and confidence scores, and Sentinel abstains when uncertainty is too high. Destructive scope is never automatic — it is held for explicit human approval, with the full decision sealed in signed evidence.

Subordinate to crypto

Sentinel never decides whether cryptography is valid, never weakens a primitive, and never overrides a failed signature check. If the AI plane is unavailable, the transport keeps enforcing security deterministically.

Detector ensemble

An ensemble of specialised detectors

World-leading defensive AI is not one monolithic model. Sentinel runs independent detector families — including a live temporal-graph detector over the entity graph — each with its own signal and its own uncertainty estimate, then composes them with calibration and abstention.

Streaming statistical

Tracks moving baselines for handshake-failure rate, retry surges, DNS bursts, bandwidth spikes, and admin auth-failure bursts — catching sudden change against a continuously updated norm.

Sequence reconstruction

A temporal-sequence model flags what it cannot reconstruct: beaconing patterns, low-and-slow exfiltration, route-manipulation sequences, and path-instability behaviour over a window.

Temporal graph

Reasons over the entity graph — identities, devices, gateways, and federated peers — to surface peer anomalies, gateway-compromise indications, lateral-risk propagation, and coordinated misuse via embedding distance.

Threat-intelligence match

Matches signed threat-intelligence capsules against destinations, domains, ASNs, artifacts, and tactics, mapping known-bad severity into the risk fabric.

Posture consistency

Compares signed device-posture attestation against the expected profile and historical device state, so drifting or compromised endpoints raise risk before they cause harm.

Adversarial-input

Detects attempts to manipulate the model itself — schema violations, impossible feature values, shift attacks, and replayed feature digests — and gates high-impact actuation when provenance is in doubt.

Device-posture admission

Trust the device, not just the credential

Sentinel raises a signed device-attested posture object at the handshake and binds it to the session. The gateway gates admission against a signed posture profile — signature, validity window, policy digest, tenant, subject, rollback, and revocation — and fails closed when the evidence does not hold. Posture is part of the trust core, not a dashboard widget.

  • Device-signed attestation

    Sealed to the device key and bound to the handshake transcript.

  • Signed posture profiles

    Distributed as signed, revocable bundles — rollback-protected.

  • Fail-closed admission

    Invalid, expired, or revoked posture is denied, not tolerated.

  • Drift raises risk

    Posture changes feed the posture-consistency detector continuously.

Post-quantum cryptography

The primitives behind every session

Hybrid key exchange
Quantum-safe + classical, combined
ML-KEM-1024X25519
Identity signatures
Post-quantum signed trust chains
ML-DSA-87
Record encryption
Authenticated, per-session keys
AES-256-GCM
Keyed hashing · STREAMHEAL
Integrity and rapid rekey
BLAKE3
Implements US NSA CNSA 2.0 in full · aligned with UK NCSC post-quantum guidance

Bounded actuation

A deterministic action ladder

Sentinel may only trigger a fixed set of bounded actions, escalating one level at a time. Each step is gated by confidence and drift thresholds, and the highest, destructive levels are always held for explicit human approval in the operator console — they never execute autonomously.

LEVEL 0

Observe

No policy change. Sentinel emits evidence and alert metadata only — the baseline for monitor-only deployments.

LEVEL 1

Alert

Raise an analyst-visible alert and request an explanation package. No traffic is disrupted.

LEVEL 2

Verify

Require step-up auth or a posture-attestation refresh, shorten session TTL, restrict to trusted gateways, or tighten the privacy profile — only within pre-authorised bounds.

LEVEL 3

Constrain

Tighten DNS or split-tunnel rules, deny selected applications or destinations, pin routes to a residency zone, or deny new sessions from an entity scope.

LEVEL 4

Isolate

Terminate a specific session, suspend a device or user pending review, quarantine a gateway pool or peer scope, or force re-enrollment.

LEVEL 5

Emergency

Draft a scoped lockdown or security-advisory bundle and request revocation through the deterministic control plane. Destructive scope always requires explicit human authority.

Sentinel will never disable encryption, suppress audit logging, lower posture requirements, widen data export to “improve the model,” or perform cross-tenant destructive actions automatically. The enforcement plane applies an action only if it is in the licensed allowed set, the signed policy posture permits it, the request is unexpired, the signed model is valid, signed evidence for the decision is durably sealed first, and any required human approval exists — and it never silently mutates that request. Autonomous actuation shipped today is per-session quarantine at the Isolate rung; the other rungs observe, alert, recommend, and escalate for human decision.

Your response posture

Monitor-only or active response — you choose

Sentinel runs in the response posture your security team is comfortable with. Start in monitor-only, where it observes, scores, and alerts without ever touching traffic. Graduate to bounded automatic response within your licensed action ceiling, and destructive scope is always held for explicit human approval.

  • Observe

    Monitor-only: evidence and alerts, no traffic impact.

  • Escalate

    Destructive proposals are held; analysts approve or deny them in the console.

  • Bounded automatic

    Acts only within your signed licence's action ceiling.

  • Evidence-first

    A signed evidence capsule is sealed before any action executes.

A separate, licensed plugin

Licensed Add-On
PackagingSeparate plugin
LicensingOwn subscription
ActivationEnabled per tenant
DefaultOff until licensed
Response modeMonitor or active
InferenceResidency-bound

Privacy & deployment

Privacy by default, everywhere it runs

Sentinel senses on metadata first, infers at the edge nearest the signal, and never lets a model update or evidence export cross a residency boundary. It is one architecture across managed, dedicated, self-hosted, sovereign, and air-gapped deployments — differences are flags, not modes.

Metadata first

Operates on transport metadata, policy events, and posture evidence. Raw payload extraction for training is forbidden by default.

Locality by default

Inference happens on-device, on-gateway, or within the tenant boundary — nearest the signal.

Residency by construction

No model update, feature export, or evidence export may violate residency and jurisdiction constraints.

Signed model supply chain

Models, calibrators, feature schemas, and threat-intelligence capsules are signed, verified artifacts with revocation.

Air-gap ready

Offline import of signed model and threat-intel bundles, offline evidence export, offline revocation — no external inference dependency.

Auditable decisions

Every enforcement decision — actuations, holds, rejections, and approval outcomes — is sealed in a signed, hash-chained evidence capsule and archived for review.

Controls posture built to the standards these reviews examine

Commissioned on customer scope SOC 2 ISO 27001 GDPR · UK GDPR HIPAA-style
Licensed plugin

A defense plane that stays in its lane

Sentinel extends AegisWire as a defense-and-orchestration plane. It is not the transport, not the handshake, not the trust root, and not the cryptographic authority — and it remains outside the FIPS 140-3 crypto-core boundary. It is licensed and enabled per tenant, with its own subscription.

Deterministic trust; AI is sensing, scoring, and recommending
Fails safe — transport keeps enforcing if the AI plane is down
Human authority for cross-tenant and infrastructure-wide scope
Full CNSA 2.0 suite & UK NCSC-aligned transport underneath, every packet

Talk to engineering

Request an architecture briefing

A technical walkthrough of the transport, trust model, and deployment options — mapped to your environment and procurement requirements.

Implements US NSA CNSA 2.0 in full · aligned with UK NCSC post-quantum guidance