Cyber defence platform

Sees the attack. Explains why.

SENTINEL AI finds the attack in a stream of events, filters out false alarms and shows its reasoning. A person makes the decision.

0¹false alarms across 2.2 million network flows of open data
×48fewer alerts than the conventional approach on the same events
6UN languages, with explanations for analysts, management and auditors
The problem

Same data. 429 alerts or 9 cases.

The conventional approach raises an alert for every suspicious event, and the analyst drowns. On the open CICIDS2017 dataset it raised 429 alerts, 188 of them false. SENTINEL AI turned the same signals into 9 cases, none of them false.

false alarm · 188alert on a real attack · 241
429alerts from the conventional approach
9cases from SENTINEL AI, 0 false
¹ CICIDS2017 with the corrected KU Leuven labels (IEEE CNS 2022): four attack days, about 550,000 flows a day. The same detectors for both approaches.How we counted →
How it works

From event to case in four steps

  1. 01

    Signal

    91 behavioural rules at the base. Each knows how much more often its signal appears during an attack than in normal work.

  2. 02

    Context

    The weight of each piece of evidence is adjusted to what the organisation knows: the machine's role, the account's rights, the maintenance window.

  3. 03

    Link

    Signals that share a process, a session, an account or an address are gathered into one case with a beginning and an end.

  4. 04

    Score

    Evidence is combined with Bayes' theorem. A case is raised only when the evidence is genuinely sufficient.

More about the technology →
Explainable AI

Every conclusion comes with evidence

Each case carries its reasoning: what evidence was found, how much each piece weighs, and why together it was enough.

  • The analyst sees the evidence and its weights
  • Management reads the same thing in plain words
  • The auditor checks the decision against a signed ledger

Ransomware

Critical
  1. Document started a command toolT1204.002×40028.6%
  2. Hidden command textT1027.010×22098.9%
  3. Reading the password store in memoryT1003.001×2,500>99.9%
  4. Recovery points destroyedT1490×4,000>99.9%
  5. Files being encrypted in bulkT1486×60,000>99.9%
prior 0.1%threshold 60%confidence
A person decidesIsolate the computer ws-013 · awaiting decision

The product's real rules and weights. The score is shown without context adjustments.

The other half of the platform

Checking a project before launch

Source code, libraries, forgotten passwords, packaging and the published site. Forty warnings about one outdated library become one task, with an explanation of what to fix.

More about project checks →
≈240kpublished vulnerabilities in a local OSV database, checked offline
40 → 1warnings with a common cause become one task
PDFa report on what to fix, for your team or a contractor
Security

A person decides. Everything is recorded.

Inside the perimeter

Data never leaves your network

Analysis runs on your server. Telemetry, evidence and decisions stay with you.

Ledger

A signature on every decision

A SHA-256 hash chain and an Ed25519 signature. The ledger's integrity can be verified from outside with the public key.

Zero trust

Access is checked every time

Tokens live 15 minutes and are bound to the device. Before any action that could disrupt work, you confirm who you are again.

Languages

Six UN languages

Interface and explanations in English, Russian, Arabic, Chinese, Spanish and French.

More about security →
Pilot

Test it on your own data

A pilot runs on one server inside your network. You see what the platform finds there, and how many alerts stop reaching your analysts.

Request a pilot →