Technology

How the platform is built

An in-house attack detection core, code and website checks, and an AI assistant on top of them. Everything runs on the customer's server, inside their network, and every decision can be checked.

Measured

Figures you can recompute

0%false positives on the organisation model across 8 runs. A conventional approach: 59–61% on the same data.
9alerts and not one false on 2.2 million CICIDS2017 network flows. A conventional approach raised 429.
930/sevents on one 8-core server, in a 5-minute load test.
101detection rules covering 71 techniques and 12 tactics of MITRE ATT&CK.
≈300kOSV vulnerability records for eight programming languages, checked without internet access.
6UN languages in the interface and the explanations, Arabic right to left.

The method and the measurement code ship with the product: the Accuracy Lab recomputes these figures on the customer's own machine.

Signal path

From a log event to a person's decision

Conventional tools send the analyst every suspicious event. HCCA first links events into a chain and accounts for how the organisation normally works, and only then decides whether there is an incident.

  1. 01

    Collection

    Agents for Windows (Security, Sysmon and PowerShell logs) and Linux (program starts from auditd), and syslog from servers and firewalls: iptables, CEF, LEEF, FortiGate, Cisco ASA. Every agent has its own identity.

  2. 02

    HCCA core

    The causal chain of an attack, an adjustment for the organisation's normal work, a Bayesian estimate of confidence. Below the threshold there is no incident.

  3. 03

    Decision

    Four explanations of one case and proposed actions with their cost to operations. A person approves.

  4. 04

    Ledger

    Every entry is chained to the previous one by SHA-256 and signed with Ed25519. The ledger is verified outside the platform.

Modules

What is inside

Built in-house

The HCCA core

Hybrid Causal-Contextual Analysis. Process trees, accounts, hosts and network flows are assembled into one attack chain. Evidence accumulates in log-odds, and each item's contribution is visible in the explanation. Every incident carries an input hash and a ruleset version: the same input gives the same result.

Language layer

SENTINEL Assistant

Analyses an incident and forecasts the attacker's next steps, writes a fix plan for developers and a shift briefing, and answers questions. It runs on a pluggable language model, in the cloud or locally inside the network. Host and account names are masked before sending, and passwords are never sent.

AppSec

Code and website checks

Eight ecosystems: Python, JavaScript, Java, Go, PHP, Ruby, Rust and .NET. A local OSV database with more than 200,000 known malicious packages, CVSS 3.x scoring. Secrets, dangerous code, container configuration. Noise is removed by the same method as in the core.

Platform security

Zero trust

Per NIST SP 800-207: short-lived tokens bound to the session and the device, a session trust score, four least-privilege roles, two-factor sign-in and re-authentication for critical actions.

Collection

Machine identities

Every agent has its own token, and the server keeps only its hash. An agent can only deliver events. An on-disk buffer and per-log bookmarks: a restart neither loses nor duplicates anything.

Explainability

One decision, four explanations

For the analyst, management, the auditor and in plain words. All four are built from one decision tree, so they never disagree. Aligned with NIST CSF 2.0, ISO/IEC 27001:2022 and MITRE ATT&CK.

Engineering choices

Why it is built this way

01

No neural network in the decision path

A conclusion that cannot be broken down into evidence cannot be shown to an auditor. The platform has a language model, but the core makes the decisions, and every accuracy figure was obtained without it.

02

No heavy ML libraries

The core is Python and probability. Fewer dependencies, a smaller image and a smaller attack surface for the security tool itself.

03

Inside the customer's network

The platform runs in a closed network. Internet access is needed only to refresh the vulnerability database, and that file can be carried over from another machine.

Stack

What it runs on

Mature open technologies. The full list of dependencies with their licences ships in CycloneDX format.

LayerTechnology
Core and APIPython, FastAPI, PydanticEvery request is validated against a schema.
DataSQLAlchemy, Alembic, SQLite or PostgreSQLSQLite for one server, PostgreSQL for several writing nodes. The schema evolves through migrations.
Cryptography and accessEd25519, SHA-256, JWT, TOTP
ConsoleReact, TypeScript, Vite, TanStack Query, Tailwind CSSSix languages, right-to-left interface for Arabic.
Language layerPluggable models: cloud by API or localAnswers follow a strict schema, data is masked before sending, every request goes to the audit ledger.
CollectionWindows and Linux agents, syslog from servers and firewalls, ingest API
Community rulesSigma (SigmaHQ): more than 900 rules, in shadowA rule is switched on only after a week of quiet on the customer's network, and then only corroborates other evidence.
DeliveryDocker, Windows service, one-click installWorks without internet access.
QualityAutomated tests and CI on every change, SBOMThe Accuracy Lab is built into the product.
Next

The near-term technical plan

  • SENTINEL's own language model

    A model trained on security tasks, so the assistant can run entirely inside a closed network.

  • Scale

    Testing on PostgreSQL with hundreds of real agents.

  • Software and updates

    An inventory of installed software and missing updates on each machine.

  • Public sector

    National software registries and certification.

Pilot

Test it on your own data

A pilot runs on one server inside your network. You see what the platform finds there, and how many alerts stop reaching your analysts.

Request a pilot →