How the platform is built
An in-house attack detection core, code and website checks, and an AI assistant on top of them. Everything runs on the customer's server, inside their network, and every decision can be checked.
Figures you can recompute
The method and the measurement code ship with the product: the Accuracy Lab recomputes these figures on the customer's own machine.
From a log event to a person's decision
Conventional tools send the analyst every suspicious event. HCCA first links events into a chain and accounts for how the organisation normally works, and only then decides whether there is an incident.
- 01
Collection
Agents for Windows (Security, Sysmon and PowerShell logs) and Linux (program starts from auditd), and syslog from servers and firewalls: iptables, CEF, LEEF, FortiGate, Cisco ASA. Every agent has its own identity.
- 02
HCCA core
The causal chain of an attack, an adjustment for the organisation's normal work, a Bayesian estimate of confidence. Below the threshold there is no incident.
- 03
Decision
Four explanations of one case and proposed actions with their cost to operations. A person approves.
- 04
Ledger
Every entry is chained to the previous one by SHA-256 and signed with Ed25519. The ledger is verified outside the platform.
What is inside
The HCCA core
Hybrid Causal-Contextual Analysis. Process trees, accounts, hosts and network flows are assembled into one attack chain. Evidence accumulates in log-odds, and each item's contribution is visible in the explanation. Every incident carries an input hash and a ruleset version: the same input gives the same result.
SENTINEL Assistant
Analyses an incident and forecasts the attacker's next steps, writes a fix plan for developers and a shift briefing, and answers questions. It runs on a pluggable language model, in the cloud or locally inside the network. Host and account names are masked before sending, and passwords are never sent.
Code and website checks
Eight ecosystems: Python, JavaScript, Java, Go, PHP, Ruby, Rust and .NET. A local OSV database with more than 200,000 known malicious packages, CVSS 3.x scoring. Secrets, dangerous code, container configuration. Noise is removed by the same method as in the core.
Zero trust
Per NIST SP 800-207: short-lived tokens bound to the session and the device, a session trust score, four least-privilege roles, two-factor sign-in and re-authentication for critical actions.
Machine identities
Every agent has its own token, and the server keeps only its hash. An agent can only deliver events. An on-disk buffer and per-log bookmarks: a restart neither loses nor duplicates anything.
One decision, four explanations
For the analyst, management, the auditor and in plain words. All four are built from one decision tree, so they never disagree. Aligned with NIST CSF 2.0, ISO/IEC 27001:2022 and MITRE ATT&CK.
Why it is built this way
No neural network in the decision path
A conclusion that cannot be broken down into evidence cannot be shown to an auditor. The platform has a language model, but the core makes the decisions, and every accuracy figure was obtained without it.
No heavy ML libraries
The core is Python and probability. Fewer dependencies, a smaller image and a smaller attack surface for the security tool itself.
Inside the customer's network
The platform runs in a closed network. Internet access is needed only to refresh the vulnerability database, and that file can be carried over from another machine.
What it runs on
Mature open technologies. The full list of dependencies with their licences ships in CycloneDX format.
| Layer | Technology |
|---|---|
| Core and API | Python, FastAPI, PydanticEvery request is validated against a schema. |
| Data | SQLAlchemy, Alembic, SQLite or PostgreSQLSQLite for one server, PostgreSQL for several writing nodes. The schema evolves through migrations. |
| Cryptography and access | Ed25519, SHA-256, JWT, TOTP |
| Console | React, TypeScript, Vite, TanStack Query, Tailwind CSSSix languages, right-to-left interface for Arabic. |
| Language layer | Pluggable models: cloud by API or localAnswers follow a strict schema, data is masked before sending, every request goes to the audit ledger. |
| Collection | Windows and Linux agents, syslog from servers and firewalls, ingest API |
| Community rules | Sigma (SigmaHQ): more than 900 rules, in shadowA rule is switched on only after a week of quiet on the customer's network, and then only corroborates other evidence. |
| Delivery | Docker, Windows service, one-click installWorks without internet access. |
| Quality | Automated tests and CI on every change, SBOMThe Accuracy Lab is built into the product. |
The near-term technical plan
SENTINEL's own language model
A model trained on security tasks, so the assistant can run entirely inside a closed network.
Scale
Testing on PostgreSQL with hundreds of real agents.
Software and updates
An inventory of installed software and missing updates on each machine.
Public sector
National software registries and certification.
Test it on your own data
A pilot runs on one server inside your network. You see what the platform finds there, and how many alerts stop reaching your analysts.
Request a pilot →