Sentinel
Discover. Moderate. Map. Enforce. Audit. Prove.
The externalized, productized version of Overwatch — purpose-built for CCOs, CISOs, General Counsel, and regulators. Govern every AI system across the enterprise under the EU AI Act, NIST AI RMF, ISO/IEC 42001, and US state laws, with an immutable, regulator-exportable record of every decision.
Externalized governance for every AI system your enterprise runs.
Overwatch governs VeraGen. Sentinel takes that same enforcement spine — real-time moderation, immutable ledger, regulator-grade evidence — and turns it outward, so any enterprise can govern any model from any vendor: OpenAI, Anthropic, Google, Meta, in-house fine-tunes, third-party SaaS with embedded AI, and autonomous agents.
80% of Fortune 5000 enterprises already run AI in production. Roughly 1% have mature governance. The EU AI Act becomes enforceable on August 2, 2026, with fines up to €35M or 7% of global turnover. Sentinel is the platform a CCO, CISO, or General Counsel lands to close that gap before the deadline — with deployment in under 90 days, not 18 months.
Three deployment patterns. One governance fabric.
Gateway Proxy
Sentinel sits inline between your apps and any LLM provider. Blocks, redacts, or rewrites prompts and outputs in real time. Sub-30ms p50 latency. Zero code change.
SDK Middleware
Drop-in SDKs for Python, Node, Java, .NET. Wrap your existing inference calls. Sentinel classifies, enforces policy, and writes evidence — all before the response reaches the user.
Async Observability
For latency-sensitive workloads, mirror traffic asynchronously. Sentinel catches drift, fairness shifts, and policy violations post-hoc and triggers incident workflows in Thrive.
The only platform built to be the audit record, not just generate one.
OneTrust and Credo emerged from privacy and assurance. Sentinel was built spec-first against the EU AI Act, NIST AI RMF, and ISO/IEC 42001 — and its ledger is engineered as the regulator’s primary source of truth.
Per-Tenant KMS Encryption
Every record encrypted with customer-controlled keys. Selective decryption requires an explicit grant from your General Counsel — even VeraGen cannot read your evidence.
Merkle-Chained WORM Ledger
Every event hashed and chained. Batches sealed to AWS S3 Object Lock in compliance mode. Tamper-evident, court-admissible, 7-year default retention.
Spec-First Regulatory Mapping
Continuously updated corpus: EU AI Act, NIST AI RMF 1.0 + GenAI Profile, ISO/IEC 42001, Colorado SB24-205, NYC LL144, SR 11-7, OCC 2011-12, FFIEC, HIPAA, OMB M-24-10.
One-Click Regulator Export
Generate an EU AI Act Annex IV technical file, a NIST RMF profile, or a Colorado risk assessment in minutes — with cryptographic provenance attached.
Land Sentinel before the deadline.
Explore the six modules and the seven personas turning AI risk into a board-level capability.