Sentinel Modules
Discovery to evidence. Inventory to export. Each module shipped as a deployable capability with its own ROI, then composed into a single governance fabric that no point tool can match.
AI Inventory & Discovery
Map every model, prompt, agent, and dataset in your enterprise.
Passive network discovery, SaaS integrations, and code/repo scanning surface every place AI is in use — including shadow AI. Each system is auto-classified by risk tier under the EU AI Act and tagged with the laws and frameworks that apply.
- ·Network & SaaS-API passive discovery
- ·Code repository & vector DB scanning
- ·EU AI Act risk-tier auto-classification
- ·Vendor, model, dataset, and agent registry
- ·Lineage from training data → prompt → output
Real-Time Prompt & Output Moderation
Block, redact, or rewrite — before the response reaches the user.
Three deployment patterns — gateway proxy, SDK middleware, async observability — all backed by classifiers for PII, PHI, prompt injection, jailbreaks, toxicity, bias, hallucination, IP leakage, and policy violations. Sub-30ms p50 latency at the gateway.
- ·Gateway, SDK, or async deployment
- ·PII / PHI / PCI redaction
- ·Prompt-injection & jailbreak detection
- ·Toxicity, bias, hallucination scoring
- ·IP & confidential-data exfiltration guards
Regulatory Mapping & Intelligence
Every control mapped to every law, automatically.
A continuously updated regulatory corpus — EU AI Act, NIST AI RMF 1.0 + GenAI Profile, ISO/IEC 42001, Colorado SB24-205, NYC LL144, SR 11-7, OCC 2011-12, FFIEC, HIPAA, OMB M-24-10, and 30+ US state AI laws — mapped to your controls and surfaced as gaps with remediation paths.
- ·EU AI Act Annex III high-risk taxonomy
- ·NIST AI RMF Govern/Map/Measure/Manage
- ·ISO/IEC 42001 AIMS control library
- ·US state law tracking (CO, NYC, CA, TX…)
- ·Regulatory diffing & change alerts
Policy Authoring & Enforcement
Write a policy once. Enforce it on every model, everywhere.
A policy DSL plus pre-built templates from the regulatory corpus. Policies compile to runtime guardrails enforced by the moderation engine, and to attestations enforced at design time during model registration and procurement.
- ·Visual + DSL policy authoring
- ·Pre-built EU AI Act / NIST / ISO templates
- ·Runtime guardrails + design-time gates
- ·Approval workflows & policy versioning
- ·Per-tenant, per-business-unit scoping
Immutable Audit Ledger & Regulator Export
The record is the truth — and the regulator’s primary source.
Every prompt, output, classifier verdict, policy citation, and human review is hashed, Merkle-chained, and sealed to AWS S3 Object Lock under per-tenant KMS keys. 7-year default retention. One-click export of Annex IV technical files, NIST RMF profiles, and state risk assessments.
- ·Merkle-chained WORM ledger
- ·AWS S3 Object Lock (compliance mode)
- ·Per-tenant KMS, selective decryption
- ·Chain-of-custody on every record
- ·One-click EU AI Act / NIST / state exports
Bias, Fairness & Drift Monitoring
Catch model decay before the regulator does.
Continuous statistical monitoring for performance drift, fairness shifts across protected classes, and concept drift relative to training distribution. Threshold breaches automatically open incidents in Thrive and pause high-risk inference paths.
- ·Disparate-impact & equalized-odds tests
- ·Population-stability & concept-drift indices
- ·Per-subgroup performance dashboards
- ·Auto-pause on threshold breach
- ·Incident handoff to Thrive workflows
Sentinel doesn’t ship alone.
Six other VeraGen apps make Sentinel more capable, faster to deploy, and cheaper to operate than any standalone governance tool.