Every agent decision, turned into a signed and independently verifiable audit package: on-premise, under your jurisdiction, compatible with your existing stack.
In most regulated organisations the AI stack is already assembled from third-party tools of different vendors: governance tools, observability platforms, LLM providers, identity systems. Each layer lives with its own vendor.
What is missing is the layer that turns this heterogeneous stack into a regulatorily usable whole — the knot-resolver that produces the single audit package a regulator can verify, without replacing any of your existing investments.
Scaffold a local pilot, run ten decisions through @sentinel.trace, write a signed PDF evidence pack, score yourself against EU AI Act Art. 12.
[pdf] extra pulls reportlab, cryptography, and pyhanko — everything needed for signed PDF evidence packs. The bare install still works; evidence-pack tells you what to add.
Sentinel automates EU AI Act Art. 12/13/14/17 — the logging, transparency, oversight, and quality-management obligations. Other articles require organisational action. We mark the split honestly.
sentinel audit-gap to see the exact split for your setup.
EU AI Act enforcement applies to decisions that touch rights, access to services, safety, or meaningful financial outcomes. The architecture is technology-agnostic; the sectors below are where procurement is already active.
Procurement, logistics, dual-use assessment. Air-gapped and classified deployments with VS-NfD path.
Credit decisioning, fraud scoring, AML, transaction approval. DORA-aligned logging, BaFin BAIT evidence.
Underwriting, claims triage, pricing. GDPR Art. 22 explainable decision records for regulated customer outcomes.
Benefit eligibility, permit approval, critical-infrastructure AI. Statutory transparency under NIS2 and sector law.
Clinical decision support, diagnostic triage, prior-authorisation. Evidence suitable for medical-device auditors.
Quality control, predictive maintenance, robotic decisioning. Standards-aligned retention across plant lifetimes.
Sentinel wraps each agent decision as it happens. Input, policy, output, and jurisdiction are bound into a signed attestation before the next call begins. No log collection, no post-hoc reconstruction, no manual mapping under audit pressure.
An auditor can only trust evidence as far as they trust whoever produced it. Sentinel runs as an independent layer — not owned by the operator, not owned by the LLM vendor, not owned by the cloud provider. The signature chain holds whether anyone trusts you or not.
Sentinel does not replace your governance tools, observability platform, or LLM provider. It sits between them — receiving policy results, enriching with traces, emitting signed evidence. Bidirectional by design: allow signals feed innovation, kill signals gate risk.
Regulatory retention runs ten years or longer. Your LLMs and agents will not. The evidence layer must outlive every model, every framework, every vendor swap — stable signature format, stable storage interface, stable regulatory mapping.
We are building Sentinel the way HashiCorp built Terraform: primitive hooks in the kernel, the ecosystem grows through the community. Three stages, honestly labelled.
Production-ready, Apache 2.0, 838 tests passing. Install with pip install sentinel-kernel.
[pqc])
Bidirectional integrations with established governance and observability players. Actively in development.
The devil sits in the details of complex enterprise landscapes. These integrations we build with the community, not for it.
Sentinel is onboarding a select group of regulated enterprises building production-grade AI. Request a design-partner conversation, or read the technical documentation to see how Sentinel fits your stack.