Sentri

AI governance and
chain of custody.

Sentri decides what each enrolled AI agent may do, holds sensitive actions for a person, and keeps a tamper-evident record of its decisions.

What Sentri does today.

Everything in this section is running in production.

Deny by default

Each tool call from an enrolled agent carries a short-lived, signed intent token. A call outside the agent's policy is refused. A call that breaks a hard rule also removes the agent's authority until an operator restores it.

Policy with a person in the loop

Policies describe who may act, on what, when, where, why and how. Sensitive actions are held for an operator to approve or reject from the console, with a reason.

Operator controls

Contain an agent, release it, or revoke its authority. Console access is role-based (viewer, operator, admin), and sign-in requires an authenticator code.

Tamper-evident evidence

The gateway and its companion services keep hash-chained records. Verification names the exact row where a record was changed.

Chain of custody

For any agent: where it was first seen, the host it runs on, what it was stopped from doing, what it could reach, and its state now. Anything not recorded is labeled as a gap, not filled in.

Escape alerts

On an enrolled host, an attempt to go around the gateway is cut off on the host and raised as a critical alert in the console and by email.

In development.

Built and tested in our lower environment. Not yet running for customers.

In development

On-behalf-of attribution

Agent actions tied to the named person they act for. Actions with no person attached are refused unless policy marks them as unattended.

In development

Shadow-agent discovery

Enrolled hosts report the AI runtimes running on them, and an operator registers or blocks each finding.

In development

Access reviews for agents

Periodic review of what each agent may do against what it actually used, with keep, narrow or revoke decisions on the record.

In development

EYEQ

Behavioral baselines for each agent that propose a review when behavior drifts.

About EYEQ

Scope, stated plainly.

  • Sentri governs agents that route through its gateway. It does not see agents on hosts you have not enrolled.
  • It controls actions. It does not read an agent's reasoning, and it does not claim to stop an agent from thinking something it never acts on.
  • The timeline on our home page is an illustrative scenario, not a recorded incident.

See what your agents do. Prove why. Decide what happens next.

Talk with the people who build and run Cipherion, in Dallas.