INC-2048 · 18 events
Turn signals into an investigable incident.
Sentinel is VENTEX's defensive security control plane. It accepts bounded telemetry from endpoints, network sensors and VENTEX products, preserves provenance and evidence, and brings related signals together as explainable incidents.
The durable SOC core and substantial deployment hardening are implemented. Production or enterprise readiness will only be claimed after green CI for the exact release SHA and real deployment qualification.
A control room for defensive telemetry.
A Windows login failure, a Suricata signature and a Zeek notice begin as three separate observations. Sentinel normalises them, binds them to traceable sources and applies deterministic, versioned correlation.
The result is not an autonomous verdict. Operators receive an incident queue, workspace, evidence, activity, ownership, hunting and graph projections—with explicit bounds, paging and provenance.
What the current product line actually supports.
Telemetry ingestion
Syslog, Windows Event Log, Linux journald, Suricata EVE, Zeek Notice, authenticated webhooks and bounded Connect and VIGIL/HomeCam boundaries.
Normalisation and assets
Typed event contract, retry-safe source identity and canonical host/asset identity across multiple sources.
Explainable correlation
Deterministic, versioned rules for critical events, authentication bursts, VENTEX Connect signals and bounded cross-sensor network correlation.
Incident workspace
Queue, detail view, lifecycle, notes, evidence, claim/release, handoff and race-protected consistent workspace projections.
Hunting and investigation graph
Structured, bounded event hunting and paged incident-rule-event-asset-IP relationships with event-ID provenance.
Evidence and audit
Evidence snapshots, revision-bound projections and a tamper-evident SHA-256 operator audit chain.
Dry-run response plans
Bounded, immutable response intent for containment, network indicators and forensic snapshots—without execution against monitored systems.
Production qualification
Kubernetes, migration, drain, signature and promotion gates are substantially implemented; real cluster, ingress, OIDC, load and soak qualification remain open.
Meaning remains stable as the system grows.
Sentinel separates untrusted producers, collector boundary, normalisation, persisted evidence, correlation and operator API. The correlation path remains I/O-free, bounded and testable.
Low-privilege sources
Collectors normalise and deliver telemetry; collection identity and operator identity remain separate trust domains.
Bounded event contract
Schemas, size limits, idempotency and asset identity constrain attacker-controlled input before domain processing.
Deterministic rules
Versioned descriptors, bounded windows and stable fingerprints keep detections historically interpretable.
PostgreSQL and audit
Alembic migrations, exact schema gates, evidence-safe retention, backup/restore and sealed audit records.
Versioned operator API
React console, OIDC Authorization Code + PKCE, backend RBAC and additional runtime validation for every security-relevant browser projection.
From telemetry to controlled response intent.
- 01
Ingest and normalise
Sources deliver defensive events through bounded contracts; Sentinel preserves source, time, asset and retry identity.
- 02
Correlate and prioritise
Versioned rules bring related evidence together as deduplicated, explainable incidents.
- 03
Hunt and investigate
Operators filter structured events, open cases and inspect bounded graph pages with explicit provenance.
- 04
Coordinate and document
Ownership, notes, handoffs, evidence and response plans are server-authorised and anchored in audit.
A security product must defend its own boundaries.
Sentinel treats telemetry, browser responses, integrations and future AI output as potentially untrusted. None silently receives authority over another.
Producer → ingest
All fields are untrusted; schema, volume, transport and replay bounds are enforced before domain interpretation.
Browser → operator API
Backend authorisation remains authoritative; the console additionally validates critical 200 responses against request and domain invariants.
Detection → decision
A correlation is an investigation start, not proof of compromise and not automatic authorisation for response.
Response plan → execution
The current slice records intent. No executor, remote shell, firewall write or host-isolation path exists.
AI → authority
Future AI may explain evidence or suggest questions, but must not silently replace rules or authorise privileged actions.
Release evidence → production
Signature, build provenance, staging behaviour and promotion are separate gates; no single artefact proves production readiness.
Substance without a premature enterprise claim.
Sentinel is functionally far beyond a concept, but deliberately remains advanced pre-alpha until exact CI and deployment qualification.
- Durable SOC core with PostgreSQL
- Operator console with OIDC/RBAC
- Collectors, correlation, hunting and graph
- Evidence, ownership, handoff and audit
- Kubernetes, drain and promotion hardening
- Green CI for the exact release SHA
- Real staging cluster and ingress
- Real OIDC and network-policy validation
- Load, failure and sustained soak tests
- Broader detection-engineering operations
- Explicitly authorised response execution
- Evidence-grounded analyst assistance
- No current production release
A real stack, not a UI facade.
VX / SENTINEL / 0.1-DEV- Control plane
- Python 3.12 · FastAPI · SQLAlchemy
- Persistence
- PostgreSQL · Alembic · exact schema gates
- Operator console
- React 19 · TypeScript · Vite
- Identity
- OIDC · Authorization Code + PKCE · RBAC
- Telemetry
- Syslog · Windows · Linux · Suricata · Zeek · webhook · VENTEX
- Observability
- Structured logs · OpenTelemetry OTLP/HTTP
- Deployment
- Containers · Kubernetes contracts · systemd examples
- Licence
- Proprietary · all rights reserved
VENTEX Sentinel questions
Short answers with the same status and claim boundaries as the technical product state.
No. Sentinel is advanced pre-alpha with an implemented SOC core and substantial release hardening. Production readiness will only be claimed after complete exact CI and real deployment qualification.
Sentinel includes SIEM-adjacent ingestion, normalisation and correlation, but is designed as a broader security-operations control plane with incident, investigation, evidence and coordination workflows.
No. The current response-plan slice is dry-run only and records authorised operator intent. It executes no commands or changes against monitored infrastructure.
The implemented Connect boundary processes only allowlisted security metadata, such as authentication, handshake or device-key signals. Message content, attachments and cryptographic secrets are outside this correlation.
