Sentinel by CryptoITData
Product delivered and calibrated by CryptoITData

Real-time AI analysis, configured for your server.

Detection runs deterministically, around the clock, at zero cost. A model reads the serious incidents in under two minutes and tells you what is real, what is noise and what to do about it — then drafts the repair procedure. Installed on your own infrastructure, calibrated for 72 hours on your traffic, handed over with the documentation.

Download the product sheet PDF · 11 pages · 0.7 MB

A single machine or a fleet. No SIEM, no external agent, no data leaving your server.

What “configured for you” means

Pick what runs on your server. Watch the configuration change.

This is not a feature list you tick off. At install time Sentinel discovers what is on the machine and writes an inventory that you confirm — then the collectors, detection rules and thresholds adjust to it. Try it below.

The panel on the right is what the installer would produce for the selected combination. On your machine the same decisions are made from what it actually finds — not from what you ticked.

/etc/sentinel/ · generated for your install 0 rules
Why now

They have been automating for a year. You patch in 43 days.

You are no longer picked by a human. You are a row in an automatically generated list — scanned, classified and prioritised by programs that work non-stop, at a cost per target close to zero. Company size no longer takes you off the list.

0 days — the median time it takes to patch a vulnerability

The pace of defence. Human, scheduled, with maintenance windows.

0 days — until mass exploitation of a KEV vulnerability

The pace of attack. Automated, continuous, no windows.

38 days in which you are vulnerable and you know it. The gap does not close by hiring faster. It closes by putting something on the server that works at the same pace as the attacker.
0 of intrusions start with the exploitation of a vulnerability — it overtook stolen credentials for the first time in 19 years
0 the one-year increase in attacks on perimeter devices (3% → 22%)
0 of ransomware victims are companies with fewer than 1,000 employees
0 faster detection for teams that use automation — and $1.9 M less per incident
The full analysis on our blog: “Internet-exposed servers — not if, but when” →
Real-time AI analysis

The attack is industrialised with AI. The analysis that reads it has to be too.

No human can read 20,000 hostile events a day, and none can write at 3am why this particular one matters. Sentinel puts a model on the judgement part — real severity, false positive or not, what to do about it, in plain English — in less than two minutes from the moment the incident opens.

But the decision to block stays deterministic. That is not a limitation: it is the reason you can leave the product running on its own.

Deterministic verdict · instant, zero cost
rule
severity
source
action

Runs 24/7, on every event. Depends on nothing outside the server.

AI verdict · added, never overwritten

If the model disagrees with the rule, you see both. Nothing is silently rewritten.

What the model does

  • Triage — recalibrates severity, flags false positives and writes the summary in plain English
  • Correlation — ties separate incidents into a single campaign with the same source behind it
  • Patch procedure — command by command, with backup, checks and rollback steps
  • Daily report — what attacked you, what was blocked, what stayed open
  • Answers questions over its own database, read-only

What it is not allowed to do

  • No blocking decisions. Detection, scoring and the decision are deterministic and run at zero cost
  • No execution. The plan it writes goes through a deterministic validator that refuses it if it is not safe — the model drafts, the validator decides
  • Not on the critical path. API down or budget exhausted: detection, blocking and alerting carry on, marked “AI analysis unavailable”
  • No budget overrun. The cap is checked before every call, and the cost per incident is visible in the dashboard
THE ATTACK SURFACE THAT AI ITSELF BRINGS

Log lines are written by the attacker. If they reach a model, that is prompt injection inside your own security tool.

An attacker can request an HTTP path that contains instructions. Sentinel treats them as untrusted data, with explicit delimiters, and the transport that actually reads files off the server runs --permission-mode plan — structurally unable to change anything. There is a test that plants IGNORE PREVIOUS INSTRUCTIONS in an access log and checks that nothing was executed.

The command channel

The incident reaches your phone in seconds. The response leaves from there too.

This is not a notification channel. It is the console. You get the incident with action buttons, block the attacker with one tap, ask for server status and start a patch — no VPN, no SSH, no opening the laptop. Everything you can do from the web dashboard you can do from the chat.

S Sentinelbot · your server live
Under 2 seconds from detection

The report comes to you, with context

You do not wait to open a dashboard. The incident is pushed to Telegram the moment the rule fires, with the source, country, ASN, number of attempts and the AI verdict in plain English — plus the buttons that resolve the situation on the spot.

Execution, not just reading

You administer the server from the chat

Commands run on the server and answer in under a second. The ones that change something ask for a separate confirmation, and the destructive ones ask for a second one that restates the target.

/dashboard/status/incidents /vulnerabilities/services/health /events/blocked/patches /selfcheck /block/unblock /resolve/falsepositive /quiet/panic

Green reads, red changes. Every command also has a Romanian variant, for phones that autocomplete in Romanian.

Why Telegram

It works exactly when everything else stops working

The bot pulls messages, it does not receive them: there is no open port pointing at it and no public endpoint to forge. If nginx, TLS or the web dashboard go down, the channel stays up — which means it is available in exactly the minute you need it.

How to buy

Three tiers. Same technology; what differs is how much we carry and how much you do.

The licence is per server. Initial configuration and the 72-hour calibration are included in every tier — without them, an agent that can block traffic is a risk, not a protection.

Install

For teams that already have someone technical and just want the tool, configured properly.

On requestone-off, per server
  • Server assessment and a confirmed inventory
  • Install, configuration for your stack, 72h calibration
  • AI triage of serious incidents, with a plain-English verdict
  • Telegram alerts with action buttons
  • Your own web dashboard, on your domain
  • Operating documentation and handover
  • Monitoring by us
  • Patch application
Request a quote
Most chosen

Managed

For companies without a dedicated security person. We watch, you decide what gets applied.

On requestmonthly subscription, per server
  • Everything in “Install”
  • We review incidents and tune the rules monthly
  • AI-drafted patch plans, reviewed by us before they reach you
  • Monthly report: what attacked you, what was blocked, what is open
  • Product updates included
  • Incident support during business hours
  • Out-of-hours intervention
Request a quote

Fleet

For several servers or clients. Per-machine configuration, one unified view.

On requestproject-based
  • Everything in “Managed”, on every machine
  • Repeatable install from a configuration file
  • Per-server thresholds and exception lists
  • Integration with your maintenance processes
  • A training session for your team
  • Negotiated SLA
Let’s talk
How it goes

From the first email to a handed-over agent: under two weeks.

01

Assessment

We look at what is exposed, what is attacking you right now, which vulnerabilities are open and how fast you would find out if someone got in. We install nothing at this stage.

day 1–2 · no obligation
02

An inventory you confirm

Discovery proposes what it found on the machine; you confirm what is critical, what is never touched automatically and who must always get through — monitors, the office, CI.

day 3
03

Install

One hour on a clean server. Nothing that ran before stops: the installer compares against the previous state and rolls back automatically if something changed.

day 3 · ~1 hour
04

Calibration on your traffic

72 hours in which automatic blocking is off and you only get what it would have blocked. This is where the false positives show up: the uptime monitor, certificate validation, your mobile IP.

day 4–6
05

Handover

We switch automatic blocking on with the tuned thresholds, hand over access to the dashboard and the bot, plus the operating documentation. From here it runs on its own.

day 7
The uncomfortable part

An agent that can block the internet must be judged by what it refuses.

Every vendor tells you what the product does. When software gets root on your server, the question that matters is a different one: what is it not allowed to do, and who stops it.

REFUSED

Blocking you

Your admin address, the private networks and loopback live in a list hard-coded in the source — not in configuration, not in the database. Compromising the database cannot widen it.

REFUSED

Blocking you by failing

The base rule is policy accept. It is a deny-lister, not a firewall. If the process dies, the database goes down or the configuration is wrong, traffic passes.

REFUSED

Keeping blocks across a reboot

Deliberate: a reboot is always a way out of a self-inflicted block. Plus a PANIC file that clears everything in under 60 seconds, watched by an independent process.

REFUSED

Applying a patch on its own

Generating the plan is automatic. Applying it takes two explicit confirmations on the phone, and the button dies if the plan is regenerated.

REFUSED

Letting the dashboard touch the firewall

The interface is the most exposed component, so it has no path to privileged actions. Compromising it leaks data; it cannot block, unblock or apply anything.

REFUSED

Believing a log

Log lines and HTTP paths are written by the attacker. They are treated as untrusted data, and a test plants IGNORE PREVIOUS INSTRUCTIONS in an access log and checks that nothing was executed.

Product status

Running in production on our own infrastructure.

The numbers below come from the repository, not from a slide deck.

0automated tests
0of them check that something dangerous is refused
0self-diagnostic checks, every 5 minutes
0external dependencies in the interface — strict CSP, no third-party JavaScript

The gaps are declared, not hidden: container logs are not collected yet, there is no dedicated file-integrity monitor beyond auditd, and the Debian install is covered by tests but not yet verified on a real Debian host. We say so before the contract, not after.

Next step

We start with a conversation, not an invoice.

Thirty minutes, free and with no obligation. You tell us what server you have and what runs on it. We tell you what is exposed, what is attacking you right now and whether Sentinel makes sense for you — including when the answer is “not yet”.

Download the product sheet PDF · 11 pages · 0.7 MB

Corporate-grade expertise. Delivered fast. No overhead, no jargon, no surprises.