Fusion · Cross-Agency Connectors
Connect your own systems — sovereign, on your terms
Sentinel reaches the records your agency already holds through an open connector framework that runs on your infrastructure. No foreign dependency, no kill-switch, no data leaving your network — and your own engineering team can add new sources whenever you need them.
Connector categories
One framework, every kind of registry
Sources are modelled as generic categories, not vendor lock-ins. Each connector declares what it supports — bulk enrolment, or lookup by face, by ID, or by plate — and is scoped to a single authorised source.
Civil registry
Match a subject against the national identity gallery your civil authority already maintains — by face or by name, under per-query authorisation.
Driving licence
Cross-reference the licence registry — the same connector shape as the civil registry, scoped to a driving-authority source.
Vehicle registry
Resolve a plate to its registered owner, joined back to the identity records you already hold.
International notices
Surface cross-border notices alongside a subject — jurisdiction-agnostic, carrying each notice’s own reference detail.
Subscriber registry
Connect the subscriber registry your telecom regulator maintains — the link between a registered identity and its account, held as a handle, never a raw record.
Bring your own
Not on the list? The framework is open. Your engineering team writes a connector for any source that can be modelled as a registry.
An open framework your engineers control
Connecting a new source is a self-contained connector class, not a vendor engagement. Generic connectors cover most cases out of the box; you only write bespoke code where a jurisdiction has quirks the generic can’t handle.
- Generic, config-driven connectors cover most sources — point one at a gallery with a JSON description of its ID format and schema.
- Your in-country engineering team can add a new source by writing a single connector class — no dependency on us to ship it.
- Extend a generic connector only where a source needs it, overriding just the behaviour that differs.
- Each connector declares its capabilities — bulk enrolment, lookup by face, by ID, or by plate — so the operator UI adapts automatically.
Click to enlargeConnected sources, each with its status and last sync — your team adds new ones.
It runs on your hardware, and stays there
Sentinel is built to be the anti-lock-in choice: deploy it where your law says data must live, keep the source records in the systems that already own them, and prove every query after the fact.
- Runs entirely on your infrastructure — cloud, on-premise, or fully air-gapped, with map tiles served from your own box.
- Reference-by-handle: Sentinel stores an irreversible embedding and a masked label; the original records never leave the source system.
- Every query is authorised, scoped to your organisation, and written to an append-only WORM audit log.
- Offline HMAC-signed licence — no phone-home, no foreign kill-switch, verifiable without contacting the cloud.
Source registries → connector plugins → the Sentinel box → a WORM audit store, all inside your air-gapped boundary.
Deployment & data handling
What you connect, and what you keep
The same contract governs every connector: your systems remain the system of record, Sentinel holds only handles, and every access is authorised and logged.
| Deployment | Cloud · on-premise · fully air-gapped — your choice of where it runs. |
| Data handling | Reference-by-handle — an irreversible embedding and a masked display label; the original records stay in the source system. |
| Audit | Every query is authorised, organisation-scoped, and written to an append-only (WORM) log. |
| Extensibility | Open connector framework — your in-country team adds new sources as a self-contained connector class. |
| Sovereignty | Runs entirely on your infrastructure; no phone-home and no foreign kill-switch. |
| Licensing | Offline HMAC-signed licence, verifiable without contacting the cloud — air-gap friendly. |
Cross-agency federation, by agreement
When two agencies each run their own Sentinel, they can link them by a bilateral agreement under mutual audit — each side keeps its own records and sees exactly what the other side queried.
- A bilateral agreement between two sovereign Sentinel installations — neither side hands over its gallery.
- Queries cross the boundary only under mutual audit, logged on both sides for later verification.
- Emerging capability — the federation data model is in place today; controlled rollout is on the roadmap.
Two sovereign clusters, linked only by a bilateral, mutually-audited bridge — neither hands over its gallery.
Connect the systems you already trust
See how Sentinel bridges your own registries — on your hardware, under your audit, with your team able to extend it.