Skip to main content

Fusion · Cross-Agency Connectors

Connect your own systems — sovereign, on your terms

Sentinel reaches the records your agency already holds through an open connector framework that runs on your infrastructure. No foreign dependency, no kill-switch, no data leaving your network — and your own engineering team can add new sources whenever you need them.

Your systems
records you already hold
Open connector
your team can write it
Your hardware
no foreign dependency
Every query audited
authorised & logged
An open framework — connect your own systems, on your terms.
3
Deployment shapes
Cloud · on-premise · air-gapped
Open
Connector framework
Add your own sources
0
Foreign kill-switch
Runs on your hardware
WORM
Audit trail
Every query logged

Connector categories

One framework, every kind of registry

Sources are modelled as generic categories, not vendor lock-ins. Each connector declares what it supports — bulk enrolment, or lookup by face, by ID, or by plate — and is scoped to a single authorised source.

Civil registry

Match a subject against the national identity gallery your civil authority already maintains — by face or by name, under per-query authorisation.

Driving licence

Cross-reference the licence registry — the same connector shape as the civil registry, scoped to a driving-authority source.

Vehicle registry

Resolve a plate to its registered owner, joined back to the identity records you already hold.

International notices

Surface cross-border notices alongside a subject — jurisdiction-agnostic, carrying each notice’s own reference detail.

Subscriber registry

Connect the subscriber registry your telecom regulator maintains — the link between a registered identity and its account, held as a handle, never a raw record.

Bring your own

Not on the list? The framework is open. Your engineering team writes a connector for any source that can be modelled as a registry.

Extensible by design

An open framework your engineers control

Connecting a new source is a self-contained connector class, not a vendor engagement. Generic connectors cover most cases out of the box; you only write bespoke code where a jurisdiction has quirks the generic can’t handle.

  • Generic, config-driven connectors cover most sources — point one at a gallery with a JSON description of its ID format and schema.
  • Your in-country engineering team can add a new source by writing a single connector class — no dependency on us to ship it.
  • Extend a generic connector only where a source needs it, overriding just the behaviour that differs.
  • Each connector declares its capabilities — bulk enrolment, lookup by face, by ID, or by plate — so the operator UI adapts automatically.
See identity resolution
The Registries admin — connected sources with active / inactive / error status pills, category icons and last-sync per sourceClick to enlarge

Connected sources, each with its status and last sync — your team adds new ones.

Sovereign by design

It runs on your hardware, and stays there

Sentinel is built to be the anti-lock-in choice: deploy it where your law says data must live, keep the source records in the systems that already own them, and prove every query after the fact.

  • Runs entirely on your infrastructure — cloud, on-premise, or fully air-gapped, with map tiles served from your own box.
  • Reference-by-handle: Sentinel stores an irreversible embedding and a masked label; the original records never leave the source system.
  • Every query is authorised, scoped to your organisation, and written to an append-only WORM audit log.
  • Offline HMAC-signed licence — no phone-home, no foreign kill-switch, verifiable without contacting the cloud.
Your network · Air-gapped
Source registriesNational ID · licences · notices
Connector pluginsYour engineers control them
Sentinel boxModels + map on-prem
WORM audit storeEvery query, immutable
No external calls leave the boundary Runs on your hardware Reason-gated & logged

Source registries → connector plugins → the Sentinel box → a WORM audit store, all inside your air-gapped boundary.

Deployment & data handling

What you connect, and what you keep

The same contract governs every connector: your systems remain the system of record, Sentinel holds only handles, and every access is authorised and logged.

DeploymentCloud · on-premise · fully air-gapped — your choice of where it runs.
Data handlingReference-by-handle — an irreversible embedding and a masked display label; the original records stay in the source system.
AuditEvery query is authorised, organisation-scoped, and written to an append-only (WORM) log.
ExtensibilityOpen connector framework — your in-country team adds new sources as a self-contained connector class.
SovereigntyRuns entirely on your infrastructure; no phone-home and no foreign kill-switch.
LicensingOffline HMAC-signed licence, verifiable without contacting the cloud — air-gap friendly.
Roadmap · Emerging

Cross-agency federation, by agreement

When two agencies each run their own Sentinel, they can link them by a bilateral agreement under mutual audit — each side keeps its own records and sees exactly what the other side queried.

  • A bilateral agreement between two sovereign Sentinel installations — neither side hands over its gallery.
  • Queries cross the boundary only under mutual audit, logged on both sides for later verification.
  • Emerging capability — the federation data model is in place today; controlled rollout is on the roadmap.
Agency A · Sovereign
Sentinel clusterOwn estate, own registries
Bilateral bridgeBy agreement · mutually audited
Agency B · Sovereign
Sentinel clusterOwn estate, own registries
Neither side gains standing access to the other — only the specific, logged queries both agencies agreed to.

Two sovereign clusters, linked only by a bilateral, mutually-audited bridge — neither hands over its gallery.

Connect the systems you already trust

See how Sentinel bridges your own registries — on your hardware, under your audit, with your team able to extend it.