Fusion · Cross-Agency Connectors
Connect your own systems — sovereign, on your terms
Sentinel reaches the records your agency already holds through an open connector framework that runs on your infrastructure. No foreign dependency, no data leaving your network — and your own engineering team can add new sources whenever you need them.
Connector categories
One framework for the sources you're authorised to connect
Sources are modelled as generic categories, not vendor lock-ins. Each connector declares what it supports and is scoped to a single authorised source.
Identity records
Match a subject against the identity records your civil authority already maintains — under per-query authorisation, operator-confirmed.
Driving licence
Cross-reference the licence registry — the same connector shape as identity records, scoped to a driving-authority source.
Vehicle registry
Resolve a plate to its registered owner, joined back to the identity records you already hold.
International notices
Surface cross-border notices alongside a subject — jurisdiction-agnostic, carrying each notice’s own reference detail.
Your authorised sources
Connect any additional reference source your agency is authorised to use — held as a handle, never a raw record.
Bring your own
Not on the list? The framework is open. Your engineering team writes a connector for any source that can be modelled as a registry.
An open framework your engineers control
Connecting a new source is a self-contained connector class, not a vendor engagement. Generic connectors cover most cases out of the box; you only write bespoke code where a jurisdiction has quirks the generic can’t handle.
- Generic, config-driven connectors cover most sources — point one at a gallery with a JSON description of its ID format and schema.
- Your in-country engineering team can add a new source by writing a single connector class — no dependency on us to ship it.
- Extend a generic connector only where a source needs it, overriding just the behaviour that differs.
- Each connector declares its capabilities — bulk enrolment, lookup by face, by ID, or by plate — so the operator UI adapts automatically.
Click to enlargeConnected sources, each with its status and last sync — your team adds new ones.
It runs on your hardware, and stays there
Sentinel is built to be the anti-lock-in choice: deploy it where your law says data must live, keep the source records in the systems that already own them, and prove every query after the fact.
- Runs entirely on your infrastructure — cloud, on-premise, or fully air-gapped, with map tiles served from your own box.
- Reference-by-handle: Sentinel stores an irreversible embedding and a masked label; the original records never leave the source system.
- Every query is authorised, scoped to your organisation, and written to an append-only WORM audit log.
- Offline HMAC-signed licence — no phone-home, verifiable without contacting the cloud.
Source registries → connector plugins → the Sentinel box → a WORM audit store, all inside your air-gapped boundary.
Deployment & data handling
What you connect, and what you keep
The same contract governs every connector: your systems remain the system of record, Sentinel holds only handles, and every access is authorised and logged.
| Deployment | Cloud · on-premise · fully air-gapped — your choice of where it runs. |
| Data handling | Reference-by-handle — an irreversible embedding and a masked display label; the original records stay in the source system. |
| Audit | Every query is authorised, organisation-scoped, and written to an append-only (WORM) log. |
| Extensibility | Open connector framework — your in-country team adds new sources as a self-contained connector class. |
| Sovereignty | Runs entirely on your infrastructure; no phone-home and no foreign dependency. |
| Licensing | Offline HMAC-signed licence, verifiable without contacting the cloud — air-gap friendly. |
Cross-agency federation, by agreement
When two agencies each run their own Sentinel, they can link them by a bilateral agreement under mutual audit — each side keeps its own records and sees exactly what the other side queried.
- A bilateral agreement between two sovereign Sentinel installations — neither side hands over its gallery.
- Queries cross the boundary only under mutual audit, logged on both sides for later verification.
- Emerging capability — the federation data model is in place today; controlled rollout is on the roadmap.
Two sovereign clusters, linked only by a bilateral, mutually-audited bridge — neither hands over its gallery.
Connect the systems you already trust
See how Sentinel bridges your own registries — on your hardware, under your audit, with your team able to extend it.