PLATFORM · DEPLOYMENT
Your data. Your network. Your choice.
The same intelligence layer for your security operations center runs three ways: fully managed in our cloud, on-premise inside your own network, or fully air-gapped with no internet at all. One codebase, the same features in every mode. Where your most sensitive data lives is a decision you make — not a constraint the platform imposes on you.
DEPLOYMENT MODELS
Choose your deployment based on your data policy — not your feature list.
Every mode is the full platform. Pattern-of-life, cross-camera tracking, sealed evidence, and the tamper-evident audit all work the same way whether we host it or you do. Pick the model your mandate requires; the capability set never changes.
Cloud-managed
The fastest way to stand Sentinel up. We operate the platform on a hardened cloud cluster — Aurora MySQL, pgvector, object storage, Redis, TLS, and custom-domain routing. Stood up in minutes, automatic scaling and managed updates. Best for multi-site operations and teams without a server estate to manage.
On-premise
A self-contained Docker Compose stack — application, MySQL, pgvector, Redis, and MinIO object storage — all behind your firewall. An offline HMAC-signed license means no phone-home. A five-step setup wizard takes you from docker compose up to your first camera in under 30 minutes.
Air-gapped
For the most sensitive environments: zero internet connectivity required, ever. Install by transferring the image bundle on secure media; license validation happens entirely on your server. AI models can be sideloaded so even model updates never touch the internet.
DATA SOVEREIGNTY
Your footage. Your intelligence. Your network.
Cloud-only platforms ask you to trust that someone else is holding your most sensitive data correctly. Sentinel does not make you take that on faith. In on-premise and air-gapped mode, footage, face embeddings, event records, and audit trails all live on infrastructure you own and control.
Footage stays on your hardware
In on-premise and air-gapped mode, all video, face embeddings, event records, and audit trails live on infrastructure you own. Nothing has to leave your network for the platform to do its job — including the AI.
Same features in every mode
This is not a stripped-down local edition. Pattern-of-life, cross-camera tracking, lawful-basis tracking, sealed evidence, and the tamper-evident audit all work identically whether we host it or you do.
Accountability is mode-independent
The privacy controls, the lawful-basis requirement, and the tamper-evident audit are identical in every deployment mode. Accountability never depends on where you host.
ON-PREMISE
One stack. Your firewall. Every feature.
The on-premise package is complete and self-contained — no external services required. All services run as Docker containers, managed with a single docker compose up, with health checks, automatic restarts, and named volumes for data persistence. Every feature works offline: face recognition, cross-camera tracking, pattern-of-life, plate search, threat detection, evidence packs with chain of custody, and the tamper-evident audit.
ON-SITE AI
The AI runs where the cameras are.
A lightweight on-site agent does the heavy lifting next to your cameras, so video is understood locally and never needs to make a round-trip to a cloud GPU. It pulls RTSP, relays it as HLS to the console, and runs the full vision pipeline in ONNX Runtime on your own hardware.
On-device AI in ONNX Runtime
Every model — faces, plates, people, vehicles, behavior, threats — runs on your own hardware with no cloud GPU and no video leaving the site for inference.
ONVIF & RTSP auto-discovery
The agent discovers ONVIF cameras automatically via WS-Discovery, or connect directly by RTSP URL. Multi-agent topology spans buildings and cities under one tenancy.
Auto-updates with rollback
The agent updates itself safely over the air and rolls back automatically if an update fails — no manual intervention required for the on-site component.
White-label ready
Built per partner brand: bundled logo, colors, product name, and about text. The software your customer installs on their own network carries your brand from the installer onward.
HOW IT WORKS
On-premise setup, live in under 30 minutes.
Pull the stack
Transfer the Docker image bundle to your server — via internet pull or secure media for air-gapped installs. A single docker compose up brings all five services online: application, MySQL, pgvector, Redis, and MinIO.
Open the setup wizard
A browser-based five-step wizard guides an administrator from a running stack to a streaming camera. Enter your offline license key, create the first organization and administrator account, and set the hostname.
Install the on-site agent
Download and run the agent installer on a Windows, Linux, or macOS machine on the same network as your cameras. The agent connects to the console and registers itself automatically.
Add cameras
The agent discovers ONVIF cameras on the local network via WS-Discovery, or add any RTSP stream by URL. Cameras appear in the console within seconds of being added.
Go live
The full platform — face recognition, plate search, cross-camera tracking, threat detection, evidence packs, the tamper-evident audit — is live on your own network. Every feature works offline.
SPECIFICATIONS
Deployment at a glance
| On-site agent OS support | Windows, Linux, macOS — Windows service, systemd unit, or launchd daemon; system-tray UI |
| Camera compatibility | Any ONVIF camera; WS-Discovery auto-detection or direct RTSP; multi-agent topology across sites |
| AI processing | On-device in ONNX Runtime on the agent — no cloud GPU required; server-side AI worker available for batch re-processing |
| On-premise stack | Docker Compose: application (Next.js) · MySQL 8.0 · PostgreSQL + pgvector · Redis · MinIO object storage |
| Cloud-managed stack | Managed cluster: Aurora MySQL · PostgreSQL + pgvector · object storage · Redis · TLS and custom-domain routing |
| License model | Offline HMAC-SHA256 signed key, verified locally — no phone-home, air-gap friendly |
| Air-gap support | Full — install via image-bundle transfer on secure media; models sideloadable; zero internet requirement |
| Setup time | On-premise live in under 30 minutes via the five-step browser setup wizard |
| Updates | Cloud-managed by us; on-premise via image pull and restart, with bundled database migrations that run automatically |
| Branding | White-label end to end — console, agent, and emails, under your own brand and custom domain |
| Languages | 12 supported; Arabic RTL first-class |
| Storage tiers | Hot (instant) · Cold (6-mo min, 3–5 h restore) · Deep Freeze (12-mo min, 12–48 h restore) |
Specifications describe shipped platform capabilities. We will confirm the deployment configuration that fits your requirements during your demo.
EXPLORE MORE
Where to go next.
Partners & White-Label
Deliver Sentinel under your own brand — branded console, agent, and emails, with a custom domain per customer and per-partner agent builds.
Learn moreSecurity & Identity
SAML, OIDC, SCIM, WebAuthn, role-based access, and per-organization session policy at the front door of every deployment.
Learn moreAI Vision Pipeline
How the on-site agent turns video into structured intelligence — faces, plates, people, vehicles, and behavior — on your own hardware.
Learn moreDeploy on your terms.
Request demo access and we’ll configure a live environment for you — or walk you through the Docker deployment on your own hardware, end to end. Full feature access in cloud, on-premise, or air-gapped. The intelligence is the same in every mode; only the address changes.