Enterprise AI Agent Governance.
Self-Hosted. EU AI Act Ready.

The only AI agent platform where compliance, security, and human oversight are architecture — not afterthoughts.

EU AI Act GDPR NIS2 ISO 42001 Self-Hosted Open Source
Compliance Frameworks
EU AI Act
GDPR
NIS2
ISO 42001
Apache 2.0

Your AI Agents Are Live.
Who's Governing Them?

×

AI vendors focus on model performance — not governance

×

Observability platforms track what happened — not whether it was allowed

×

Cloud providers bundle governance with vendor lock-in

×

Open-source guardrails handle injection — but miss audit, compliance, and identity

€35M+
Maximum EU AI Act penalty
Aug 2026
EU AI Act enforcement deadline
0
Governance platforms with built-in EU compliance

The Control Plane Between
Your AI Agents and the Real World

Self-hosted enterprise platform that governs every AI agent action through deterministic policy enforcement, human-approval workflows, and immutable audit trails.

Governance by Architecture

SHIELD policy engine enforces decisions before execution — not retrospectively. Deny-by-default. Declarative. Auditable.

Compliance Evidence Automated

AI Act risk classification, GDPR data subject rights, NIS2 incident reporting — evidence artifacts generated from operations, not paperwork.

Self-Hosted, Fully Owned

Zero cloud dependency. Air-gapped support via Ollama. Your data never leaves your infrastructure. Deploy on Docker, Kubernetes, or bare metal.

Everything You Need to Govern
AI Agents at Enterprise Scale

SHIELD Policy Engine

Deny-by-default governance

Declarative YAML policies with typed effects: allow, deny, require_approval, allow_with_redaction. Every agent action evaluated before execution.

Deterministic decisions, not probabilistic monitoring

Immutable Audit Trail

Ed25519 signed evidence chains

Append-only audit log with optional cryptographic hash-chain signing. Tamper-evident records for regulatory proof and forensic analysis.

Answer "who approved what, when?" in seconds

Human Approval Workflows

Oversight where it matters

Configurable approval gating for high-risk operations. Identity-bound decisions with OIDC/SAML SSO. Bulk actions via admin console.

High-value decisions always require human sign-off

Enterprise Identity & Access

OIDC + SAML + SCIM + RBAC

Full SSO with OIDC (PKCE) and SAML 2.0. SCIM v2 provisioning for automated joiners/movers/leavers. Role-based access control with per-tenant isolation.

Employees offboarded? Sessions revoked instantly.

Skill Governance Lifecycle

Draft → Approve → Sign → Publish → Monitor

YAML-based skill definitions with Ed25519 signing. Supply-chain integrity verification. A/B testing, metrics tracking, and LLM usage budgets.

No agent skill runs without review and signing

Distributed Kill Switch

Immediate emergency halt

Durable kill switch that halts all agent execution across replicas within seconds. Persists across restarts. Because "undo" doesn't exist for sent emails.

One click to stop everything. Instantly.

Defense-in-Depth Security

Prompt Injection Detection (13-pattern heuristic fusion) PII Scanner (15+ regex patterns) AES-256-GCM Encrypted Memory Store Deno Sandbox (restricted permissions) CSRF Enforcement on Mutations Token-Bucket Rate Limiting Request Body Guard (configurable max size) Secret Validator (fail-fast on placeholders)

Security-First Architecture.
Self-Hosted on Your Infrastructure.

// Your Infrastructure

AI Agents            Sentinel Gateway
Claude, GPT,SHIELD Policy Engine
Ollama              Audit Trail (Ed25519)
                    Identity (OIDC / SAML)
Enterprise          Skill Engine + Signing
SAP, M365,Kill Switch (distributed)
Jira                Compliance (AI Act / GDPR / NIS2)

Storage: SQLite (single) | PostgreSQL (multi-tenant)
Deploy:  Docker | K3s / Kubernetes | Ansible / VM

Docker Compose

Single command startup. 6 profiles: dev, TLS, multi-tenant, observability, demo, local-LLM.

docker compose up

Kubernetes (K3s)

HA with replicas, PDB, HPA, default-deny NetworkPolicy. Production-ready Kustomize configs.

bash scripts/deploy-k3s.sh prod-ha

VM / Ansible

Single-node bare metal. Systemd service management. No container runtime required.

ansible-playbook deploy.yml

Built for EU Regulation.
Not Bolted On.

Governance workflows and audit artifacts generated from operations. Compliance evidence automation across four frameworks.

EU AI Act

Implemented
  • Risk classification engine (Annex III mapping)
  • Technical documentation per Art. 11
  • Transparency disclosure headers (Art. 50)
  • X-Sentinel-AI-Disclosure: true

GDPR

Implemented
  • Data-Subject Rights APIs (access, erasure, portability)
  • Processing register pre-populated
  • DPIA baseline generator with data-flow mapping
  • Retention policies with legal-hold protection

NIS2

Implemented
  • Incident reporting with 1h/24h/72h deadline calculator
  • Asset register (SBOM as machine-readable inventory)
  • Supply-chain governance with vulnerability SLA
  • Access control with managed secret policies

ISO 42001

Readiness Package
  • AI Management System readiness mapping
  • Release evidence checklist
  • Control register with gap analysis
  • Governance loop for continuous improvement

Compliance API Preview

# Classify an agent under EU AI Act
curl -X POST https://sentinel.your-domain.com/v1/compliance/ai-act/classify \
  -H "Authorization: Bearer $TOKEN" \
  -d '{"agentId": "invoice-matcher", "purpose": "automated_invoice_processing"}'

# Response
{
  "riskLevel": "limited",
  "transparencyObligations": ["art50_disclosure"],
  "recommendedControls": ["human_oversight", "audit_logging"]
}

Transparent Pricing.
No Per-Token Surprises.

Predictable annual licensing. No consumption billing. No cloud vendor lock-in.

Starter

€44,000/year
  • 1 production environment
  • Up to 10 governed agents
  • SQLite or PostgreSQL
  • Standard support (next business day)
  • Core compliance modules
  • 99.5% SLA
Start Pilot

Enterprise

€295,000+/year
  • 6+ production environments
  • Unlimited + HA clustering
  • Dedicated PostgreSQL
  • Premium+ support (30min Sev-1, 24/7)
  • Full compliance + custom modules
  • Dedicated Customer Success Manager
  • On-site onboarding available
  • 99.95% SLA
Contact Sales

Optional Add-Ons

Additional Managed Environment€16,500/year
High-Availability Operations Package€39,000/year
Compliance Evidence Package€32,000/year
Custom Adapter Implementation Sprint€28,000/sprint

Support & SLA Matrix

SeverityStandardPremiumPremium+
Sev-1 CriticalNext business day1h response, 24/730min response, 24/7
Sev-2 High8 business hours4 hours2 hours
Sev-3 Medium3 business daysNext business day8 business hours
Sev-4 Low5 business days2 business daysNext business day

All prices in EUR. USD invoicing available on request. Annual billing, net 30. Initial term 12 months with annual renewal.

30-60 Day Pilot

Try Sentinel Agent on one priority workflow. Baseline KPIs measured — cycle-time reduction, approval latency, compliance evidence completion rate. Up to 50% of pilot fee credited toward Year 1 subscription.

Start Your Pilot

Built to Enterprise Standards

0
Tests Passing, Zero Failures
0
REST API Endpoints
0
Thousand Lines of TypeScript
0
PostgreSQL RLS-Isolated Tables
6-Job CI/CD Pipeline 18 Architecture Decision Records Ed25519 Signed Audit WCAG 2.1 AA Accessible

Connect to Your Enterprise Systems

IMAP Email

Triage, categorize, draft responses with approval gates

Microsoft 365

Mail, calendar, files via Graph API with policy enforcement

Jira / Confluence

Read/write with mutation audit trails

SAP OData

Approval-gated transactions for high-value operations

Custom Adapters

Build your own with the MCP Adapter SDK

Frequently Asked Questions

LangSmith and LangFuse are observability platforms — they show you what happened. Sentinel Agent is a governance control plane — it enforces what's allowed to happen. SHIELD policies evaluate every action before execution, not after. Our immutable Ed25519 audit trail proves tamper evidence. And our compliance modules automate EU AI Act, GDPR, and NIS2 evidence — something no observability platform offers.

Yes. Sentinel Agent supports Ollama for local LLM inference with zero external API calls. Combined with Docker or VM deployment, you can run the entire platform on-premises with no internet connectivity required.

Anthropic Claude, any OpenAI-compatible API, and Ollama for local/air-gapped deployments. The platform is LLM-agnostic — you bring your own models, we govern them.

Yes. The full 46,000+ LOC TypeScript codebase is available under Apache 2.0. All security controls, compliance modules, deployment configs, and tests are included. Commercial support, SLAs, and managed services are available through FRECH & WUEST GmbH.

Docker Compose: under 5 minutes. Kubernetes (K3s): under 30 minutes with our production configs. VM deployment: under 1 hour with Ansible playbook. A typical pilot is operational within 1-2 weeks including configuration and integration.

Sentinel Agent is self-hosted. Your data lives on your infrastructure, in your data center, in your jurisdiction. There is zero cloud dependency and no data ever leaves your control.

Sentinel Agent includes AI Act risk classification (Annex III), technical documentation support (Art. 11), and transparency disclosure headers (Art. 50). Our compliance module generates the evidence artifacts regulators expect. Starting a pilot now gives you a proven governance framework well before the deadline.

How We Compare

CapabilitySentinel AgentLangSmith / LangFuseAWS Bedrock GuardrailsGuardrails AIDIY
Pre-execution policy enforcementPartialBuild it
Immutable audit trail (Ed25519)Build it
EU AI Act compliance moduleBuild it
GDPR data-subject rights APIsBuild it
Self-hosted / air-gappedCloud onlyAWS only
Human approval workflowsBuild it
OIDC + SAML + SCIMSAMLIAMBuild it
Kill switch (distributed)Build it
Prompt injection detectionBuild it
Time to production2 weeks1 day1 day1 week18+ months

Ready to Govern Your AI Agents?

Start a 30-60 day pilot. Measure the difference. Up to 50% credited toward your first year.