Security should never require blind trust.

We explain what Sentinel communicates, how it protects accesses and secrets, what data it retains and where the responsibilities of the platform end.

Self-hosted coremTLS agent-serverConfines declared
Control

The core remains in the defined infrastructure.

The console and database do not depend on a mandatory public SaaS for essential operation.

Protection

Identity and channels are verified.

Agent, users and operations use separate controls, suitable for the type of communication.

Transparency

The limits are part of security.

Backups, human monitoring and SLAs are not implicit: they apply only when stated in the offer.

Data flow

Operational data comes from the protected server.

The agent applies the local defences and sends the necessary information to the central core for fleet management.

01Request or EventWeb traffic, access, log or file change
→
02Local AgentAnalysis, policy and server block
→
03MTLS channelAgent and core authenticate
→
04Central consoleEvent, status, audit and report

The content and detail of the events depend on the modules and configuration. Paths, logs, retention periods and integrations are defined in the deployment.

Data processed

Four categories, with precise operational purposes.

Infrastructure

Fleet inventory

Server ID, hostname, operating system, agent version, declared capabilities and connection status.

Security

Events and blocks

Type of event, date, server, origin, rule, outcome and technical details provided by the configured module.

Access

Users and audits

Console accounts, role, status of the second factor and trace of administrative operations.

Integrations

Configurations and secrets

Tokens and technical credentials strictly necessary for optional channels configured in the deployment.

Communications and secrets

Protection in transit and application encryption.

The gRPC link between agent and core uses mTLS certificates. Sentinel stores application secrets in a vault with AES-256-GCM with its primary key kept outside the database.

  • mTLS: mutual verification of identity in the agent-server channel.
  • TLS: protects dashboards and exposed APIs via the configured reverse proxy.
  • AES-256-GCM: Authenticated encryption for vault-managed secrets.
  • Key rotation: primary key support and previous keys for transition.

The presence of a control in the software does not replace the configuration: certificates, keys and permissions are checked during deployment.

protected channels
Agentclient certificate
mTLS
CoreCA and server certificate
Secret vaultsAES-256-GCM · key separated from DB

Access to the console

A single login must not open every door.

Credentials

Password and session

Passwords are verified via bcrypt hash. Authentication cookies are HttpOnly, SameSite and Secure on HTTPS requests.

Second factor

TOTP

The second step can be enabled for accounts and uses a temporary session separate from the fully authenticated session.

Authorisation

Viewer, Operator and Admin

The roles separate consultation, operational activities and administration; controls are also applied by the APIs.

Changes

CSRF and rate-limit

Session operations require a valid CSRF token and login rate limiting restricts repeated attempts.

Audit and retention

Sensitive actions leave a trace.

The audit log combines actor, action, resource, origin, outcome and date. Normal application functions cannot rewrite an already recorded entry.

  • Append-only for updates: The database prevents the modification of existing audit entries.
  • Separate Retention: Audits, events, agent logs and block history have configurable windows.
  • Retention-based deletion: Immutability does not mean unlimited preservation.
  • Limited access: The audit log is restricted to the intended role.

Software default values

Events30 days
Agent logs14 days
Block history90 days
Audits180 days

The values can be changed in deployment. The contract and technical requirements prevail over the defaults.

Updates

A new release must demonstrate its origin and integrity.

The agent update process includes checks before and after replacement.

01

Ed25519 signature

The manifest is rejected if the signature of the checksum is invalid.

02

Checksum SHA-256

The downloaded bytes must match the declared fingerprint.

03

Rollout canary

The distribution may start from a limited group before extending to the fleet.

04

Agent backup and rollback

The previous release is temporarily preserved for restoration if the health check fails.

Operational boundaries

What Sentinel does not include by default.

Platform controls

  • Configured application and host protection.
  • Protected communication between components.
  • Roles, 2FA, audit and application retention.
  • Verified updates and controllable rollout.
  • Centralised visibility on events and status.

Not implicit in the standard fee

  • Full backup of servers, databases or applications.
  • Continuous 24/7 human monitoring.
  • SLA or response times not reported in the offer.
  • Forensic recovery of systems already compromised.
  • Scrubbing of L3/L4 volumetric network attacks.

The temporary backup used during the agent update is not an infrastructure backup. Backups, replication and disaster recovery depend on the services purchased and deployment.

Responsible disclosure

Have you identified a possible vulnerability?

Send a technical description to security@gtechgroup.it, indicating component, version, impact and steps to reproduce. Avoid destructive tests, access to third-party data and publication before coordination.

Frequently asked questions

Security explained without vague formulas.

Where are the data stored?

In the self-hosted core defined for the customer. Location, backup and access depend on the deployment and infrastructure services purchased.

Are data encrypted?

Agent-server communications use mTLS. Application secrets can be encrypted with AES-256-GCM and database-separated key.

Can audit records be deleted?

It cannot be rewritten by the normal application functions, but it can be deleted when the configured retention period expires.

Does the service include backup?

Not automatically. The infrastructure backup is distinct from Sentinel and only applies when included in the server service, VPS, hosting or offer.

Is Sentinel a 24/7 SOC?

No, except for a specific agreement. Automation works continuously; human monitoring, communication channels and response times follow the contract or any SLA.

How do I report a vulnerability?

Write to security@gtechgroup.it. The contact is also published in the domain's standard security.txt file.

We evaluate security and deployment together.

We confirm controls, retention, responsibilities and infrastructure services prior to activation.