Architecture v0.2 β SentinelAI base + PromptShield merge
Direction (2026-09): keep the SentinelAI stack (AWS serverless, on-device processing, no Vercel/Supabase) and fold in the best of PromptShield for the regulated-SMB market (healthcare / legal / accounting, 5β200 staff). Brand (SentinelAI vs PromptShield) is a later call.
Why this direction: our stack is AWS-native with nothing leaving the device by default, and β a happy accident β Presidio is Python, so it runs inside our Python/FastAPI agent, exactly where PromptShield couldn't run it (Vercel functions can't launch a Python sidecar).
Classification pipeline (endpoint, layered)
Each layer runs only if the previous one wasn't confident. Secrets are tokenized before any model.
paste / prompt (in memory, never persisted raw)
β
βΌ
1. Regex redaction + tokenization secrets (keys, SSN, MRN, cardsβ¦) β tokens BEFORE any model
β
βΌ
2. Presidio [NEW β PromptShield] local PII/PHI named-entity detection (Python, in-agent)
β
βΌ
3. Local SLM (Ollama) suppress false positives / detect semantic PHIΒ·LegalΒ·IP
β
βΌ
4. Cloud LLM (Bedrock) [optional] only if tenant allows AND device isn't localOnlyProcessing
β
βΌ
category (closed set) + confidence β policy decides monitor / warn / block β event to platform
Components
| Layer | v0.2 | Change |
|---|---|---|
| Sensors | MV3 browser extension (have) + native desktop clipboard agent (foreground-gated) | +desktop agent for non-browser AI apps |
| Endpoint agent (Python/FastAPI) | regex β Presidio β Ollama β optional Bedrock; policy + fail-open + tokenization | +Presidio, +tokenization, +enforcement modes |
| Central platform (AWS serverless) | Lambda + DynamoDB + Cognito auth + roles + policies + onboarding; billing later | +auth/roles/tenancy, +policy API, +onboarding |
| Dashboard (Next static / CloudFront) | +login, onboarding, policy editor, event detail, roles; keep events + feedback | +auth-gated app surface |
Categories (closed set + confidence)
Compliance-aligned discriminated union: PHI Β· PII Β· Financial Β· Legal-Privileged Β· Source-Code-IP Β·
None (+ optional Credential/Secret β see Decision 1). Every classification carries a confidence
and provenance (which layer + rules_version).
Enforcement modes (reconciles blocking vs non-blocking)
Policy-driven per org + category β this is how we keep both worlds:
| Mode | Behavior | For |
|---|---|---|
monitor |
log only, no user friction | audit-first compliance buyers (PromptShield default) |
warn |
non-blocking dialog + log | coaching |
block |
intercept-before-send (proven in SentinelAI) | strict enforcement |
Default for the regulated-SMB market: warn (auditable, low friction); block available.
Privacy & safety (non-negotiables β adopted from PromptShield)
- Raw text never persisted β processed in memory, discarded.
- Tokenize secrets before any LLM call (local or cloud).
- Excerpts masked, β€ 80 chars.
- Fail open β pipeline/backend down β allow + queue the event locally.
- Tenant isolation β enforced from the authenticated identity; per-tenant DynamoDB partition (DynamoDB has no Postgres RLS, so isolation is enforced in the data layer + IAM, not ad-hoc filters).
- No keylogging β the desktop agent reads the clipboard only while a recognized AI app is foreground.
- On-device by default β cloud LLM escalation is opt-in per tenant;
localOnlyProcessingdisables it.
What we keep from SentinelAI (unchanged)
AWS serverless (SAM), DynamoDB, on-device Ollama, the MV3 extension + block-before-send technique,
org/department policy tailoring, rules versioning (/rules), and the dlp.kshetra.studio
docs/dashboard/backlog site.
What we drop from PromptShield
Vercel + Supabase (we're AWS-native), and the Electron desktop agent (we extend our Python agent instead β same job, no Electron, one language). Presidio, the privacy rules, categories, roles/auth, onboarding, and billing all come across.