🛡️ SentinelAISecurity Analyst Portal

SentinelAI — What's Installed Where

A reference for what SentinelAI puts on an endpoint, what's editable, and what talks to what.

Files & folders

macOS (install-macos.sh):

What Location
Agent code + venv ~/.sentinelai/ (app/, .venv/)
Policy (editable) ~/.sentinelai/policy.json
Agent log ~/.sentinelai/agent.log
Services (launchd) ~/Library/LaunchAgents/com.sentinelai.agent.plist, …ollama.plist
Ollama binary /usr/local/bin/ollama (or Ollama.app)
Downloaded models ~/.ollama/models
Extension the extension/ folder you Load-unpacked

Windows (SentinelAI-Windows.zip):

What Location
Agent (self-contained exe) %LOCALAPPDATA%\SentinelAI\sentinelai-agent.exe
Policy (editable) %LOCALAPPDATA%\SentinelAI\policy.json
Run wrapper + log %LOCALAPPDATA%\SentinelAI\run-agent.cmd, agent.log
Service Task Scheduler → "SentinelAI Agent"
Ollama %LOCALAPPDATA%\Programs\Ollama\
Downloaded models %USERPROFILE%\.ollama\models
Extension the extracted …\SentinelAI-Windows\extension\ folder

(%LOCALAPPDATA% = C:\Users\<user>\AppData\Local.)

What the customer edits

To change… Edit Effect
Org / department context, proprietary codenames, "public is fine" hints policy.json Live (auto-reloads)
Cloud it reports to SENTINEL_BACKEND_URL on restart
Model / thresholds / timeout OLLAMA_MODEL, SENTINEL_AI_MIN_CONF, SENTINEL_AI_DETECT_MIN_CONF, OLLAMA_TIMEOUT on restart
Department (interim, pre-auth) SENTINEL_ORG_ID / SENTINEL_DEPARTMENT selects policy bundle
The rules (regex, risk bands) code (classifier.py/risk.py) — not customer config rebuild + RULES_VERSION bump

Env vars live in the launchd plist (macOS) or run-agent.cmd (Windows). policy.json is the one file a customer edits for tailoring — see docs/TAILORING.md.

Dependencies, services, toggles

Component Windows macOS Notes
Python runtime not needed (bundled in the exe) system python3 + venv light-touch installer needs Python; the exe package doesn't
Background service Scheduled Task "SentinelAI Agent" (SYSTEM, at startup, auto-restart) launchd com.sentinelai.agent (RunAtLoad + KeepAlive) keeps the agent alive
Ollama (model runtime) its service / ollama serve launchd com.sentinelai.ollama optional — only for the AI toggle; rules work without it
Browser extension (MV3) Edge/Chrome, Load unpacked (or MDM force-install) same the sensor + enforcer
AI toggle extension popup (stored in Chrome chrome.storage, not a file) same off by default

Ports & external services

Path Address Exposure
Extension → Agent http://127.0.0.1:8787 loopback only
Agent → Ollama http://127.0.0.1:11434 loopback only
Agent → cloud backend (telemetry) https://…lambda-url.us-east-1.on.aws (443) outbound HTTPS; metadata + truncated snippet only
Dashboard / docs / download https://dlp.kshetra.studio (443, CloudFront) public site
Behind the backend Lambda → DynamoDB AWS-internal

Privacy-critical: ports 8787 and 11434 bind to 127.0.0.1 — prompt text and the model never leave the laptop. The only outbound traffic is the event record to your AWS.

Health & version checks

curl http://127.0.0.1:8787/health   # status + rules_version
curl http://127.0.0.1:8787/rules    # full rule inventory (see docs/RULES.md)