Skip to main content
Home Products SinonSentinel

50 Tools. One Platform. Your Data.

Unifies RMM, EDR, patch management, PAM, SOAR, backup, compliance, and 40+ more capabilities into a single deployment. Deploy on your infrastructure or let us host it for you. Either way, your clients' data is 100% yours. We never access, mine, or sell it. Fully customisable per client.

No per-endpoint SaaS fees. No data mining. No vendor lock-in. Hardware-accelerated AI with Hailo-10H NPU support.

Coming Soon

This product is currently in development. Contact us to register your interest.

The Numbers Behind SinonSentinel

50

Integrated Features

From endpoint agents to compliance reporting: every capability an MSP needs, in one codebase.

10

Security & IT Domains

Endpoint, network, identity, threat detection, cloud, vulnerability, response, compliance, and MSP operations. All covered.

58

API Route Modules

Every feature backed by a dedicated REST API module.

52

Database Migrations

Schema versioned from day one across the platform's data model.

52

Battle-Tested Migrations

Schema versioned from day one. Every table, index, and constraint tracked through 52 Alembic migrations.

What SinonSentinel Does

Eight core capabilities. Each one replaces a standalone vendor tool. Together, they eliminate the need for a fragmented MSP stack.

🖥

RMM & Agent Deployment

Lightweight agents report real-time telemetry (CPU, memory, disk, network, process lists) directly to your SinonSentinel instance. Define alert policies, discover network assets automatically, and manage endpoints remotely without routing any data through a third-party cloud.

Full remote shell, scripting, and task execution built in.

🛡

EDR & Threat Detection

Behavioural analysis correlates process trees, file mutations, and network connections to surface threats that signature-based tools miss. Automated containment isolates compromised endpoints in seconds. All endpoint telemetry stays on your network: no vendor-side data lake required.

Includes process rollback and forensic timeline reconstruction.

SOAR & Attack Stories

Automated playbooks orchestrate response across all 50 features: isolate an endpoint via EDR, block a domain via DNS Shield, revoke credentials via PAM, all from a single workflow. Visual attack story reconstruction maps the full kill chain. AI-assisted remediation suggests next steps based on incident context.

Evidence locker preserves chain-of-custody for every artefact.

🔐

Privileged Access Management (PAM)

Credential vaulting with AES-256 encryption at rest. Just-in-time access grants temporary elevated privileges with automatic revocation. Full session recording captures every keystroke and command for audit. Granular approval workflows enforce dual-authorisation for sensitive operations.

Every credential checkout produces an immutable audit trail.

🌐

EASM & Dark Web Monitoring

External attack surface discovery scans your clients' domains, subdomains, exposed services, and certificate chains continuously. Dark web monitoring detects credential leaks, data dumps, and brand mentions across paste sites, forums, and marketplaces. Alerts fire before attackers can exploit what they find.

Automated subdomain enumeration with DNS, certificate transparency, and passive reconnaissance.

💾

Backup, DR & Chaos Engineering

Automated backup scheduling with retention policies. Disaster recovery orchestration handles failover sequencing and validation. Controlled chaos engineering models failure scenarios (process kills, network partitions, disk pressure) into staging environments to prove your recovery runbooks actually work before an incident forces you to find out.

DR plans are tested, not assumed.

📋

Compliance Drift & Regulatory Intelligence

Continuous compliance monitoring against CIS Benchmarks, NIST CSF, SOC 2, ISO 27001, and custom frameworks. Drift detection alerts the moment a configuration deviates from baseline. Security-as-Code policy enforcement lets you define compliance rules as version-controlled artefacts. Regulatory intelligence tracks changes to frameworks and maps them to your current controls.

Compliance becomes a continuous process, not a quarterly scramble.

🏢

MSP Hub & Client Portal

Per-client branded portals give your customers visibility into their security posture without exposing your internal tooling. Quarterly Business Review generation pulls live data from every module. Revenue analytics track MRR, churn, and margin per client. Prospect lifecycle management handles the pipeline from lead through onboarding to renewal.

Billing reconciliation, insurance readiness scoring, and skills gap analysis included.

One Platform to Replace Your Entire Stack

Most MSPs run 10 to 15 separate vendor tools across endpoint management, security, compliance, and client operations. Each tool has its own agent, its own dashboard, its own billing model, and its own data silo. SinonSentinel consolidates all of them into a single deployment.

Before SinonSentinel

  • Separate RMM tool (ConnectWise, Datto, NinjaOne)
  • Separate EDR vendor (SentinelOne, CrowdStrike, Sophos)
  • Separate patch management (Automox, ManageEngine)
  • Separate PAM tool (CyberArk, Delinea, Keeper)
  • Separate DNS filtering (Cisco Umbrella, DNSFilter)
  • Separate email security (Proofpoint, Abnormal)
  • Separate SOAR / ticketing (Palo Alto XSOAR, Tines)
  • Separate backup vendor (Veeam, Acronis, Axcient)
  • Separate compliance platform (Drata, Vanta, Scytale)
  • Separate vulnerability scanner (Tenable, Qualys, Rapid7)
  • Separate dark web monitoring (SpyCloud, ID Agent)
  • Separate EASM tool (Censys, Shodan)
  • Separate threat intel feed (Recorded Future, GreyNoise)
  • Separate client portal / PSA (HaloPSA, Autotask)
  • Separate billing & analytics (various)

15+ vendors. 15+ invoices. 15+ integrations to maintain.

After SinonSentinel

  • One codebase: a unified Python backend and TypeScript frontend
  • One database: PostgreSQL with 52 versioned migrations
  • One deployment: bare metal, Docker, Kubernetes, cloud VMs, virtual environments, or air-gapped
  • One agent: covers RMM telemetry, EDR behavioural analysis, patch inventory, and device trust
  • One API: 58 route modules with consistent authentication, tenant isolation, and audit logging
  • One UI: purpose-built management views, searchable and filterable
  • One bill: your infrastructure costs — no per-endpoint SaaS surcharges

Single pane of glass is a marketing cliche. This is the engineering reality.

Your Brand. Your Workflows. Your Clients' Experience.

SinonSentinel is not a rigid SaaS product where every MSP gets the same interface with the same limitations. It is a platform you own and configure to match how your organisation actually operates.

White-Labelling & Branding

Deploy SinonSentinel under your own brand. Each client tenant can have its own logo, colour scheme, and custom domain. Your clients see your brand, not ours. The entire login experience, portal, PDF reports, and email notifications carry your identity.

Custom Workflows & Automation

Define your own SOAR playbooks, alert escalation paths, and automated response sequences. Playbooks can chain actions across any of the 50 features: isolate an endpoint, revoke a credential, create a case, notify a client, all in a single automated workflow that matches your SOPs.

Branded Client Portals

Each client gets a purpose-built portal showing exactly the data you choose to expose. Dashboards, compliance scores, incident summaries, and posture ratings. All rendered under your brand with your terminology. Clients self-serve without seeing your operational tooling.

Configurable Dashboards

Build dashboards per client, per team, or per analyst. Widget library covers every data source in the platform: endpoint health, detection rates, compliance drift, patch coverage, backup status, and more. Drag, drop, and save layouts per user role.

Alert Policies & Escalation Paths

Define alert thresholds, routing rules, and escalation ladders per client. Critical detections for Client A can page your SOC lead. Informational alerts for Client B can create a ticket. Every policy is tenant-scoped and version-controlled.

Per-Tenant Feature Toggles

Not every client needs all 50 features. The feature toggle system lets you enable or disable any capability per tenant, per group, or per user. Client A gets EDR + PAM + Compliance. Client B gets RMM + Patch + Backup. You control exactly what each client sees and pays for.

All 50 Features — Organised by Domain

Every feature listed below is implemented with dedicated database tables, API routes, service logic, and frontend views. These are not roadmap items or coming-soon placeholders.

Endpoint Security (5 Features)

RMM & Agent Management EDR & Behavioural Detection Patch Management Device Trust Scoring Application Allowlisting

Real-time agent telemetry, process-level behavioural analysis, automated patch deployment with approval workflows, device trust posture scoring, and application allowlisting to prevent unauthorised software execution. Every data point stays on your infrastructure.

Network & Perimeter (4 Features)

DNS Shield & Threat Filtering Network Infrastructure Monitoring Microsegmentation External Attack Surface Management (EASM)

DNS-layer threat blocking with category filtering and custom policies. Network device monitoring for switches, routers, and firewalls. Microsegmentation policy enforcement to limit lateral movement. Continuous external attack surface discovery across domains, subdomains, and exposed services.

Identity & Access (3 Features)

Privileged Access Management (PAM) Identity Threat Detection & Response (ITDR) Identity Correlation Engine

Credential vault with JIT access, session recording, and approval workflows. Anomalous authentication detection: impossible travel, credential stuffing, privilege escalation patterns. Cross-source identity correlation maps the same user across Active Directory, cloud IdPs, VPN logs, and endpoint activity.

Threat Detection & Intelligence (6 Features)

Email Security Threat Intelligence Platform Dark Web Monitoring Phishing Simulation Deception Technology (Honeypots) Continuous Threat Exposure Management (CTEM)

Inbound email analysis with header inspection, URL detonation, and attachment sandboxing. Multi-feed threat intelligence aggregation with IoC matching. Dark web credential leak detection. Phishing simulation campaigns with training tracking. Honeypot deployment for early breach detection. CTEM continuously maps your exposure to real-world attack techniques.

Cloud & SaaS Security (3 Features)

CSPM & Cloud DLP SaaS Security Posture Management (SSPM) Shadow IT Discovery

Cloud security posture management scans AWS/Azure/GCP configurations against CIS benchmarks. SSPM monitors SaaS application configurations: OAuth grants, sharing settings, admin roles. Shadow IT discovery identifies unsanctioned cloud services through DNS, proxy, and endpoint telemetry.

Vulnerability & Risk (5 Features)

Vulnerability Management Security Posture Score Risk Prediction Engine Security Benchmarking Digital Twin Simulation

Vulnerability scanning with CVE prioritisation based on exploitability and asset criticality. Composite posture scoring aggregates data from every module into a single defensible metric. Predictive risk modelling forecasts likely attack paths. Benchmarking compares posture against industry peers. Digital twin builds a modelled snapshot of your environment to run attack scenarios without touching production.

Response & Forensics (5 Features)

SOAR Playbooks Attack Story Reconstruction Investigation Workbench Evidence Locker AI-Assisted Remediation

Automated response orchestration chains actions across the full platform. Visual attack story graphs reconstruct kill chains from raw telemetry. Investigation workbench provides a structured interface for threat hunting with pivot and drill-down. Evidence locker preserves artefacts with hash verification and chain-of-custody metadata. AI remediation analyses incident context and recommends containment and recovery actions.

Compliance & Governance (5 Features)

Compliance Drift Detection Regulatory Intelligence Security as Code Insurance Readiness Quarterly Business Reviews (QBR)

Continuous drift monitoring against CIS, NIST, SOC 2, ISO 27001, and custom frameworks. Regulatory intelligence tracks framework changes and maps impact to your controls. Security-as-Code defines compliance policies as version-controlled YAML artefacts: auditable, repeatable, testable. Insurance readiness scoring assesses your posture against common cyber insurance questionnaires. Automated QBR report generation pulls live data from every module.

Resilience & Infrastructure (4 Features)

Backup & Disaster Recovery Supply Chain Risk Monitoring Chaos Engineering Asset Relationship Graph

Automated backup with configurable retention and DR orchestration with failover validation. Supply chain monitoring tracks dependencies (software vendors, SaaS providers, open-source libraries) and alerts on disclosed vulnerabilities or compromises. Chaos engineering runs controlled failure experiments to validate resilience. Asset graph maps relationships between endpoints, users, services, and network segments to understand blast radius.

MSP Operations (10 Features)

MSP Hub Dashboard Client Portal Revenue Analytics Prospect Lifecycle Client Onboarding Billing Reconciliation Insurance Brokerage Tools Skills Gap Analysis Communications Hub Agentic AI Assistants

The MSP operations layer treats the business of running an MSP as a first-class concern. Revenue analytics tracks MRR, churn, ARPU, and margin per client. Prospect lifecycle management handles pipeline from lead capture through proposal to signed contract. Automated onboarding workflows provision tenants, deploy agents, and configure baseline policies. Billing reconciliation matches usage to contracts. Insurance brokerage tools help position cyber insurance alongside your services. Skills gap analysis identifies training needs across your team. Communications hub centralises client notifications. Agentic AI provides LLM-powered assistants for incident triage, report generation, and anomaly investigation.

Deployment Options

SinonSentinel runs wherever you need it: on physical hardware, in virtual machines, across cloud providers, inside containers, or on air-gapped networks. Every deployment method includes the complete platform, with all 50 features, all 58 API modules, and every management view. No feature gating by deployment type.

🖥

Bare Metal

Direct installation on Ubuntu/Debian or RHEL/Rocky. PostgreSQL, Redis, and Nginx configured automatically. Systemd services for the FastAPI backend, Celery workers, and agent communication broker. Single-server or distributed deployment.

install.sh --install
📦

Docker

Production-ready Docker Compose with dedicated containers for the API, worker pool, Redis, PostgreSQL, and Nginx reverse proxy. Health checks, restart policies, and volume mounts pre-configured. One command from clone to running platform.

docker compose up -d

Kubernetes

Helm chart with configurable replicas, resource limits, and horizontal pod autoscaling. Bitnami subcharts for PostgreSQL and Redis. Ingress, TLS termination, and network policies included. Tested on EKS, AKS, GKE, and bare-metal K8s clusters.

helm install sinonsentinel ./helm
🔒

Air-Gapped

For defence, government, and high-security environments with no internet access. Pre-packaged bundle includes all Python wheels, Node modules, container images, and system dependencies. Offline installation with the same feature set. Nothing phones home.

install-airgap.sh --bundle ./sinonsentinel-bundle.tar.gz

Cloud VMs

Deploy on AWS EC2, Azure VMs, GCP Compute Engine, or any IaaS provider. Use your cloud infrastructure without surrendering data to vendor-managed SaaS. All installation scripts work identically whether the host is physical or cloud-provisioned. Combine with managed Kubernetes (EKS, AKS, GKE) for elastic scaling.

🖥

Virtual Environments

Full support for VMware ESXi/vSphere, Microsoft Hyper-V, Proxmox VE, KVM/QEMU, and Xen. Deploy as a VM alongside your existing virtualised infrastructure. Snapshot, clone, and template using standard hypervisor tooling. No hardware-specific dependencies.

Why Your Clients' Data Stays Yours

Three arguments that get stronger every year.

Your Clients Trust You With Their Data

When you use a cloud-hosted RMM or EDR, every endpoint's telemetry (process lists, file hashes, network connections, user activity) flows through your vendor's infrastructure. Your client signed an agreement with you, not with your vendor's cloud provider.

With SinonSentinel, client data stays under your control, whether you self-host or let SinonTech host it for you. Either way, we never access, read, mine, or sell your clients' data. You own 100% of it. You can answer "where is our data stored?" with confidence.

Data ownership is not a feature. It is a contractual obligation.

MSP Tools Are Prime Targets

The Kaseya VSA attack in 2021 compromised over 1,500 organisations through a single vendor's cloud infrastructure. SolarWinds Orion demonstrated that supply chain compromise can persist for months undetected. MSP tooling has privileged access to every managed endpoint, making it the highest-value target in any attack chain.

SinonSentinel eliminates the shared-cloud attack surface. Your instance is not shared infrastructure, whether it runs on your servers or ours. There is no multi-tenant vendor cloud where a vulnerability in one MSP's environment affects all others. Your security posture is your own.

Your platform should not be someone else's single point of failure.

Margin Matters

Per-endpoint SaaS pricing hits at every scale. A solo IT consultant managing 30 endpoints pays per seat. A growing MSP with 500 endpoints watches margins shrink with every onboarding. An enterprise MSP at 10,000+ sees vendor costs consume the revenue growth they worked to build.

SinonSentinel breaks that linear cost curve. Whether you self-host or use our managed hosting, costs scale with compute and storage, not with endpoint count. Whether you manage 20 endpoints or 20,000, the same deployment runs without per-seat surcharges. Start small on a single server and grow into a clustered deployment as your client base expands.

Same platform at 50 endpoints as at 50,000. Your margins improve at every stage of growth.

Under the Hood

SinonSentinel is built by engineers who have operated MSP infrastructure at scale. The architecture reflects hard-won lessons about what breaks at 2 AM and what survives audit season.

Backend

LanguagePython 3.11+ with FastAPI
DatabasePostgreSQL with 52 Alembic migrations
Task QueueCelery with Redis broker
API Surface58 route modules, JWT + API key authentication
Multi-TenancyRow-level tenant isolation on every table
MiddlewareRate limiting, structured audit logging, tenant context injection
AI AccelerationHardware Abstraction Layer (HAL) with Hailo-10H NPU, NVIDIA GPU, and CPU fallback
AI Models15 security classifiers (107 classes) — threat, malware, ransomware, phishing, LOLBin, encrypted traffic, identity, cloud
Agent ProtocolLightweight agent binary with encrypted check-in

Frontend

FrameworkReact 18 with TypeScript
Build ToolVite
StylingTailwind CSS with dark mode default
StateZustand stores with React Query for server state
RoutingReact Router with role-based and feature-gated access
ViewsPurpose-built page components across all 50 features
ComponentsShared component library (badges, cards, charts, tables, forms)

Hardware-Accelerated AI — Hailo-10H NPU

SinonSentinel includes a Hardware Abstraction Layer (HAL) that detects and utilises dedicated AI accelerator hardware. When a Hailo-10H NPU is present, security classification tasks run at sub-millisecond latency, catching threats before they execute, not after.

Why Dedicated AI Hardware?

Traditional security tools classify threats on general-purpose CPUs, adding latency to every decision. A ransomware process can encrypt thousands of files in the time it takes a CPU-bound model to return a verdict.

The Hailo-10H NPU is a dedicated neural processing unit designed for real-time inference. It runs 15 security classification models simultaneously, each scoring events in under 1 millisecond. The NPU handles classification and scoring workloads while your CPU and GPU remain free for LLM-powered tasks like remediation reasoning and report generation.

The HAL automatically detects available hardware (CPU, NVIDIA GPU, Hailo NPU) and routes each task type to the optimal accelerator. No configuration required. It just works. If no NPU is present, everything falls back to GPU or CPU gracefully.

Smart Task Routing

Task CategoryPreferred Device
Threat / malware classificationHailo NPU → GPU → CPU
Ransomware behavioural detectionHailo NPU → GPU → CPU
Encrypted traffic classificationHailo NPU → GPU → CPU
LOLBin / Living-off-the-LandHailo NPU → GPU → CPU
DNS threat scoringHailo NPU → GPU → CPU
Phishing / URL risk scoringHailo NPU → GPU → CPU
Identity / insider threatHailo NPU → GPU → CPU
Cloud / container threatHailo NPU → GPU → CPU
Remediation reasoning (LLM)GPU → CPU
Report generation (LLM)GPU → CPU

15 Security AI Models — 102 Classification Classes

Each model is a 1-D CNN classifier optimised for the Hailo-10H architecture. Models are trained on real-world security datasets (EMBER, NSL-KDD, URLhaus, OpenPhish, Tranco, Bambenek, MalwareBazaar, DikeDataset) with synthetic augmentation for rare attack classes.

Endpoint Security

Threat Classification (10 classes): benign, malware, ransomware, trojan, worm, adware, spyware, rootkit, exploit, APT

Malware Classification (10 classes): clean, PE malware, script, document, packed, obfuscated, dropper, backdoor, keylogger, miner

LOLBin Detection (8 classes): benign admin, recon, credential access, lateral movement, defence evasion, persistence, exfiltration, execution

Ransomware Behavioural (6 classes): normal I/O, bulk rename, shadow copy delete, rapid enumeration, encryption pattern, ransom note drop

Network & Identity

DNS Threat Scoring (7 classes): clean, DGA, typosquat, homograph, tunnel, fast-flux, malicious redirect

Network Traffic Analysis (7 classes): normal, scan, DoS, exfiltration, C2 beacon, lateral movement, brute force

Encrypted Traffic (7 classes): legitimate TLS, malware C2, Tor, VPN tunnel, cryptominer, SSL stripping, expired cert abuse

Identity Threat (8 classes): normal login, impossible travel, credential stuffing, password spray, MFA fatigue, session hijack, privilege escalation, dormant account

Email, Cloud & Insider

Phishing Detection (5 classes): legitimate, phishing, spear phishing, whaling, smishing

Email Attachment Risk (7 classes): safe document, macro-enabled, password-protected archive, LNK shortcut, ISO image, HTML smuggling, polyglot file

URL Risk Classification (8 classes): benign, credential harvest, drive-by download, watering hole, malvertising, SEO poisoning, tech support scam, cryptojacking

File Classification (5 classes): benign, suspicious, malicious, encrypted, packed

Anomaly Detection (4 classes): normal, suspicious, anomalous, critical

Insider Threat (7 classes): normal, data hoarding, access escalation, off-hours bulk download, resignation risk, policy violation, unauthorised tool

Cloud Threat (8 classes): normal, privilege escalation, resource hijack, S3 exfiltration, container escape, crypto mining, IAM persistence, public exposure

Training Pipeline

Every model ships with a complete training pipeline: synthetic data generators with domain-realistic patterns, real data loaders from free OSINT feeds, a unified data loader that prefers real data with automatic synthetic fallback, and ONNX export for Hailo DFC compilation.

python train_all.py --train-only

Train all 15 models, export to ONNX, and compile to .hef: one command.

Real-World Data Sources

  • EMBER (Elastic) — 1M+ PE file feature vectors
  • NSL-KDD (UNB/CIC) — 148K labelled network connections
  • URLhaus (abuse.ch) — active malware distribution URLs
  • OpenPhish — community phishing URL feed
  • Tranco Top-1M — research-grade clean domain ranking
  • Bambenek & Netlab 360 — DGA domain feeds
  • MalwareBazaar (abuse.ch) — tagged malware families
  • HuggingFace SMS / Email — smishing and spear phishing datasets
  • DikeDataset — labelled PE file hashes

Replace Your Stack. Own Your Platform.

SinonSentinel is in active development. Request access to receive deployment documentation, architecture walkthroughs, and priority onboarding when the platform enters beta.

Contact Us

Get in touch to discuss your requirements.

SinonSentinel is part of the SOC-in-a-Box suite by SinonTech.

Self-hosted security infrastructure for organisations that take data sovereignty seriously.

SinonForge (Git) · SinonStore (Object Storage) · SinonMeet (Video Conferencing) · Umbra (SIEM) · SinonSentinel (MSP Platform) · UmbraShield (AppSec)