New · v1.0.0 shipped

GRIFFai Platform Extension

See every agent.
Change nothing.

GRIFF Sentinel is a standalone, local-first security monitor for AI agent activity — deterministic detections, tamper-evident evidence, and signed case bundles, entirely on your machine.

Loopback-only · No outbound network · Monitor-only by construction · Signed releases

Sentinel console

Investigation chronology
Agent session openedObserved

Lifecycle observation ingested over authenticated OTLP

Unexpected artifact write patternRule hit

Deterministic rule matched; chronology + correlation attached

Prompt content withheldRedacted

Pseudonymized before persistence — never stored raw

4adapters
13UI surfaces
SHA-256event chain

Monitor-only

It observes. It never enforces.

Agent security, on the record

You cannot govern what you cannot see.

Agents act fast and leave thin trails. Sentinel watches agent activity where it happens — locally — and turns it into an evidence-grade record you control, without touching the agents themselves.

Deterministic detections

Monitor-only rules you can read, author, and simulate — not a black-box verdict.

Tamper-evident record

Append-only events participate in a per-stream SHA-256 integrity chain.

Privacy before persistence

Sensitive content is dropped, redacted, or pseudonymized before it is ever stored.

Evidence you can hand over

Case bundles export signed, with checksums and provenance attached.

How it works

From raw agent activity to signed evidence.

  1. Ingest

    Authenticated OTLP and lifecycle observations arrive from agent adapters — Claude, Codex, Cursor, Gemini — plus an adapter kit for your own.

  2. Redact

    Prompts, message bodies, and credentials are dropped, redacted, or pseudonymized before anything persists.

  3. Detect

    Deterministic monitor-only rules evaluate the stream; the Rule Lab validates and simulates drafts without side effects.

  4. Investigate

    A local 13-surface operator console: chronology, correlation, artifact inventory, memory-integrity lineage, diagnostics.

  5. Export

    Signed case bundles carry the evidence out — with integrity chain status and provenance, not screenshots.

Boundaries are the feature

A security monitor should not be another risk.

v1.0.0 ships monitor-only for Windows (amd64), verified end to end: signed archive, SBOM, license evidence, and provenance re-checked at deploy and on every managed start.

Monitor-only by construction

No enforcement, no agent hooks, no live-product mutation. Observe and pure simulation only.

Local-first

Listens on loopback only. No off-device outbound network path exists in the shipped binary.

Privacy before persistence

Sensitive content is dropped, redacted, or pseudonymized before it reaches Sentinel's own store.

Verified supply chain

Signed release archive with SBOM, checksums, license evidence, and provenance — verified, not asserted.

Opaque agent security

Trust a verdict you cannot inspect.

  • Cloud-side analysis of your agent activity
  • Probabilistic scoring with no replayable rule
  • Evidence that is a screenshot, not a chain
  • An enforcement layer that can break the work

GRIFF Sentinel

Inspect every rule. Keep every receipt.

  • Runs entirely on your machine
  • Deterministic rules you author and simulate
  • Append-only, hash-chained evidence
  • Monitor-only — it can never break the work

GRIFF Sentinel v1.0.0

Watch the machines.
Keep the proof.

Bring one workstation running agents. Sentinel will show you what they did, prove the record was not altered, and hand you the evidence — without ever touching the agents.