Filter & Track-Back Gateway
Scans incoming email, text, and links, flags what's hostile, and sanitizes dangerous links into safe tokenized ones before they can do harm.
SENTINEL lures an attack into a trap, feeds it bait, documents everything in a forensics lab, and hands a tokenized evidence package straight to law enforcement — protecting a single family or an entire nation. We never touch anyone else's machine. That is what keeps it lawful.
Nothing ever touches a system we don't own.
No captured malware is ever executed.
Trackers are passive tokens — they identify, they never attack.
Evidence goes to the FBI IC3 / CISA, not back at the attacker.
Every hostile email, text, link, or intrusion on your own decoy surface follows the same documented path. It is caught, studied, and turned into evidence — before anything is allowed back out the door.
A decoy inbox receives a hostile email, SMS, or link on infrastructure we own. To the attacker it looks like a real target.
VigilantGuard routes the artifact into an isolated sandbox. It is held, never allowed to touch anything real.
The trap serves fake-but-real-looking credentials, keys, and files — all watermarked and tokenized, so any theft is trackable.
The lab classifies the artifact, extracts indicators, checks for a known signature or "cure," and writes a documented case file.
Tamper-evident tracker tokens are minted and bound to the case. Passive only — they identify the artifact, they never strike back.
A chain-of-custody evidence bundle with an integrity hash is packaged for FBI IC3 / CISA. Government tier gets its own isolated stream.
Just like your phone screens a call, SENTINEL screens every inbound connection. Nothing gets through until it proves who it is with the right token — and everything is logged, whether it's welcome or not.
Every caller drops into a sandbox before it can reach anything real. A copy is made; the original is held at the door.
The sandbox tears the copy apart to learn everything about it. If it's clean and the token checks out, the held original is released — with a verification anchor added.
Unknown callers are challenged, exactly like a caller-ID screen. No valid token, no entry — the attempt is recorded.
A person's token, a business's token, and a government token are all structurally different. A token that doesn't match what the caller should carry is flagged instantly.
The moment a breach or forged token is seen, the token type is switched across your systems — so the stolen one is already useless.
Who called, what token they showed, the verdict, the severity, and the exact time — all in a single running log, like a call history.
Each piece runs on its own and connects into the unified Cyber Forensics Test Lab. All local-first, all built and verified — 45 of 45 automated checks passing.
Scans incoming email, text, and links, flags what's hostile, and sanitizes dangerous links into safe tokenized ones before they can do harm.
Screens every inbound connection, forces a valid typed token, sandboxes a copy first, logs every call, and rotates tokens the instant a breach is seen.
Decoy servers and bait files that quietly pull an intruder in, auto-clone a clean decoy, and hold the hostile copy in a sealed glovebox.
Analyzes captured artifacts as inert bytes — never executed — documents the case, and grows a signature catalog to spot repeats.
AES-256-GCM authenticated encryption with tiered key derivation. Even the file listing reveals nothing. Family to government-grade.
Follows the public money trail with read-only taint analysis. Produces a law-enforcement referral. Never moves or seizes a single coin.
Jurisdiction-aware tokenized egress — domestic vs. international — with cryptographic tenant isolation. Connects to the Sovereign Control Tower.
Rotating, typed identity tokens for person, business & government — split by domestic vs. international — so no one can ever claim to be someone they are not. Even the cloud gets a token going in and a different one coming out.
Caller ID for everything leaving your system. Sensitive data is tokenized and traced on the way out, so it can never be hijacked in transit — and the most sensitive material rotates fastest.
True isolation for nuclear, grid & industrial control — not on any network whatsoever. A one-way data diode, an air-gapped vault on the protected high side, separate zones, and instant lockdown on any forged crossing.
The first film sets the doctrine in motion. The second walks through every module, step by step, with the words on screen and a narrator explaining each one.
SENTINEL is also a teaching tool. Know the lure before it reaches you — here's how the most common attacks work and how track-back answers each one.
What it looks like: An email that seems to come from your bank, boss, or a service you use, pushing you to click a link or "verify" your login right now.
Tells: urgency and threats, a mismatched sender address, links whose real destination differs from the text, and generic greetings.
How SENTINEL answers: PhishBot 3.0 scans the message, flags it, and rewrites the dangerous link into a safe tokenized one. A copy is routed to the trap so the attempt is documented, not just deleted.
What it looks like: A text about a "package delivery," "toll charge," or "suspicious login," with a short link.
Tells: unknown numbers, shortened links, and a request to tap a link or reply with personal info.
How SENTINEL answers: The decoy SMS surface catches the lure, PhishBot 3.0 classifies it, and the link is tokenized so any click can be traced back through the case file.
What it looks like: A link or file that installs malware or steals credentials the moment it's opened.
Tells: unexpected attachments, files that ask you to "enable content," and links that redirect several times.
How SENTINEL answers: The artifact is detonated only inside a simulated sandbox — never on a real machine — and studied under the forensics microscope as inert bytes.
What it looks like: Your files are encrypted and a note demands cryptocurrency to get them back.
Tells: sudden file-extension changes, a ransom note on the desktop, and a countdown timer.
How SENTINEL answers: The vault keeps an air-gapped encrypted copy so you're never held hostage, and on-chain tracing follows the ransom's public money trail for a law-enforcement referral — trace, not touch.
The line: Reaching into an attacker's system to retaliate is a federal crime under the Computer Fraud and Abuse Act (18 U.S.C. §1030). Honeypots, canary tokens, and beacons on your own systems are lawful active defense.
How SENTINEL stays on the right side: everything runs on infrastructure you own, nothing reaches out to anyone, and evidence goes to the authorities — who are the ones allowed to act.
Want this as a classroom module? The curriculum can be dropped into a whiteboard or LMS as a widget. See the docs.
Simple, honest pricing. Every plan starts with a free trial on hardware you already own — no data ever leaves your network.
Protect a household.
Up to 5 people · 1 household
Protect an organization.
Per site · up to 50 seats
Protect a nation.
Agency & critical-infrastructure
Prices are introductory and shown in USD. Nonprofits, schools, and houses of worship: ask about reduced pricing at Kristen@bornbetween2generals.com.
The full platform — plans, architecture, vision, and working prototypes — is packaged and ready to review.
The whole ecosystem on a few pages: all ten SENTINEL modules, the Sovereign layer, and the BB2G Sovereign AI Cluster — black & teal, logo throughout.
Open → PDFThe problem, the legal bedrock, the modules, the market tiers, and the go-to-market.
Open → PDFThe engineering blueprint: modules, vault, predictive threat modeling, the evidence model.
Open → PDFHow SENTINEL and the Sovereign Control Tower form one doctrine at three scales.
Open → ZIPAll documents plus the working prototypes — now including the Identity Fabric, Egress Guard, and Critical-Infra Air-Gap — with per-module run instructions.
Download →Request a free trial for your family, business, or agency, or join the briefing list for updates on new modules and the doctrine.
New modules, doctrine notes, and release news. No spam, unsubscribe anytime.
Read the long-form field notes and subscribe on Substack.
Subscribe on Substack →Substack link goes live once your publication is set up. Email us at Kristen@bornbetween2generals.com if the address changes.