Internal systems

Six things we had to build ourselves

None of these is a product. Each exists because every option we evaluated required a third party who could prevent us from switching it off — which, for an institution whose founding condition is the ability to stop, was disqualifying regardless of quality.

Sentinel Grid

Infrastructure fabric

since 1998

The substrate everything else runs on.

A private compute and storage fabric spanning our sites, built on the assumption that any site can be unreachable at any time and that the institution must keep functioning while it is. Every record has custody in at least three places and can prove it.

  • Zero-trust between sites; no implicit intra-network authority
  • Content-addressed storage with independent integrity audit
  • Partition-tolerant by construction, not by configuration
  • Full state reconstructible from any two surviving sites

Architecture & failure modes →

Atlas Engine

Analysis platform

since 2011

Turns thirty years of inconsistent records into something answerable.

The retrieval and reasoning layer over the institutional record. Its defining constraint is attribution: Atlas will decline to answer rather than answer without a citable source, and every response carries the provenance of the material it drew on.

  • Refuses unsourced synthesis by design
  • Provenance chain attached to every result
  • Operates on the Archive of record, not on a copy
  • Contradictions surfaced rather than resolved silently

Architecture & failure modes →

Argus

Observation and integrity monitoring

since 2006

Watches our own instruments for the moment they begin to lie.

Argus monitors the health and honesty of SENTINEL's own sensing estate. It does not observe people or public spaces. Its purpose is narrow and internal: detecting the drift, miscalibration and quiet failure that turn an instrument into a confident source of wrong numbers.

  • Cross-instrument corroboration before alerting
  • Calibration drift detection over multi-year baselines
  • Explicit false-positive budget per class of alarm
  • No collection against individuals, by charter

Architecture & failure modes →

Helios

Power and thermal continuity

since 1989

Keeps the lights on at sites where nobody is coming to help.

Islanded generation, storage and thermal management for remote stations. Helios assumes no grid, no fuel delivery for the season, and no engineer on site, and is designed to shed load in a defined order rather than fail as a unit.

  • Deterministic load-shedding order, rehearsed annually
  • Multi-season autonomy at reduced draw
  • Thermal envelope maintained ahead of compute
  • Manual override reachable without power

Architecture & failure modes →

Project Polaris

Timing and reference

since 2016

An agreed answer to what time it is, when nothing else agrees.

Distributed time and frequency reference for sites that may go months without external synchronisation. Polaris exists because a surprising share of our historical data quality incidents reduced, eventually, to two instruments disagreeing about when something happened.

  • Holdover measured in months, not hours
  • Disagreement surfaced rather than averaged away
  • Signed time attestations attached to observations
  • Independent of any single external reference

Architecture & failure modes →

Nexus

Secure interchange

since 2020

How material leaves the institution, when it leaves at all.

The controlled boundary between SENTINEL and everyone else: partner exchange, coordinated disclosure, and Archive publication all pass through it. Nexus enforces the redaction the Disclosure Board approved, and records what was released and when.

  • Redaction applied at the boundary, not by the requester
  • Every release recorded, dated and attributable
  • End-to-end encrypted partner channels
  • Publication is append-only; withdrawal is itself a record

Architecture & failure modes →

Security posture

Ordinary practice, applied consistently

We make no claim to unbreakable systems and we do not use the phrase “military-grade”, which means nothing. What we do is unremarkable and we do it everywhere.

Zero trust between sites

Being inside the fabric confers no authority. Every request is authenticated on its own merits, because a third of the estate is routinely outside.

End-to-end encryption

Partner channels and Archive publication both pass through Nexus. Metadata exposure is treated as part of the threat model, not an afterthought.

Cryptographic integrity

Records are content-addressed and audited continuously per site. A site that has lost or altered something reports it rather than waiting to be asked.

Hardware security

Key material for long-lived deployed instruments is held in hardware, with threshold custody so no single person can act alone.

Open standards

We prefer specified, analysable protocols over proprietary ones. Where we design our own construction we publish it for review before relying on it.

Responsible disclosure

A published timeline, a named contact, and a commitment not to sell findings. Good-faith reporters are not pursued.

Reporting a vulnerability →