Skip to content

How it works

Sentinel connects three parties: employees' devices running the Klipsu app, your Sentinel server, and your security team and tools.

1. Enrollment

An administrator creates an enrollment code in the console. The employee chooses Work account in the Klipsu app, enters the server address, confirms your organisation and its key fingerprint, and completes the enrollment page with the code and their work email. With MDM, the app enrolls without the browser step.

The device pins the policy signing key at enrollment. From then on it accepts only policies signed with that key, or with a successor key announced in advance.

2. Sync stays end-to-end encrypted

Clipboard history is encrypted on the device with the employee's vault key. The key is derived from a recovery phrase that never leaves their devices. Sentinel stores and relays the ciphertext and cannot read it. That covers text, images and files.

3. Detection on the device

When text is copied, the Klipsu app evaluates the current signed policy locally. For each matching rule it:

  1. masks the match as the rule specifies (for example AKIA••••••••••••7Q2F);
  2. applies the rule's actions: notify the employee, clear the clipboard, or keep the item out of sync;
  3. if the rule asks for evidence, seals the clip to your organisation's evidence key and keeps it on the device for the rule's retention period;
  4. queues a finding and sends it to Sentinel.

Sentinel re-checks that every masked value matches the rule's masking. Values that don't conform are withheld and counted, so a faulty client cannot leak more than the rule allows.

4. Alerts and response

Findings for the same person, device and rule within the grouping window form an alert. Analysts triage alerts in the console, and integrations forward events to your SIEM, webhooks or Slack.

5. Evidence on request

When the masked match is not enough, an investigator can request the sealed evidence for one finding.

The evidence private key is encrypted with a key derived from the evidence passphrase, which Sentinel never stores. A stolen database and server key file are not enough to read evidence.

Next steps

Klipsu Sentinel is a product of Lygon Software · enterprise@klipsu.com