Appearance
Release notes
1.0.0 (September 2026)
First release of Klipsu Sentinel.
Server
- Self-hosted Klipsu sync server, compatible with the Klipsu cloud API for sync, media, pairing and device management.
- Enrollment with shared, domain-restricted or personal codes; a browser enrollment page; MDM enrollment.
- Detection policies: 24 built-in detectors, custom regular expressions with validators, keywords, document fingerprints; per-rule masking, actions, scope and evidence settings; signed, versioned policy bundles.
- Findings with server-side mask checks, alert grouping and triage, bulk actions, comments, assignment, live updates.
- Sealed evidence: request, device upload, passphrase-protected opening, cancellation, expiry.
- Integrations: webhooks (HMAC-signed), syslog (RFC 5424 JSON, CEF; UDP, TCP, TLS), Slack, with retries and delivery history.
- Administration: four roles, two-factor authentication (optionally required), pseudonymisation for analysts, retention and endpoint settings, key rotation (policy signing, evidence, key-encryption key), offline licensing, a hash-chained audit log with verification and CSV export.
- Operations: single static binary for Linux x86-64 and ARM64 and for Windows x86-64 (native Windows service), embedded console and database migrations, PostgreSQL 14+, horizontal scaling, health endpoints, structured logs.
Known limitations
- Klipsu apps: devices connect through the Klipsu apps' enterprise mode, which is being rolled out separately for macOS, Windows, Linux, iOS and Android. Contact Lygon Software for availability on your platforms before planning a rollout. Until then you can evaluate the server and console with the built-in demo (
sentinel demo seedandsentinel demo runwithdev: trueon a test machine). - Detection covers text; images and files are synced encrypted but not scanned.
- Single sign-on (OIDC/SAML) for the console is planned; v1 uses local accounts with two-factor authentication.
- The console is available in English.