One Security Platform for Cameras, Doors, Alarms, and Sensors
Replace Verkada ($15K+/year hardware lock-in), Avigilon ($8K+/year Command Station), and Genetec ($20K+/year) with a single, open, cloud-native security OS. ONVIF camera discovery, Wiegand / OSDP / BACnet access control, AI threat detection across 10 categories, alarm panel integration with existing DSC / Honeywell / Bosch panels, 8 environmental sensor types, edge GPU inference for HIPAA / GDPR sites, central station dispatch in SIA-DC09 / Contact ID, NVR recording to your own bucket, immutable audit trail. $129/month flat — unlimited users, everything included, no hardware lock-in.
Real Security Coverage — From Lobby to Loading Dock
ONVIF/RTSP Devices
Point Sentinel at your existing cameras — no forklift replacement. Register ONVIF/RTSP + USB guard-station cameras and the device registry surfaces which are known and which are online right now (full subnet WS-Discovery via a discovery adapter is on the roadmap)
Alarm Panels
Partition management with Away/Stay/Night arm modes, configurable entry/exit delays, chime mode, and panic — the same controls your existing panel offers, now visible and controllable from the same screen as your cameras
Access Control
Badge/RFID/NFC/biometric readers, door schedules, anti-passback (can't badge back in without badging out first), and mantrap interlocks — so a stolen badge or a tailgating attempt gets caught by policy, not by luck
AI Threat Detection
Object recognition (person/vehicle/weapon/package), behavior analysis, and anomaly detection turn hours of raw footage into the handful of moments an operator actually needs to see
NVR Recording
Continuous/motion/scheduled recording with HLS transcoding for instant browser playback, retention policies, and legal hold — so footage is there when you need it and gone (or preserved) exactly as your policy dictates
Environmental Monitoring
8 sensor types — temperature, flood, CO, glass-break, vibration, beam, pressure-mat, motion — catch the incidents a camera alone would miss, like a server-room temperature spike at 3 AM
Real-Time NOC
Sub-second updates via WebSocket push (vs the 5–30s polling most VMS platforms settle for) means an operator sees an event essentially the moment it happens, not after a lag long enough for someone to walk away
Incident War Room
Every clip, note, and access-log entry attaches to an immutable evidence chain with a full timeline — so when an incident goes to HR, insurance, or law enforcement, the record can't be disputed or quietly edited
Visitor Management
Pre-registration, NDA capture, photo badge, and host notification via CRM turn "who is this person and why are they here" into a 15-second check-in instead of a sign-in clipboard nobody reads
Zone Automation
Occupancy-based triggers move a PTZ camera, lock a door, or arm a partition automatically — with hysteresis protection so a zone never gets stuck mid-action because a sensor blipped
Central Station
UL-listed monitoring integration over SIA-DC09 / Contact ID routes confirmed alarms to fire / police / medical dispatch automatically — the same protocols your existing monitoring contract already expects
Bridge Integration
GPU-accelerated AI runs at the edge (not in the cloud), talks to serial alarm panels (DSC/Honeywell), and reads Wiegand / RFID readers directly — so sites that can't send footage off-premises still get the full feature set
What's in the Box
Device registry
register ONVIF/RTSP + USB guard-station cameras; surfaces known + online devices (full subnet WS-Discovery on roadmap)
Environmental monitoring
8 sensor types with threshold rules and dispatch
Alarm panels
partitions, arm modes, entry/exit delays, sensor bypass, panic types
AI threat detection
object, behavior, anomaly scoring with threat levels
Access control
door / gate / turnstile / elevator / mantrap with lockdown cascade
NVR retention
policies, legal hold, S3 / R2 / MinIO / local with garbage collection
Central station
SIA-DC09 / Contact ID / Ademco transports, UL-listed dispatch
Zone automation
occupancy triggers, PTZ presets, auto-revert hysteresis
Compliance
SOC2 / ISO 27001 / GDPR evidence with immutable audit trail
Smart Search
AI-powered query across camera feeds and access logs
Visitor management
pre-registration, NDA capture, badge printing, host notification
Real-time NOC
sub-second updates via WebSocket push to browser + mobile
Firmware management
pluggable Axis/Hikvision/Hanwha/Dahua/Bosch adapter framework (vendor push protocols in progress)
Mobile app
security operators get push notifications and live feeds on iOS / Android
`sentinel_devices`
ONVIF/RTSP config, streams, PTZ capabilities, firmware
`sentinel_access_points`
Door configs, controller protocol, schedules, anti-passback
`sentinel_alarm_partitions`
Partition config, arm modes, sensor assignments, delays
`sentinel_smart_searches`
Saved video clip definitions
`sentinel_central_station_configs`
UL monitoring account credentials
`sentinel_recordings`
NVR clip metadata, storage URIs, motion windows
`sentinel_incidents`
War room records, evidence chain, severity tracking
`sentinel_ai_threat_logs`
Detection events, confidence scores, bounding boxes
`sentinel_anomaly_detections`
Anomaly scores, baselines, deviation percentages
The Verkada Problem — $15K/Year for Hardware Lock-In
Your current spend with Verkada: → 50 cameras × $800/camera = $40,000 (hardware) → Cloud licenses: $20/camera/month = $1,000/month = $12,000/year → NVR storage: $500/month → Annual cost: $52,500/year
What you get: → Verkada-only cameras (no mixing vendors) → Monthly subscription that never ends → Your footage in THEIR cloud → $5,000/year for AI features → Can't export to standard formats → Locked into their proprietary ecosystem
Every year you stay: $52,5005 years: $262,50010 years: $525,000```
**Sentinel cost:**
```50 cameras (your existing ONVIF hardware): → $0 hardware (reuse what you have)
Sentinel: $129/month flat — everything included, unlimited users → ONVIF/RTSP management → Access control → NVR recording → Zone management → Event detection → Incident management → Visitor management → Compliance policies → Forensic playback → AI threat detection → Behavior analysis → Anomaly detection → Personnel tracking → Compliance dashboards
Annual cost: $1,548/year
Savings vs Verkada: $50,952/year10-year savings: $509,520+Alarm Panels — Replace Your DSC PowerSeries
Every Sentinel alarm partition tracks:
- Identity & status — a name (e.g. "Building A – Floors 1-3"), current status, and arm mode (away / stay / night / disarmed)
- Zone & sensor grouping — the security zones and individual door / window / motion sensors assigned to the partition
- Timing — entry delay (time to disarm after entering), exit delay (time to exit after arming), and siren duration, all configurable per partition
- Chime mode — an audible beep on sensor trip, with quiet hours to suppress it overnight
- Auto-arming — a schedule that arms and disarms automatically on the days and times you choose
Arm modes: away (full perimeter + interior), stay (perimeter only, interior motion bypassed), night (perimeter + selected interior sensors), disarmed. Partition status also tracks the arming / entry-delay countdown, active alarm, and tamper (cover removed or wiring fault) states.
Sensor types: door/window contact, motion (PIR / dual-tech), glass break, smoke, carbon monoxide, flood, temperature, vibration, photoelectric beam, and pressure mat.
What you get:
``` Traditional DSC PowerSeries: → Proprietary keypad (~$200) → Monthly monitoring: $30-50/month → No remote control → No video integration
Sentinel Alarm Panel (via Bridge): → Works with existing DSC/Honeywell panels → OR replaces them entirely (IP-based) → $0 additional hardware (integrates via Bridge serial) → Remote arm/disarm from mobile → Central station dispatch → Triggers camera recording on alarm → Cross-module: dispatches helpdesk ticket ```
AI Threat Detection — Object + Behavior + Anomaly
The detection space Sentinel covers:
Detection types: person, vehicle, weapon and package detection (Enterprise), animal detection, face detection (Enterprise), and license plate recognition (Enterprise).
Anomaly types: behavior (loitering, running, wrong-direction), occupancy (zone under- or over-capacity), motion pattern (unusual movement paths), access pattern (unusual badge activity), and time anomalies (activity outside normal hours).
Threat levels: low, guarded, elevated, high, severe. Sentinel aggregates multiple signals into a single threat level per event, with every contributing factor surfaced to the operator in plain language (e.g. "person detected after hours," "badge denied") rather than a raw score.
Anomaly results compare live activity against a learned per-zone baseline — expected value vs. actual, how far it deviated, and which metric was affected (average occupancy, access attempts, etc.) — and carry a status you can acknowledge, investigate, or resolve.
Watchlists let you flag a person or vehicle — by reference photo or license plate — for continuous matching against live camera feeds, useful for tracking a terminated employee or a vehicle that shouldn't be back on site. Matches are reviewer-confirmed (true/false positive) to keep the model improving over time.
Behavior analysis examples:
``` Loitering Detection: → Person lingers in a zone past a configurable dwell-time threshold without moving on → Severity: medium → high, escalating the longer it continues → Action: Create AI threat log, notify operators
Tailgating Detection: → One badge swipe, two people entering → Triggered by: door held open, or motion after door closes → Severity: high (security policy violation) → Action: Alert, create incident, log access violation
Wrong Direction: → Person walking against normal traffic flow → Emergency exit triggered at wrong time → Severity: critical → Action: Immediate alert, lock zone
Occupancy Anomaly: → Zone normally has 10-15 people (baseline) → Suddenly 0 people (overnight) → fire evacuation? → Deviation: 100% below baseline → Severity: high → Action: Alert facilities manager ```
Bridge Integration — GPU AI, Serial Panels, Wiegand
Bridge brings hardware-side capabilities to Sentinel. When Bridge discovers a device on your network, it captures the device name, manufacturer, model, and firmware version; the IP address and protocol (ONVIF, RTSP, UPnP, or USB); every available stream with its quality profile, resolution, frame rate, and codec; PTZ capabilities (continuous pan/tilt/zoom, absolute or relative positioning, and number of stored presets); and whether the camera supports audio.
You can run a standard ONVIF scan, a full network sweep, or a targeted RTSP probe — scoped to a subnet range, with a configurable timeout and support for custom RTSP paths on cameras that don't announce themselves cleanly.
What Bridge enables:
``` Without Bridge (browser-only): → ONVIF camera discovery on local subnet → View RTSP streams via HLS transcoding → Basic event detection → Access control commands
With Bridge ($0 — included): → GPU-accelerated AI detection (NVIDIA CUDA) → Face recognition, license plate recognition → Local NVR recording (FFmpeg pipeline → local disk) → Serial alarm panel (DSC PowerSeries, Honeywell Vista) → Wiegand/RFID reader (direct USB, no controller) → Multi-camera sync for playback → Hardware PTZ joystick support
Bridge connection: → Outbound WebSocket only (no inbound ports) → Auto-discovery on local network → Scope-based API key auth → $0 API fees (local network) ```
Incident War Room — Immutable Evidence Chain
What an incident record looks like:
Every incident carries a title (e.g. "Unauthorized access attempt — Loading Dock"), a severity (low / medium / high / critical), and a status (new / in progress / resolved / closed).
Evidence chain (immutable — once attached, nothing can be edited or deleted):
- Video clips, linked to the exact recording and time range, stamped with who attached them and when
- Snapshots captured from the live feed
- Notes from guards and officers on scene
- Linked access-log entries (credential, door, and result)
Timeline (built automatically from the evidence as it arrives):
22:14:00 — Motion detected, loading dock
22:14:03 — AI flags a person in frame
22:14:05 — Badge denied at the loading dock door
22:14:12 — Tailgating pattern detected
22:15:00 — Incident created automatically
22:15:30 — Assigned to the on-shift guard
22:16:00 — Loading dock zone locked down
Every incident can automatically open a linked Helpdesk ticket.
Cross-module synergy:
Alarm fires at 10:14 PM
↓
Sentinel creates Incident (immutable)
↓
Cross-module events:
→ helpdesk: Creates high-priority ticket, assigns to on-call
→ fleet: Broadcasts "facility_lockdown" alert to drivers
→ smart-spaces: Elevator control → restricted floor access
→ notifications: Push + SMS to security director
→ collab: Creates #security-incident channel, invites responders
↓
Guards join War Room:
→ Live camera feeds (loading dock, exits)
→ Playback timeline scrubber
→ Attach evidence clips
→ Real-time chat with responders
↓
Resolution:
→ Suspect apprehended by police
→ Incident closed with full evidence export
→ Compliance audit trail: 7 years retention
Zone Automation — Smart, Hysteresis-Protected Rules
Each automation rule combines:
- A trigger — an occupancy floor and/or ceiling for the zone, optionally required to hold steady for a set duration before firing
- One or more actions — move a camera to a PTZ preset, send a notification, lock or unlock specific access points, start or stop recording on specific devices, or arm/disarm an alarm partition
- A cooldown — the minimum time between repeat firings, so one sustained condition doesn't spam actions
- An optional auto-revert — automatically undoes the action after a delay (hysteresis protection), so a zone never gets stuck in a triggered state
- A priority — higher-priority rules are evaluated first when more than one rule could fire
Example rules:
``` Rule 1: "Lobby After-Hours Camera Preset" trigger: occupancyMax = 0, sustainedForSeconds = 300 (5 min no one) actions: Set PTZ to wide overview preset cooldown: 600 (10 min)
Rule 2: "Parking Garage Occupancy Alert" trigger: occupancyMax = 200 (over capacity) actions: Notify security, log event cooldown: 60
Rule 3: "Server Room Temperature Alert" trigger: temperature > 75°F actions: Alert facilities, trigger HVAC override, log event autoRevert: delaySeconds = 300 (revert after 5 min) cooldown: 300
Rule 4: "Loading Dock — After Hours Auto-Lock" trigger: time = 18:00 (6 PM) actions: Lock all loading dock doors cooldown: 0 autoRevert: enabled, delaySeconds = 0 (no revert — manual unlock only) ```
Frequently Asked Questions
No. If they speak ONVIF or RTSP (>95% of cameras manufactured since ~2015 do), Sentinel discovers and manages them. The Verkada-style hardware lock-in model is what we're explicitly replacing — your investment in Axis, Hikvision, Hanwha, Dahua, Bosch, Avigilon, or any standards-compliant manufacturer transfers over.
Sentinel is the NVR. Continuous, motion-triggered, or scheduled recording with retention policies, legal hold, and HLS transcoding for browser playback. Storage targets your bucket — S3, R2, Backblaze B2, MinIO, or local disk via Bridge. Garbage collection runs on schedule per retention policy.
Sentinel speaks SIA-DC09 and Contact ID — the two protocols UL-listed monitoring centers use to receive alarm events. Pair your account with the monitoring center, configure dispatch rules per partition (fire / police / medical), and confirmed alarms route to dispatch automatically. The monitoring contract you sign with the central station is separate from Aeion; we're the on-prem brain that sends the signal.
Sentinel listens for `executive.crisis.defcon_change` events. DEFCON 2 triggers automatic Vault-camera lockdown (recordings continue but live-view access is restricted to incident responders). DEFCON 1 (Kill Switch) revokes all API tokens — Sentinel devices stop accepting new commands until the kill switch is released. Every transition writes to the same immutable audit trail.
Same detection categories (person, vehicle, weapon, package, license plate, behavior anomalies, occupancy, tailgating). Difference: Sentinel runs the inference locally on Bridge GPU (NVIDIA CUDA) or via the cloud AI module, your choice. For HIPAA / GDPR / military sites that can't send footage to a cloud, edge inference keeps the bytes on-premises. Watchlists are tenant-scoped — no cross-customer face/plate data sharing.
Yes. Bridge's serial integration speaks to the panel's existing keypad bus — you don't replace the panel, you add Sentinel as a parallel controller. Arm / disarm / partition status syncs both ways. Replacing the panel entirely with the Sentinel IP-based partition model is also an option, but most customers keep their existing UL-listed panel and use Sentinel for the brain.
Per-collection retention policies with legal-hold flags. Legal hold pins recordings against retention cleanup until released by an authorized user — the standard "litigation hold" pattern. All access to held recordings logs to the immutable audit trail. 7-year retention is the platform default for incident records; configurable per tenant.
Yes, via Bridge — supports Brother QL-820NWB, Zebra ZD420, and any USB-class label printer. Photo capture from the guard-station camera, badge generation, and host notification (CRM-linked) take ~15 seconds per visitor.