SELINA LABS
SURFACE 02ANNOUNCED / RUNNING IN PRODUCTION LIVE

Sentinel

A security layer built for AI systems rather than adapted to them. Sentinel holds the perimeter of a deployed model application, intercepts hostile input in the request path, and contains abuse before it compounds. Currently hardening Selina.ai. Spinning out as a standalone product.

SHE NARRATES THIS SURFACE
PERIMETER ENFORCEMENTACTIVE
INJECTION HEURISTICSLOADED
CONTAINMENT PATHAUTOMATED
PRIVATE CONTENT READNONE
STRATUM 00THREAT SURFACE ACTIVE

Every AI application inherits an attack surface nobody designed for.

Web application firewalls understand requests. They do not understand instructions. A model wrapper accepts natural language as executable intent, which collapses the distinction between the payload and the prose carrying it. Signature matching cannot see that, because there is no malformed byte sequence to catch. Rate limiting cannot stop it, because a single well-formed message is enough.

The failure mode is not a crash. It is an application that continues to behave correctly by every operational metric while doing something its operator never authorized. Uptime stays green. Latency stays flat. The system is compromised and the dashboard says nominal.

Sentinel treats the prompt boundary as the actual security boundary. It models what normal interaction looks like for a given application, flags deviation probabilistically rather than by signature, and contains the session before a successful technique can be repeated at scale.

PERIMETER SWEEP

Contacts illuminate as the sweep resolves them. Illustrative.

STRATUM 01ENFORCEMENT FEED ACTIVE
INTERCEPT LOGSYNTHETIC

REQUEST CLASSIFICATION

Traffic scored continuously against a learned envelope. Height is deviation, not volume. Sustained excursion escalates to containment.

STRATUM 02CAPABILITY MATRIX ACTIVE

01

Injection interception

Instruction-override attempts are identified in the request path and neutralized before they reach the reasoning layer. The payload never becomes an instruction.

02

Jailbreak resistance

Continuous adversarial evaluation against identity hijack, role subversion and gradual constraint erosion across every model the application can route to.

03

Behavioral baselining

Probabilistic models of normal traffic make novel attacks legible as deviation, which means detection does not require a prior signature for the technique.

04

Automated containment

Detection triggers isolation without waiting for a human in the loop. Blast radius is bounded in minutes rather than discovered in a quarterly audit.

05

Content blindness

The guard watches the door, never the room. Enforcement runs on metadata, timing and behavioral signal rather than the substance of private conversation.

06

Wrapper-native design

Purpose-built for model applications rather than retrofitted from web firewalls that have no representation of a prompt as an executable object.

07

Multi-model coverage

Defense travels with the application, not the provider. Routing across vendors does not open a gap in the perimeter or reset the threat baseline.

08

Enumeration defense

Systematic probing for capability boundaries, hidden instructions or credential structure is recognized as a campaign rather than a series of odd requests.

09

Telemetry surface

Every enforcement decision is observable and attributable, so posture can be reasoned about instead of assumed.

9 CONTROLSMODEL AGNOSTICMETADATA ONLYAUTOMATED CONTAINMENT
STRATUM 03THREAT MODEL ACTIVE

What we assume the attacker already has.

01FULL API ACCESSThe adversary can send arbitrary well-formed requests at will, with no malformed input required.
02KNOWLEDGE OF THE STACKThey know which providers are behind the application and how wrappers of this class typically fail.
03PATIENCEAttacks arrive as gradual constraint erosion across many turns rather than a single obvious payload.
04AUTOMATIONProbing is scripted, distributed across origins and tuned by feedback from prior attempts.
05NOVEL TECHNIQUEThe specific method may not exist in any signature database at the time it is used.
06NO INSIDER ACCESSThe one thing we do not concede. Key isolation and content blindness hold even under successful perimeter probing.
STRATUM 04POSTURE ACTIVE
01DEPLOYMENTSits in front of the application boundary. Requires no access to plaintext user content.
02DETECTIONBehavioral and probabilistic. Adversarial patterns surface as deviation from a learned baseline.
03RESPONSEAutomated containment on detection, with escalation bounded in minutes rather than audit cycles.
04SCOPEInjection, jailbreak, impersonation, credential probing, enumeration and coordinated abuse.
05PRIVACYOperates on metadata and traffic behavior. Private conversation content is out of scope by construction.
06OBSERVABILITYEvery enforcement decision is logged and attributable without exposing what the user actually wrote.
07STATUSRunning in production against Selina.ai. Standalone release announced with no date committed.
STRATUM 05DOMAIN ACTIVE
/ prompt injection defense/ jailbreak resistance/ identity hijack prevention/ instruction override detection/ behavioral baselining/ anomaly detection/ abuse containment/ rate shaping/ credential probing detection/ enumeration defense/ adversarial evaluation/ red team automation/ perimeter telemetry/ metadata-only monitoring/ cross-provider coverage

AVAILABILITY

Sentinel is announced without a release date. If you operate an AI application and want to be told when it opens, open a channel.

MEET SELINA