Sentinel-Ops by YadriWorks - Runtime AI Governance Engine
Yadriworks Inc · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
## Prevent Unauthorized AI Actions Before They Execute
Sentinel-Ops is the governance layer for AI-enabled applications in production. It intercepts every tool call, API request, and LLM interaction your application makes and enforces a declarative Safe Operating Envelope (SOE) policy - without modifying your application code.
Show the rest of the publisher’s description (31 more lines)
**The Problem:** Organizations deploying autonomous AI agents, RAG pipelines, and LLM-powered services face a critical gap - these systems can access unauthorized data, execute destructive commands, or drift beyond their intended scope with no deterministic control plane in place. Security and compliance teams need enforceable guardrails, not just monitoring.
## Three Constraints, One Policy File
- **Identity** - Define what role the application can claim, what authority it has, and which environments it can operate in.
- **Data Access** - Control which files and paths the application can read and write using glob patterns. Deny access to credentials, PII, and production data.
- **Tool Actions** - Specify which commands, tools, and API calls the application can execute using glob and regex patterns. Block destructive operations like rm -rf, DROP TABLE, or unauthorized API calls.
## Example Use Case
A financial services team running 20 autonomous coding agents needs to ensure no agent can access production credentials, customer PII, or execute database mutations outside a sandbox. With Sentinel-Ops, a single .soe.json policy file enforces these boundaries deterministically across all agents - every violation is denied and logged with full audit context for compliance review.
## How It Works
- Define your governance policy in a .soe.json file
- Deploy Sentinel-Ops via CloudFormation (5 minutes)
- Point your AI application through the SOE API or transparent sidecar proxy
- Every tool call is evaluated: ALLOW, DENY, or ESCALATE
## Key Capabilities
**Deterministic Enforcement:** 95% of decisions are made via regex/glob matching in under 1ms. No LLM in the critical path. Zero hallucination risk. Fail-closed - unknown actions are denied by default.
**AI-Assisted Classification:** For the 5% of ambiguous cases, Sentinel AI uses your LLM provider (Groq or Anthropic) to reason about intent. You provide the API key and control this entirely.
**Cumulative Risk Scoring:** Arbiter tracks risk across sessions. An application that makes 50 borderline calls gets progressively restricted - even if each individual call is allowed.
**Cross-Application Anomaly Detection:** Beacon monitors patterns across all governed applications. Detects coordinated attacks, unusual trajectories, and behavioral anomalies.
**Immutable Audit Trail:** Every decision is logged to an append-only event store with SHA-256 hash chain. Export compliance reports in OSCAL and STIX formats. Route events to Amazon EventBridge for your existing alerting stack.
**Content Guardrails:** Built-in PII detection (SSN, credit card, phone, email), prompt injection defense, and content safety scanning.
**Real-Time Dashboard:** Live view of allows, denies, risk budgets, and application activity.
## Governs Any AI-Enabled Application
Autonomous agents (Claude Code, LangGraph, CrewAI, AutoGen), multi-agent systems, RAG pipelines, chatbots, LLM-powered microservices, and any HTTP-based AI workload.
Two integration modes - zero code changes required:
- **Sidecar proxy** - transparent network-level interception
- **REST API** - direct /v1/evaluate calls from any framework
## Architecture and Data Privacy
Your data never leaves your AWS account. Sentinel-Ops runs entirely within your infrastructure as an ECS Fargate service. The only data transmitted externally is aggregate usage counts to AWS Marketplace for billing. No telemetry, no phone-home, no data collection by YadriWorks Inc.
## Deployment
CloudFormation creates all required resources: ECS Cluster, Task Definition, Application Load Balancer, WAF, Security Groups, DynamoDB, S3, CloudWatch Logs, Secrets Manager, and IAM roles (least privilege). Multi-AZ high availability with auto-scaling included.
## Get Started
Review pricing dimensions on the Pricing tab, then deploy via CloudFormation in minutes. For a guided deployment walkthrough or to request a sample SOE policy tailored to your AI stack, contact the YadriWorks team. Visit https://yadriworks.ai/docs for full documentation and policy examples.
Highlights
Highlighted by the publisher on AWS Marketplace.
Sub-millisecond deterministic enforcement with zero hallucination risk. 95% of policy decisions resolve via glob and regex matching in under 1ms with no LLM in the critical path. Fail-closed by default - any action not explicitly permitted is denied. A single .soe.json policy file governs identity claims, data access paths, and tool-call permissions across all your AI applications including autonomous agents, RAG pipelines, chatbots, and LLM microservices.
Immutable compliance audit trail with OSCAL and STIX export. Every allow, deny, and escalation decision is cryptographically logged to an append-only event store with SHA-256 hash chain verification. Route real-time governance events to Amazon EventBridge for integration with your existing SIEM and incident response workflows. Cross-application anomaly detection via Beacon identifies coordinated threats and suspicious behavioral patterns.
Deploy in 5 minutes with zero code changes to your AI applications. Transparent sidecar proxy intercepts tool calls at the network level - no SDK integration, no code modifications, no vendor lock-in. Works with Claude Code, LangChain, CrewAI, AutoGen, and any HTTP-based AI workload. CloudFormation provisions all AWS resources with least-privilege IAM. Your data never leaves your AWS account - no telemetry, no phone-home, no external data collection by YadriWorks.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Plans and pricing as listed
10 listed- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
Refund terms
As stated by the publisher on AWS Marketplace.
30-day money-back guarantee. Contact support@yadriworks.ai within 30 days of subscription for a full refund. After 30 days, subscriptions are non-refundable for the remainder of the contract term.
Sources
Linked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

