The breach was contained
before anyone woke up.
Sentinel is a 24/7 autonomous cyber response platform. It detects, decides and contains in under 45 seconds, without waiting on an analyst, and records the reasoning behind every action it takes.
Snapshot
HLD Sentinel
Stage
Shipping on production infrastructure
Live in beta
Customers
Across 5 industries
12
Detection coverage
vs fixed-signature baseline, benchmarked
+80%
Containment target
Detection to contained, no analyst
<45s
Live simulation
A cyber attack chain.
Watch Sentinel neutralise it.
Real network topology, a real intrusion chain, and Sentinel's real response logic running on simulated telemetry, so you can see exactly how it behaves before a live incident tests it. Press run and watch it end.
HLD Sentinel · Live simulation
Cyber attack & autonomous defence
20 endpoints · multi-stage intrusion · simulated telemetry
Standby
Awaiting run…
The product
Detect. Decide. Respond.
No approval gate in the middle.
Sentinel is not a faster alerting product. It sits in the control path, which is what lets it act rather than escalate.
Detect
Continuously monitors activity across every connected system in real time, covering external intrusion attempts and internal misuse alike.
Decide
Classifies the threat automatically, with confidence scoring and a recorded reasoning chain, instead of waiting on an analyst to notice and triage it.
Respond
Contains the threat in under 45 seconds, before lateral movement turns one compromised endpoint into an incident.
Response sequence
From first signal
to clean systems.
The full autonomous pipeline, from anomaly to systems back online. Each step is logged with its rationale, and each step is reversible.
Timings are drawn from Sentinel's controlled simulation environment and describe the reference sequence, not a guaranteed per-incident SLA. The published containment target is under 45 seconds end to end.
T+0.0s
Anomaly surfaced
Endpoint telemetry, network flows and identity signals are correlated as one stream. A phish landing on a single endpoint is classified without waiting for a ticket to be opened.
T+0.1s
Threat classified, with the reasoning recorded
The indicator is cross-referenced against live threat intelligence and the blast radius of your own environment. Confidence score, signal sources and the hypotheses ruled out are written to the decision log at the moment the call is made.
T+0.2s
Segmentation pushed to the fabric
Network policy is written and deployed so lateral movement paths collapse before a second host is reached. Every policy change is versioned and reversible.
T+0.3s
Affected endpoints isolated in parallel
Agents act concurrently rather than working a queue. Isolation is a network-policy change, not a wipe, and a single command restores any endpoint once the all-clear is confirmed.
T+0.4s
Sessions terminated, credentials rotated, C2 sinkholed
Active sessions are ended, accounts rotated, and command-and-control traffic redirected to a Sentinel-controlled decoy. Every revocation is logged and reissuable.
<45s
Verified-clean systems back online, report generated
Clean endpoints reconnect and a complete incident report is delivered: not only what happened, but why each decision was made and what was ruled out.
Platform capabilities
Built for the threat you have not seen yet.
Autonomous agent orchestration
Concurrent agents operate independently, with no single point of failure and no human approval loop between detection and containment.
Behavioural baselining
Sentinel maps normal across every user, endpoint and service account, so novel behaviour surfaces without a signature existing for it first.
Dynamic segmentation
Real-time topology awareness keeps containment accurate. When an attacker moves, containment moves with them, automatically and reversibly.
Threat intelligence fusion
Every indicator and technique is cross-referenced against live feeds the moment it is observed, with attribution confidence updated in real time.
Deception fabric
Attacker traffic is redirected to Sentinel-controlled decoy environments while production systems stay untouched and observable.
Decision-record engine
A court-ready timeline and plain-language decision log generated automatically, covering the full MITRE ATT&CK framework.
Evidence
Numbers you can check,
against a method we publish.
Sentinel's performance claims come from a frozen, reproducible benchmark. The corpus, the baseline, the thresholds and the formulas are fixed before execution and published in full, so the result can be recalculated rather than taken on trust.
+0%
Increase in detection coverage
18 of 20 labelled attack scenarios detected, against 10 for the frozen fixed-signature baseline.
(18 − 10) ÷ 10 × 100
0%
Fewer analyst review items
100 related alerts consolidated into 40 incident groups by target and time window.
(100 − 40) ÷ 100 × 100
0%
Fewer manual routing decisions
45 of 100 independent incidents routed automatically after clearing both the risk and confidence thresholds.
(100 − 55) ÷ 100 × 100
Benchmark ID
SB-2026-08-24.1
Corpus
sentinel-controlled-corpus-v1
Last verified
24 August 2026
Internally verified by HLD Group's automated benchmark suite against a frozen synthetic corpus, referencing the Sigma 2.1.0 fixed-signature model, MITRE ATT&CK Enterprise v19 and NIST SP 800-61r3. This measures product coverage on a labelled scenario set, not a production customer detection rate.
Next step
Let's build the standard
for autonomous cyber response.
For security teams
See Sentinel against your own environment.
A briefing walks through the response pipeline, the decision record, and how containment behaves on a network shaped like yours. Beta places are released in small batches so each one gets a proper onboarding.
For investors
We are building toward a seed round.
The round is not open yet. We are having the conversations now, ahead of it, with people who want to understand the category before it is priced. The deck covers the market, the model, the competitive position and where the money goes.
HLD Software Group Pty Ltd. Nothing on this page is an offer of securities or an invitation to subscribe. Forward-looking statements reflect current expectations and are not guarantees of future performance.