You should not have to trust us. Here is how you verify us.
A monitoring and coding agent sees your most sensitive stream, your source and your telemetry, all day. So the design starts from one rule: that stream stays on your side of the wall, and you can prove it.
Nothing leaves the machine unless you route it out.
By default Surrogate runs entirely on the model you host. The only way anything reaches the outside is through a gate you configure and audit. Unplug the network and the agent keeps working.
What that means in practice.
On-prem, VPC, or air-gapped
The weights run on your GPU, on hardware you control. There is no default path from your code to a network you do not own.
Auditable by design
Every request that would leave the machine passes one gate. It reaches only providers that will not train on your data, and it records what left. You can turn it off and run fully offline.
Deployed into your account
When you want Sentinel run for you, it deploys into your own cloud account. The control plane sees health and metadata. Your code and its inference stay in your account.
No badges yet, and we will say so
We do not hold SOC 2 or ISO certification yet. We are pre-seed and we would rather be honest than paint a badge row. Instead we offer a technical walkthrough and an architecture review, which is what a regulated buyer should want to see anyway.
Teams locked out of cloud agents
Finance, government, healthcare, and critical infrastructure, where policy forbids source and telemetry from leaving the perimeter.
Bring us your environment and its rules.
We will walk you through exactly what runs where, what the gate allows, and how to audit it. Run it disconnected and watch.