Requirements
System requirements
What you need to prepare depends on the deployment option and the scale you manage.
Deployment options
All three options run on the same platform, analysis engine, and audit framework — nothing differs between them.
Private Cloud
Customer's cloud
- Infrastructure to prepare
- Cloud account and permissions
- Where it is installed
- Customer's cloud account
- Where data resides
- Customer's cloud
- Who operates it
- Customer (with our support)
- AI execution
- Choice of cloud API, BYOK, or air-gapped GPU
On-Premise
Air-gapped deployment
- Infrastructure to prepare
- Your own servers and storage
- Where it is installed
- Customer's data center
- Where data resides
- Customer's data center
- Who operates it
- Customer (with our support)
- AI execution
- Air-gapped GPU (no external communication) · by consultation
Hybrid
Combined to fit the environment
- Infrastructure to prepare
- As agreed
- Where it is installed
- Split by layer
- Where data resides
- Only the layers the customer chooses
- Who operates it
- Divided as agreed
- AI execution
- Choice of cloud API, BYOK, or air-gapped GPU
On-premise server layout
Based on an on-premise deployment of the security platform, sized for a single tenant with 10,000 endpoints.
| Role | Nodes | Spec |
|---|---|---|
| Kubernetes convergedCollection · normalization (OCSF) · storage · LLM gateway | 3 | 16 vCPU · 64GB · SSD 2TB |
| Application serverAnalysis engine · tickets · approvals · threat intel · console · auth · DB | 1 | 8 vCPU · 32GB · SSD 500GB |
- This assumes the full product is deployed.
- Final specifications are confirmed after a site survey and performance validation.
AI execution
Every AI call passes through a single gateway.
Cloud API
Standard in productionThe gateway calls an external LLM API. No GPU required.
Prepare: Outbound 443 allowed
Bring your own key (BYOK)
By consultationYou register the LLM key from your own contract with the gateway.
Prepare: LLM contract and key in the customer's name
Air-gapped GPU
By consultationAn open model runs on a GPU server and inference stays internal. No external communication.
Prepare: GPU server and an offline delivery procedure
Integrations
What you need to prepare is API access for each product. Your existing vendor contracts stay as they are.
Based on 49 registered vendors and 43 supplied; for products not on the list we will confirm whether integration is possible.
Palo Alto, SentinelOne, Trellix, Cisco, CrowdStrike, and others
Sizing unit · endpoints
Okta, Microsoft Entra ID, Google Workspace, Cisco Duo, and others
Sizing unit · users
Palo Alto, Cisco, Fortinet, Check Point, and others
Sizing unit · devices
Red Canary, Arctic Wolf, Secureworks, and others (bidirectional)
Sizing unit · users
AWS CloudTrail, Azure Monitor, GCP Security Command Center, and others
Sizing unit · cloud accounts
Palo Alto Prisma, Cisco Umbrella, Zscaler, and others
Sizing unit · users
CVE-based vulnerability data integration
Recorded Future, MISP, Anomali, VirusTotal, and others
Frequently asked questions
- Can we use it alongside our existing SIEM?
- Yes. Sentivex is an analysis and response layer that sits on top of your detection stack, so it collects and normalizes alerts without replacing your existing SIEM or EDR.
- Where is our data stored?
- It depends on the deployment option. Private Cloud stores data isolated per tenant; with On-Premise the entire stack is installed inside the customer's data center and nothing leaves it.
- What happens to our existing vendor contracts?
- They stay as they are. Collection, analysis, and regular reporting continue uninterrupted even while you transition off a vendor or a contract expires.
- Can it run on an air-gapped network?
- Yes. Sources that require outbound calls, such as cloud EDR APIs, need to switch to an on-premise manager or be relayed through a DMZ, and threat intel and model updates are brought in offline.
Tell us your environment and we'll put a configuration together
Tell us the security products you use and the scale you manage, and we will come back with an infrastructure plan per deployment option and an expected timeline.