The cross-cutting layer that makes AI deployment responsible. Define policy once — Sentry enforces it everywhere, from the models you ingest to the agents that act on your behalf.
Security and compliance can't be bolted onto one layer and called done.
Sentry runs through all of them — one policy layer, enforced end to end.
Bud Sentry is the security and compliance layer of the Bud ecosystem — and it is deliberately cross-cutting. The policies and settings you define here apply to every other layer: model training, ingestion, inference, and the agent layer above them.
Responsible AI deployment comes down to two questions: is it secure, and can you prove it was compliant. Sentry is built to answer both — at runtime, on every request, with an evidence trail behind each decision.
Set a rule once and it holds wherever AI touches your business — the model being ingested, the request being served, the agent calling a tool. No per-layer reimplementation, no gaps between them.
Cross-cutting by designMost stacks treat them separately — scanners on one side, policy documents on the other. Sentry unifies both under one layer, because an unsafe model and an unlawful decision are the same class of deployment risk.
Secure & compliantControls act where the risk actually occurs — on the input, on the output, and at the tool boundary — blocking, redacting, or routing to a human before an action is taken, not after.
Runtime, not paperworkEvery decision is recorded as an audit span. That's the difference between claiming you have controls and showing an auditor each decision and why it was made.
ProvableAgentic AI moves enterprises from systems that answer to systems that act — calling tools, writing records, making consequential decisions. That shift turns governance into a runtime control problem, exactly as regulators are making it mandatory.
EU AI Act bans on prohibited practices already apply, and high-risk duties — risk management, logging, human oversight — phase in across 2026–2027. Deploying without controls is a measurable liability.
Unlike chatbots, agents call tools, write data, and make decisions. Prompt injection and goal hijack become operational threats — an over-trusted agent can leak data or fire an unsafe action on its own.
Regulators, SOC 2 and ISO auditors, and enterprise procurement now demand evidence of controls. A decision-level audit trail is what separates asserting compliance from proving it.
PII, PHI, and secrets routinely escape through prompts and responses, each exposure carrying regulatory penalties and breach-notification cost. Redaction at the boundary is table stakes.
A multinational must satisfy the EU, a patchwork of US state rules, and APAC laws at once — a target that keeps moving. Adaptable runtime controls beat point solutions hardcoded to one law.
It is no longer whether to govern AI, but whether you can prove you did — to an auditor, to a regulator, and to the customer whose data or decision was involved.
Each pillar guards a different point in the lifecycle — what enters your environment, what flows through it, and what your agents do with it.
A zero-trust ingestion lifecycle. Every model is verified, contained, and continuously monitored before it is allowed anywhere near production.
Layer — Model ingestionRuntime guardrails on every request — 23 specialised models across security, safety, toxicity, compliance, and quality. Runs on commodity CPUs.
Layer — Inference & runtime Explore Bud SentinelRuntime governance for agentic systems — eight regulation-mapped policy packs that block, redact, and route at the moment of risk, recording every decision.
Layer — Agents & tool callsPull a model from Hugging Face or any third-party source and you're not just downloading weights — you could be importing executable scripts, obfuscated binaries, or embedded malware. Sentry treats every model as untrusted until proven otherwise.
Malicious PyTorch models have been found embedding reverse-shell backdoors that trigger on load, enabling full system compromise.
Parameters subtly modified to exhibit backdoor behaviour — responding to secret inputs or leaking information during inference. Hard to detect in large models.
Even “safe” formats aren't immune — tainted metadata can inject misleading info, and loader-library vulnerabilities can be exploited for code execution.
Specially formatted files that trigger arbitrary code execution or sandbox escapes through vulnerabilities in model-loading libraries.
Embedded scripts that open outbound connections to attacker-controlled servers, enabling remote access and data exfiltration from inside your infrastructure.
Compiled executables and obfuscated binaries packaged alongside weights that bypass traditional scanners and execute during setup.
Sentinel is the enforcement engine on the inference path — 23 specialised models across 33 variants, inspecting input and output. Built on Resource Aware Attention, it runs on the commodity CPUs you already have.
Every other system trades one failure mode for the other — blocking attacks but refusing legitimate users, or keeping refusals low while letting attacks through. Sentinel leads on both: a 15.97% attack success rate at a 14.92% false refusal rate. Benchmarked across JailBreakBench, PIGuard, WildJailbreak and Qualifire PI.
AgentMesh wraps live AI agents with eight pre-built governance policies that inspect every input, output, and tool call — then deny, redact, or route to a human, recording each decision as an OpenTelemetry audit span.
Controls sit exactly where the risk is. Every input, every output, and every tool call passes the policy engine before anything irreversible happens.
Not a blank policy engine you have to author from scratch. Eight packs ship ready, each traced to the regulation it satisfies.
Blocks illegal content; routes toxicity, violence, and self-harm to review.
Redacts PII/PHI and secrets/credentials in both request and response.
Blocks jailbreak and agent goal-hijack on input, before the agent acts.
Bias monitoring, a human gate on consequential decisions, and synthetic-media controls.
Each verdict is recorded as an OpenTelemetry span — what was inspected, what was decided, and which rule decided it. Compliance stops being a claim and becomes a query.
The difference between “we have guardrails” and “we can show you every decision, and why.”
One deployment, many shifting regimes — mapped to the frameworks your auditors actually cite.
The same eleven regions Bud Sentinel's compliance models detect — the guardrail engine and the governance layer share one map.
Regulated-advice routing and disclaimers; payment-card (PCI-DSS) redaction.
Bias monitoring and decision oversight aligned to NAIC model conduct.
PHI redaction under HIPAA; medical-advice oversight with a human gate.
Legal-advice routing with human review and disclaimer.
Bias signal plus a human gate on consequential decisions — EEOC, NYC LL144, and state ADMT laws.
Text-level child-safety duties; AI-disclosure for synthetic media.
Public sector & law enforcement — Article 5 backstops on social scoring and criminal-risk profiling. The cross-cutting packs apply to any enterprise deploying agentic AI.
It isn't a product that sits beside the stack — it's the layer the rest of the stack inherits from.
Secure what you ingest, guardrail what you serve, govern what your agents do — and keep the evidence to prove all three.