ShadowPine Sentinel™

Your network,
finally clear.

AI-assisted monitoring, troubleshooting, and documentation — on one appliance you run in your own environment.

14-day free assessment Money-back guarantee Runs in your environment
sentinel.local
ShadowPine Sentinel dashboard — device reachability, active incidents, and assessment readiness in one view
What Sentinel sees

One appliance. Your whole network.

Discovery, incidents, and deep telemetry — gathered locally and presented in plain language.

Automatic discovery

Every device and link, mapped for you.

Read-only SNMP with LLDP/CDP neighbor discovery builds a live map of what's actually connected — with a confidence level on every link.

NODES5
LINKS4
LLDP4
CDP0
UNKNOWN3
Network mapHigh confidenceLow / observed
SP-DEMO-SW01 SP-DEMO-SW02 Office FW-DEMO-1.demo.local
Real-time incidents

Know before your users do.

Each incident is prioritized and backed by evidence.

P2 · URGENT
Interface internal down on FW-DEMO-1.demo.local
P2warningopen10:23 PM
Interface lan1 down on FW-DEMO-1.demo.local
P2warningopen10:23 PM
Interface Gi0/12 down on SP-DEMO-SW01
P2warningacknowledged5:23 PM
Deep telemetry

Drill into any interface.

Bandwidth and errors, over time.

Interface detail · wan1 Gbps
Utilization (%)
InboundOutbound
Throughput
InboundOutbound
Evidence-bound AI

Ask in plain English.
Get an answer you can trust.

Tune answers to the audience — executive, customer, or engineer — for the right level of detail every time. Every answer stays bound to the evidence Sentinel actually collected.

sentinel.local — assistant
Sentinel is checking the evidence
Sentinel AI

Port Gi1/0/12 on SP-DEMO-SW01 dropped into err-disabled at 22:14 after a port-security violation — two MAC addresses appeared on a port locked to one. That port is the tagged uplink to AP-BLDG2-N, so the access point and the Building 2 SSIDs went down with it. This is a switch-side lockout, not an AP or RF problem.

Recommended fix — clear the violation and bounce the port: shutdownno shutdown on Gi1/0/12, then confirm AP-BLDG2-N re-associates and the SSIDs return.
SNMP · interface-oper-down · Gi1/0/12 port-security · psecure-violation
Runs your way — connect your own local MCP server, bring your own LLM key, or use the built-in ShadowPine key.
Built for teams like yours

Enterprise visibility.
Without the enterprise price tag.

For organizations that run important networks and want clear, dependable visibility — at a footprint that fits your team.

Local government

Counties and city offices that keep essential services online. One clear, always-current picture of the whole network.

Schools & districts

Networks that simply need to work — for students, teachers, and admin. Documented, with issues flagged early.

Healthcare offices

Uptime matters when patient care depends on it. Your environment stays documented and your team notified fast.

Warehousing & logistics

Scanners, Wi-Fi, and switching keep your floor moving. Problems surface before they slow operations.

Small & mid-sized business

You rely on your network every day. Clear visibility into how it's performing — no network degree required.

Managed service providers

Deploy across client environments for consistent, proactive oversight — and give customers cleaner visibility too.

How Sentinel AI works

The AI reads the evidence. It doesn't guess.

Answers come only from the telemetry the appliance actually collected — cited, and honest about what it's unsure of.

01

Collect

Your devices report their real status — interface states, error counts, uptime — via SNMP, syslog, and telemetry. The appliance records it all, locally.

02

Correlate

Sentinel's engine compares readings against baselines and thresholds, identifies anomalies, and determines what actually happened — all without AI.

03

Translate

The assistant turns that structured output into language your team can read and act on. A translator, not an analyst.

If Sentinel says a port is down, it's because the device reported it down. Raw logs and secrets never leave the appliance.

SP
Working county network admin
U.S. federal network experience
TS/SCI cleared
Who's behind Sentinel

Built by someone who runs a network like yours.

Sentinel is built and supported by a working network administrator — not a faceless software company. Day to day, ShadowPine's founder keeps a large, distributed county network running across dozens of sites, and built Sentinel out of that exact reality: the need to know what's wrong, fast, without a room full of engineers on call.

That background also includes years of U.S. federal network work and an active Top Secret/SCI clearance — environments where keeping data in-house, documenting every change, and getting it right isn't optional. That's the standard Sentinel is held to, and the person who answers when you need help.

Try it risk-free

Prove the value in 14 days — or your money back.

We're confident Sentinel will earn its place on your network. So we make it easy to find out, with zero risk.

Free 14-day assessment

Run Sentinel on your real network for two weeks at no cost. Decide based on your own environment — not a canned demo.

Money-back guarantee

If it isn't useful for your team after 14 days, you get your money back. No fine print, no friction.

Start your free assessment
No credit card to begin. We'll help you get Sentinel running on your network.
Deployment options

However you run your environment, Sentinel fits.

Deploy it yourself as a virtual machine, have us install a dedicated hardware appliance, or let us set it up for you — including on hardware you already have.

Virtual appliance

Download our OVF/OVA template and deploy Sentinel as a VM in your own hypervisor — entirely inside your environment.

OVF / OVAVMware & ProxmoxSelf-deploy

Hardware appliance

Prefer a turnkey box? We supply and install a dedicated appliance on-site — racked, configured, and ready before we leave.

TurnkeyOn-site installDedicated device

Assisted installation

Want a hand? We'll deploy and configure Sentinel for a fixed, flat fee — discovery dialed in and your first reports running.

Fixed feeWe deploy & configure
Consulting & engineering

Built-in consulting to evolve your network as you grow.

Beyond the appliance, ShadowPine works alongside your team — senior, hands-on expertise when you need it, without a full-time hire.

Network design & deployment

Greenfield builds and refreshes — designed, staged, and cut over with a written rollback plan.

Cisco CatalystSwitchingRouting

Identity & access control

Cisco ISE with 802.1X certificate auth and segmentation — deployed correctly, documented at handoff.

Cisco ISE802.1XTrustSec

Firewall & threat defense

Installs, refreshes, rulebase cleanup, and VPN hardening across Cisco FTD, ASA, and FortiGate.

FirepowerASAFortiGate

SASE & zero-trust access

Cisco Umbrella and Secure Access for modern, secure connectivity without traditional VPN complexity.

Secure AccessUmbrellaZTNA

Wireless reliability

Eliminate dead zones and roaming problems — Cisco WLC and FortiAP with proper RF tuning.

Cisco WLCFortiAPRF tuning

Cleared & regulated work

TS/SCI-cleared engineering for federal and regulated environments, with STIG-aligned, audit-ready docs.

TS/SCISTIGChange control
How we work

A predictable process, start to finish.

Every engagement follows the same disciplined path — so you know what to expect, and your network stays supportable.

01

Discovery

We learn your environment, goals, and constraints — and recommend the most sensible next step, not the most expensive one.

02

Scope & plan

Defined deliverables, a written work plan, and fixed pricing where the scope allows.

03

Execute cleanly

Planned maintenance windows and rollback paths on every engagement. No unplanned production changes.

04

Handoff

Diagrams, configurations, and a complete change log at close. Your team can support what we built.

Get started

Tell us about your network.

Whether you want early access to Sentinel or engineering help on a project — start with a brief description of your environment and what you're trying to fix.

Location
Cartersville, Georgia — serving North Georgia and remote clients
Response time
We reply within one business day. Include a brief description of your environment.