OpenSentinel

The Future of Non-Invasive Bot Protection (1.0 Production Release)

Privacy-first. Zero-click. Powered by Rust, local ONNX ML & Behavioural Analysis. Forged in Mzansi to protect the Open Web.

OpenSentinel Shield

The Problem: You Are The Product

Unpaid Labour

Every time you are forced to identify a traffic light, crosswalk, or bicycle, you are actively performing unpaid labour to train commercial artificial intelligence models. Your time and attention are monetised without consent, turning the act of browsing into a transactional product.

Privacy Invasion

Traditional CAPTCHA systems rely on invasive tracking cookies, browser fingerprinting, and device profiling. To determine humanity, they track digital footprints across the web, constructing detailed profiles that breach user privacy and digital sovereignty.

Accessibility Barriers

Visual puzzles and distorted text tests present severe barriers for visually impaired individuals. These interruptive challenges continually frustrate users, inherently degrading user experience and lowering conversion rates for online services.

The Solution: Behavioural Sovereignty

OpenSentinel shifts security from the archaic "Challenge-Response" model to a seamless "Passive Observation" methodology. We verify humanity by analysing how you interact with a page, rather than demanding what objects you can identify in a photograph.

1. Passive Telemetry

Our ultra-lightweight JavaScript sensor (under 20kb) silently observes interaction metrics such as mouse trajectory linearity, velocity variance, and keystroke flight dynamics. Because human interaction exhibits natural physical variance whilst bots operate with rigid precision, we accurately distinguish between the two.

2. Local Analysis

We believe privacy is a fundamental human right. OpenSentinel processes behavioural telemetry locally, extracting abstract features rather than personal identifiers. We calculate the statistical shape of interactions, guaranteeing strict compliance with global privacy standards like POPIA and GDPR.

3. Rust Performance

The OpenSentinel backend is engineered using Rust and Actix-web, delivering high concurrent throughput, minimal memory usage, and microsecond verification speeds capable of handling enterprise traffic loads gracefully.

First-Party SDK Ecosystem

OpenSentinel offers native integration packages tailored for modern Web and backend development stacks.

React SDK

NPM React SDK Package Version

@azanian-eagle/opensentinel-react provides full TypeScript support, SSR safety checks, and the customizable useOpenSentinel() React hook with automated cleanup.

View package on npm →

npm install @azanian-eagle/opensentinel-react

Python SDK

PyPI Python SDK Package Version

azanian-eagle-opensentinel offers a lightweight client wrapper for server-side verification using Python standard libraries (no heavy external HTTP runtime dependencies).

View package on PyPI →

pip install azanian-eagle-opensentinel

Vanilla JS / UMD

NPM Client Sensor Package Version

@azanian-eagle/opensentinel-client delivers a sub-20kb browser sensor featuring client-side Proof-of-Work nonces, AES-256-GCM encryption, and exponential backoff retry mechanisms.

View package on npm →

<script src="/src/sensor.js"></script>

Live Observability & Dashboard

Enterprise-Grade Telemetry & Health Monitoring: OpenSentinel ships built-in observability tools to give site operators total visibility into verification traffic, bot rates, and network performance.

  • ✓ Authenticated Analytics Dashboard: Real-time visual metrics served directly from the Rust backend at /api/dashboard (secured via HTTP Basic Authentication using the ADMIN_TOKEN environment variable).
  • ✓ Prometheus Metrics Endpoint: Native Prometheus exporter at /metrics exposing request counters, verification outcomes (verify_success_total, verify_failed_total), rate-limiting events, and threat federation statistics.
  • ✓ Container Probes: Standardized /healthz and /readyz health checks for seamless Kubernetes liveness and readiness probe integration.

Who Is This For?

For Developers & Software Engineers

Eliminate bloated third-party scripts that compromise application performance and user privacy. OpenSentinel provides modern, developer-first tools:

  • ✓ Drop-in Integration: Add bot protection using our SDKs or two lines of client script.
  • ✓ Transparent & Open Source: Fully audit code licensed under the permissive MIT Licence.
  • ✓ Ultra-Lightweight Footprint: Avoid heavy WebAssembly payloads that delay Time to Interactive (TTI).

For Funders, Financiers & Investors

Support an ethical, high-performance cybersecurity framework designed to challenge monopolistic data-harvesting paradigms.

  • ✓ Privacy Market Opportunity: Evolving privacy regulations (GDPR, POPIA, CCPA) create growing demand for non-invasive security solutions.
  • ✓ Digital Sovereignty: A "Made with ♥ in South Africa" technology disrupting traditional cybersecurity markets.
  • ✓ High Scalability: Engineered in Rust to deliver enterprise throughput at exceptionally low operational overhead.

For The General Public

Reclaim your browsing experience and assert your right to privacy without constant interrogation.

  • ✓ Absolute Privacy: Zero cross-site tracking, zero user profiling, and zero cookie beacons.
  • ✓ Frictionless Experience: No fire hydrants, crosswalks, or distorted characters. Browse naturally.
  • ✓ Local Innovation: Champion South African open-source software engineering excellence.

The Competitive Edge

See how OpenSentinel compares directly against established industry solutions like Cloudflare Turnstile and Google reCAPTCHA.

Feature OpenSentinel Cloudflare Turnstile hCaptcha / reCAPTCHA
User Experience ✓ Zero Friction (Passive) ✓ Mostly Invisible ✗ Interruptive Puzzles
Privacy (POPIA/GDPR) ✓ Compliant by Design (No Tracking) ⚠ Opaque Telemetry ✗ Extensive Profiling
Third-Party AI Training ✓ Zero (Local ONNX Inference) ⚠ Opaque Model Usage ✗ Unpaid AI Training
Decentralised Threat Sharing ✓ Yes (Ed25519 Signed P2P) ✗ Centralised Vendor Lock-in ✗ Centralised Vendor Lock-in
Code Transparency ✓ Open Source (MIT) ✗ Proprietary ✗ Proprietary
Observability & Metrics ✓ Dashboard & Prometheus Exporter ⚠ Restricted Cloud Metrics ⚠ Restricted Cloud Metrics

Phase 3: Federated P2P Threat Intelligence

Collective Protection Without Data Harvesting: OpenSentinel achieves network-wide intelligence through an open, peer-to-peer Federated Threat Intelligence Network without aggregating personal user profiles.

Cryptographically Signed Signatures

Participating nodes exchange anonymised mathematical threat signatures signed using Ed25519 keypairs. This ensures signature origin validation and prevents threat pollution.

Dynamic Peer Discovery

Nodes dynamically query discovery endpoints specified via FEDERATION_DISCOVERY_URL to automatically discover new peer instances across the global network.

Resilient Client Fallback

The client sensor supports multiple fallback endpoint arrays. If a primary node experiences network instability, the sensor seamlessly retries secondary trusted nodes with exponential backoff.

Technical Architecture & How It Works

OpenSentinel fuses lightweight client instrumentation, blazing-fast Rust execution, and local ONNX machine-learning inference.

1. Sensor Telemetry & Encryption

The client sensor records interaction coordinate arrays and timing metrics. Telemetry is encrypted using client-side AES-256-GCM encryption paired with a dynamic 32-byte key before transmission.

2. Cryptographic Proof-of-Work

To deter automated script attacks and high-volume request spam, the client computes SHA-256 Proof-of-Work nonces before dispatch, raising computational costs for automated bots.

3. Rust Backend & ONNX ML

The Actix-web server decrypts incoming payloads, validates timestamp windows and nonces against replay attacks, and passes feature vectors to the local Random Forest ONNX model (`ort` crate) for real-time score generation.

Implementation Manual & Production Deployment

Deploy the sovereign backend service and integrate our official client packages in minutes.

Step 1: Deploy the Sovereign Backend Node

Crates.io Server Package Version

Install prebuilt binaries via Shell script or Homebrew, or compile via crates.io:

shell / brew
# Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/Azanian-Eagle/OpenSentinel/releases/download/1.0.4279/opensentinel-server-installer.sh | sh

# Or install via Homebrew
brew install opensentinel-server

Or pull the official tagged release image with Docker:

docker
docker pull ghcr.io/azanian-eagle/opensentinel:v1.0.4279
cp .env.example .env
docker compose up -d

Configure essential environment variables in .env:

.env
PORT=8080
PAYLOAD_SECRET_KEY=0102030405060708090a0b4c0d0e0f101112131415161718191a1b1c1d1e1f20
ADMIN_TOKEN=your_secure_admin_token
FEDERATION_ENABLED=true
TRUSTED_PEERS=https://node1.example.com

Step 2: Integrate Frontend Client

Integrate using vanilla JavaScript, React, or Python:

integration.html
<script src="/src/sensor.js"></script>
<script>
  OpenSentinel.init({
    endpoints: ['https://api.yourdomain.com/verify'],
    enablePoW: true,
    onSuccess: function(token) {
        console.log('Human verified successfully.');
    },
    onFailure: function() {
        console.warn('Bot behaviour detected.');
    }
  });
</script>

Regulatory Compliance & Data Protection

Built for the Modern Regulatory Landscape: OpenSentinel is systematically designed from the ground up to guarantee absolute compliance with global data protection laws, including South Africa's Protection of Personal Information Act (POPIA), Europe's General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

  • ✓ Zero Personally Identifiable Information (PII): We categorically never collect IP addresses, browser fingerprints, email addresses, or any other data that could identify an individual user.
  • ✓ Strict Data Minimisation: The sensor only measures the mathematical variance of user interactions (mouse trajectory linearity, speed, keystroke intervals). This abstract telemetry is completely anonymous and impossible to reverse-engineer into personal profiles.
  • ✓ Localised Processing: Our state-of-the-art ONNX machine-learning model runs entirely on your own server infrastructure. We do not utilise external cloud APIs, ensuring your users' behavioural data never leaves your sovereign control.
  • ✓ No Cross-Site Tracking: We fundamentally reject tracking cookies, local storage beacons, or persistent identifiers. Interactions across different sites remain entirely independent.

Open-Source Community & Governance

Contributing to the Vision

OpenSentinel thrives on radical transparency and community collaboration. We actively encourage security researchers, software engineers, and data scientists to audit our codebase, refine model definitions, and submit pull requests. See CONTRIBUTING.md on GitHub.

Security Policy

Security is paramount. We maintain a clear vulnerability disclosure policy. Potential security findings in our core Rust backend or sensor components should be reported privately according to our SECURITY.md guidelines.

Transparent Governance

OpenSentinel is governed under a permissive MIT Licence, a transparent technical governance model, and a standard Code of Conduct to ensure welcoming community collaboration worldwide.

About OpenSentinel

OpenSentinel is an independent South African open-source initiative dedicated to reclaiming digital privacy and web sovereignty. We believe cybersecurity tools must remain transparent, universally accessible, and deeply respectful of fundamental human rights.

Forged in Mzansi to serve the global web, OpenSentinel adheres strictly to rigorous memory safety, high-performance systems engineering, and privacy-first architectural principles.

Our Mission: To equip developers worldwide with transparent, high-performance, and entirely free open-source alternatives to Big Tech security monopolies.