OpenSentinel
The Future of Non-Invasive Bot Protection (1.0 Production Release)
Privacy-first. Zero-click. Powered by Rust, local ONNX ML & Behavioural Analysis. Forged in Mzansi to protect the Open Web.
The Problem: You Are The Product
Unpaid Labour
Every time you are forced to identify a traffic light, crosswalk, or bicycle, you are actively performing unpaid labour to train commercial artificial intelligence models. Your time and attention are monetised without consent, turning the act of browsing into a transactional product.
Privacy Invasion
Traditional CAPTCHA systems rely on invasive tracking cookies, browser fingerprinting, and device profiling. To determine humanity, they track digital footprints across the web, constructing detailed profiles that breach user privacy and digital sovereignty.
Accessibility Barriers
Visual puzzles and distorted text tests present severe barriers for visually impaired individuals. These interruptive challenges continually frustrate users, inherently degrading user experience and lowering conversion rates for online services.
The Solution: Behavioural Sovereignty
OpenSentinel shifts security from the archaic "Challenge-Response" model to a seamless "Passive Observation" methodology. We verify humanity by analysing how you interact with a page, rather than demanding what objects you can identify in a photograph.
1. Passive Telemetry
Our ultra-lightweight JavaScript sensor (under 20kb) silently observes interaction metrics such as mouse trajectory linearity, velocity variance, and keystroke flight dynamics. Because human interaction exhibits natural physical variance whilst bots operate with rigid precision, we accurately distinguish between the two.
2. Local Analysis
We believe privacy is a fundamental human right. OpenSentinel processes behavioural telemetry locally, extracting abstract features rather than personal identifiers. We calculate the statistical shape of interactions, guaranteeing strict compliance with global privacy standards like POPIA and GDPR.
3. Rust Performance
The OpenSentinel backend is engineered using Rust and Actix-web, delivering high concurrent throughput, minimal memory usage, and microsecond verification speeds capable of handling enterprise traffic loads gracefully.
First-Party SDK Ecosystem
OpenSentinel offers native integration packages tailored for modern Web and backend development stacks.
@azanian-eagle/opensentinel-react provides full TypeScript support, SSR safety checks, and the customizable useOpenSentinel() React hook with automated cleanup.
npm install @azanian-eagle/opensentinel-react
azanian-eagle-opensentinel offers a lightweight client wrapper for server-side verification using Python standard libraries (no heavy external HTTP runtime dependencies).
pip install azanian-eagle-opensentinel
@azanian-eagle/opensentinel-client delivers a sub-20kb browser sensor featuring client-side Proof-of-Work nonces, AES-256-GCM encryption, and exponential backoff retry mechanisms.
<script src="/src/sensor.js"></script>
Live Observability & Dashboard
Enterprise-Grade Telemetry & Health Monitoring: OpenSentinel ships built-in observability tools to give site operators total visibility into verification traffic, bot rates, and network performance.
- ✓ Authenticated Analytics Dashboard: Real-time visual metrics served directly from the Rust backend at
/api/dashboard(secured via HTTP Basic Authentication using theADMIN_TOKENenvironment variable). - ✓ Prometheus Metrics Endpoint: Native Prometheus exporter at
/metricsexposing request counters, verification outcomes (verify_success_total,verify_failed_total), rate-limiting events, and threat federation statistics. - ✓ Container Probes: Standardized
/healthzand/readyzhealth checks for seamless Kubernetes liveness and readiness probe integration.
Who Is This For?
For Developers & Software Engineers
Eliminate bloated third-party scripts that compromise application performance and user privacy. OpenSentinel provides modern, developer-first tools:
- ✓ Drop-in Integration: Add bot protection using our SDKs or two lines of client script.
- ✓ Transparent & Open Source: Fully audit code licensed under the permissive MIT Licence.
- ✓ Ultra-Lightweight Footprint: Avoid heavy WebAssembly payloads that delay Time to Interactive (TTI).
For Funders, Financiers & Investors
Support an ethical, high-performance cybersecurity framework designed to challenge monopolistic data-harvesting paradigms.
- ✓ Privacy Market Opportunity: Evolving privacy regulations (GDPR, POPIA, CCPA) create growing demand for non-invasive security solutions.
- ✓ Digital Sovereignty: A "Made with ♥ in South Africa" technology disrupting traditional cybersecurity markets.
- ✓ High Scalability: Engineered in Rust to deliver enterprise throughput at exceptionally low operational overhead.
For The General Public
Reclaim your browsing experience and assert your right to privacy without constant interrogation.
- ✓ Absolute Privacy: Zero cross-site tracking, zero user profiling, and zero cookie beacons.
- ✓ Frictionless Experience: No fire hydrants, crosswalks, or distorted characters. Browse naturally.
- ✓ Local Innovation: Champion South African open-source software engineering excellence.
The Competitive Edge
See how OpenSentinel compares directly against established industry solutions like Cloudflare Turnstile and Google reCAPTCHA.
| Feature | OpenSentinel | Cloudflare Turnstile | hCaptcha / reCAPTCHA |
|---|---|---|---|
| User Experience | ✓ Zero Friction (Passive) | ✓ Mostly Invisible | ✗ Interruptive Puzzles |
| Privacy (POPIA/GDPR) | ✓ Compliant by Design (No Tracking) | ⚠ Opaque Telemetry | ✗ Extensive Profiling |
| Third-Party AI Training | ✓ Zero (Local ONNX Inference) | ⚠ Opaque Model Usage | ✗ Unpaid AI Training |
| Decentralised Threat Sharing | ✓ Yes (Ed25519 Signed P2P) | ✗ Centralised Vendor Lock-in | ✗ Centralised Vendor Lock-in |
| Code Transparency | ✓ Open Source (MIT) | ✗ Proprietary | ✗ Proprietary |
| Observability & Metrics | ✓ Dashboard & Prometheus Exporter | ⚠ Restricted Cloud Metrics | ⚠ Restricted Cloud Metrics |
Phase 3: Federated P2P Threat Intelligence
Collective Protection Without Data Harvesting: OpenSentinel achieves network-wide intelligence through an open, peer-to-peer Federated Threat Intelligence Network without aggregating personal user profiles.
Cryptographically Signed Signatures
Participating nodes exchange anonymised mathematical threat signatures signed using Ed25519 keypairs. This ensures signature origin validation and prevents threat pollution.
Dynamic Peer Discovery
Nodes dynamically query discovery endpoints specified via FEDERATION_DISCOVERY_URL to automatically discover new peer instances across the global network.
Resilient Client Fallback
The client sensor supports multiple fallback endpoint arrays. If a primary node experiences network instability, the sensor seamlessly retries secondary trusted nodes with exponential backoff.
Technical Architecture & How It Works
OpenSentinel fuses lightweight client instrumentation, blazing-fast Rust execution, and local ONNX machine-learning inference.
1. Sensor Telemetry & Encryption
The client sensor records interaction coordinate arrays and timing metrics. Telemetry is encrypted using client-side AES-256-GCM encryption paired with a dynamic 32-byte key before transmission.
2. Cryptographic Proof-of-Work
To deter automated script attacks and high-volume request spam, the client computes SHA-256 Proof-of-Work nonces before dispatch, raising computational costs for automated bots.
3. Rust Backend & ONNX ML
The Actix-web server decrypts incoming payloads, validates timestamp windows and nonces against replay attacks, and passes feature vectors to the local Random Forest ONNX model (`ort` crate) for real-time score generation.
Implementation Manual & Production Deployment
Deploy the sovereign backend service and integrate our official client packages in minutes.
Install prebuilt binaries via Shell script or Homebrew, or compile via crates.io:
# Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/Azanian-Eagle/OpenSentinel/releases/download/1.0.4279/opensentinel-server-installer.sh | sh
# Or install via Homebrew
brew install opensentinel-server
Or pull the official tagged release image with Docker:
docker pull ghcr.io/azanian-eagle/opensentinel:v1.0.4279
cp .env.example .env
docker compose up -d
Configure essential environment variables in .env:
PORT=8080
PAYLOAD_SECRET_KEY=0102030405060708090a0b4c0d0e0f101112131415161718191a1b1c1d1e1f20
ADMIN_TOKEN=your_secure_admin_token
FEDERATION_ENABLED=true
TRUSTED_PEERS=https://node1.example.com
Step 2: Integrate Frontend Client
Integrate using vanilla JavaScript, React, or Python:
<script src="/src/sensor.js"></script>
<script>
OpenSentinel.init({
endpoints: ['https://api.yourdomain.com/verify'],
enablePoW: true,
onSuccess: function(token) {
console.log('Human verified successfully.');
},
onFailure: function() {
console.warn('Bot behaviour detected.');
}
});
</script>
Regulatory Compliance & Data Protection
Built for the Modern Regulatory Landscape: OpenSentinel is systematically designed from the ground up to guarantee absolute compliance with global data protection laws, including South Africa's Protection of Personal Information Act (POPIA), Europe's General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
- ✓ Zero Personally Identifiable Information (PII): We categorically never collect IP addresses, browser fingerprints, email addresses, or any other data that could identify an individual user.
- ✓ Strict Data Minimisation: The sensor only measures the mathematical variance of user interactions (mouse trajectory linearity, speed, keystroke intervals). This abstract telemetry is completely anonymous and impossible to reverse-engineer into personal profiles.
- ✓ Localised Processing: Our state-of-the-art ONNX machine-learning model runs entirely on your own server infrastructure. We do not utilise external cloud APIs, ensuring your users' behavioural data never leaves your sovereign control.
- ✓ No Cross-Site Tracking: We fundamentally reject tracking cookies, local storage beacons, or persistent identifiers. Interactions across different sites remain entirely independent.
Open-Source Community & Governance
Contributing to the Vision
OpenSentinel thrives on radical transparency and community collaboration. We actively encourage security researchers, software engineers, and data scientists to audit our codebase, refine model definitions, and submit pull requests. See CONTRIBUTING.md on GitHub.
Security Policy
Security is paramount. We maintain a clear vulnerability disclosure policy. Potential security findings in our core Rust backend or sensor components should be reported privately according to our SECURITY.md guidelines.
Transparent Governance
OpenSentinel is governed under a permissive MIT Licence, a transparent technical governance model, and a standard Code of Conduct to ensure welcoming community collaboration worldwide.
About OpenSentinel
OpenSentinel is an independent South African open-source initiative dedicated to reclaiming digital privacy and web sovereignty. We believe cybersecurity tools must remain transparent, universally accessible, and deeply respectful of fundamental human rights.
Forged in Mzansi to serve the global web, OpenSentinel adheres strictly to rigorous memory safety, high-performance systems engineering, and privacy-first architectural principles.
Our Mission: To equip developers worldwide with transparent, high-performance, and entirely free open-source alternatives to Big Tech security monopolies.