Skip to content

Sentinel Mesh

SENTINEL MESH

Every AI provider is a silo — separate key, separate bill, no single view of who called what or where it ran.

Sentinel Mesh puts every request on one governed path.

THE PROBLEM

Every provider is its own silo

Adopt more than one AI provider and each one becomes an island — its own key, its own bill, its own dashboard, its own idea of what a request looks like. Nobody can answer the questions that actually matter: who called what, what it cost, and where it ran. Spend leaks across accounts you can’t see into. Sensitive data crosses borders you can’t prove it didn’t. And the day you want to switch models or add one, you’re rewriting apps.

Sentinel Mesh is the gateway that ends the silo. Every request — whatever app, whatever model — follows one governed path behind a single API at sentinel.junaid.pk/v1: one key, one audit trail, one bill. You always know who made a call, what it cost, and where it ran. And because the in-country model is the default, the safe answer is the one you get without doing anything.

THE PIPELINE

One governed path — the pipeline

The value of a single path is that every request is accountable in the same way: authenticated, budgeted, guarded, and metered before anyone is billed and after any answer is returned. Nothing routes around it.

  1. Sign-in — each sk-mesh-… key is scoped to what it may do (chat, analytics, admin) and carries a hard per-key rate limit. Keys are stored encrypted, never in the clear — so a leaked key can’t run wild, and every call is tied to a known caller.
  2. Limits & credits — every workspace has a monthly usage allowance, and each request sets aside credit from the prepaid balance up front, so a burst of traffic can never quietly overspend your balance.
  3. Guardrails — blocked terms are stopped and personal data is redacted before a request goes out. Each workspace can tighten the platform rules further (never loosen them), and a live feed shows what was caught.
  4. Routing — the request runs on our in-country model by default, kept inside the country on the sovereign path. Reaching for anything else is a deliberate, per-request choice.
  5. Meter & settle — the call is priced and recorded in PKR, and the amount set aside earlier is charged at the final rate — so every rupee shows up against a specific caller and request.
The Sentinel Mesh request pipeline Every request follows one governed path through five stages in order: key sign-in; credit budgeting against the prepaid balance; guardrails; routing to the in-country model by default, kept inside Pakistan; and metering and billing in PKR against the caller and call. STAYS IN-COUNTRY 1 Sign-in sk-mesh-… key scoped, rate-capped 2 Budget reserve credit from prepaid balance 3 Guardrails block · redact before dispatch 4 Route in-country model sovereign by default 5 Meter & bill priced in PKR per caller & call REQUEST RESPONSE + USAGE
Every request takes the same path — signed in, budgeted, guarded, run, and billed. Only the routing stage leaves the gateway: sovereign by default, and always kept in-country for anything marked sensitive, whatever your routing choice. Other providers stay off unless you turn them on for a request — and in the Sentinel Qila defence version they are not present at all.

ONE API

One API, no rewrites

Every provider expects a different request shape, which is why adding or switching one usually means touching code. Sentinel removes that tax.

Sentinel Mesh accepts requests in the three most common formats — OpenAI (/v1/chat/completions), Anthropic (/v1/messages), and Gemini (/v1beta) — all through the same pipeline, with live streaming on the OpenAI route. Whatever your app already speaks, it works unchanged, and switching the model behind it never touches your code.

Three wire formats, one in-country pipeline Sentinel accepts requests in the OpenAI, Anthropic and Gemini wire formats, so existing SDKs work unchanged. These are request shapes the gateway serves, not external providers it calls: all three feed the same governed pipeline and, by default, the same in-country model. THE SHAPE YOU SEND — YOUR SDK, UNCHANGED OpenAI wire format POST /v1/chat/completions Anthropic wire format POST /v1/messages Gemini wire format POST /v1beta One pipeline auth · quota · guardrails route · meter · settle STREAMING ON /v1 In-country model a leading 35B model in Pakistan · nothing leaves DEFAULT PATH These are request shapes Sentinel serves — not calls to those companies. Your request reaches the in-country model; routing anywhere else is opt-in and off by default.
Three front doors, one governed path. Point an existing OpenAI, Anthropic or Gemini app at Sentinel and it just works — no rewrite. These are formats Sentinel serves in-country; they are not the outside providers described under routing below.

THREE WAYS TO RUN IT

One engine, three ways to run it

Sentinel Mesh is a single gateway. How you run it changes where it lives and how you pay for it — never what it is. You are never buying a different product or a second stack.

OfferingWhere it runsSovereigntyBilling
Reseller SaaSSentinel’s in-country cloud — sell it as your own, build on it directly, or try it free in the PlaygroundSovereign by default; other providers stay off unless you turn them on for a requestPriced per use — pay-as-you-go on local rails
Mesh on-premiseThe same full gateway, run on your own servers for your internal trafficSelf-hosted — you decide which providers to use, so your data leaving the building is your call; not isolated, not sovereign-onlyOne flat annual licence
Sentinel QilaThe air-gapped defence version, on your own infrastructureSovereign-only — fully isolated, no outbound traffic allowed, so nothing ever leavesOne flat annual licence

Whichever way you run it, you see your own usage and Sentinel Watch in full — a licence changes how you pay, not what you can see.

WHY IT HOLDS UP

What the gateway guarantees

Answers you can trust, with the reasoning shown

Our in-country model thinks before it answers. Sentinel captures that thinking and shows it next to the reply — a collapsible 💭 Thinking view in the Playground and Sandbox — so you get a deliberate, well-reasoned answer and can see how it got there. The reasoning stays in-country, on a sovereign model, so nothing leaves the country to earn your trust.

Many models, one key — sovereign-first

Locking your apps to a single provider is a risk; wiring up several yourself is a maintenance burden. Sentinel gives you a pool of models behind one key: the router picks the best fit for each request and moves down the list if one fails — the OpenRouter idea, rebuilt on sovereign ground.

  • Sovereign is the default, not the fallback — ask for nothing and you get the in-country model. Reaching for an outside provider is a deliberate choice you make per request, so outside routing can be switched on across the platform without quietly moving anyone’s normal traffic offshore.
  • Choose how requests are matched — by lowest cost, by fastest response (measured live by the gateway), or by task — where the request is read as code, analysis, or chat and matched to a model that suits it.
  • Sovereign-first — the in-country model always leads, and any request marked sensitive stays in-country no matter what. Outside providers are off unless you turn them on for a request; the sovereign path never leaves.
  • Add providers without a rebuild — operators add, key, enable, or disable providers and models from the admin console (/app/admin/engine), and routing picks them up straight away. Any OpenAI-compatible service works out of the box. Keys can be replaced but never read back.
  • Not present in the defence versionSentinel Qila ships with no way to reach an outside provider at all. It runs fully isolated inside your perimeter — no outbound traffic allowed, so nothing can ever leave. That’s what makes “nothing leaves” something you can prove, not just something you’ve configured.

Every reply tells you which model answered and whether it stayed sovereign, so you can always see where a request ran.

Billing that matches how you run it

On the Reseller SaaS, every request is priced and recorded — operators get a clear bill per customer, per period, showing what they paid, what they charged, and the margin in between. AI becomes a product you can resell at a visible profit. Run Mesh on your own infrastructure — on-premise or as Sentinel Qila — and you pay one flat annual licence instead, with no per-call charges. Either way you keep full visibility of your usage and Sentinel Watch: a licence changes how you pay, not what you can see.

Capacity you can count on

Demand for AI is spiky, and a shared platform has to make sure a burst of free traffic never starves paying or mission-critical work. Priority runs defence › paid › free, with high availability across sovereign endpoints. Every key has a limit, and Sentinel Mesh is the single authority that enforces them — so the platform stays predictable under load.

See the Quickstart to make a call.