10 Guards. Zero Gaps.

Every data exit vector is covered with a dedicated, configurable guard. Block or alert — your choice.

Endpoint Protection

10 dedicated guards covering every data exit vector on the device.

USB Guard

Detects, blocks, and ejects unauthorized USB storage devices. Whitelist trusted devices by serial number.

Blocks

  • USB flash drives
  • External hard drives
  • Phone USB tethering
  • SD card readers

Configuration

  • Block all / whitelist mode
  • Whitelist by serial number
  • Alert-only mode
  • Auto-eject on detection

Network Guard

Blocks unauthorized network ports, protocols, and connections. Prevents SSH/SCP file exfiltration.

Blocks

  • SSH / SCP file transfers
  • FTP / SFTP uploads
  • Unauthorized VPN connections
  • Port-based exfiltration

Configuration

  • Port whitelist / blacklist
  • Protocol filtering
  • Connection logging
  • Alert on blocked attempt

Browser Guard

Monitors and blocks file uploads, sensitive data pasting, and data exfiltration through web browsers.

Blocks

  • File uploads to cloud storage
  • Sensitive data paste to ChatGPT/Pastebin
  • Drag-and-drop to web apps
  • Form-based data submission

Configuration

  • Domain blacklist (35+ pre-configured)
  • Upload blocking
  • Paste detection
  • Custom domain rules

Process Guard

Detects and terminates unauthorized processes. Prevents use of file transfer tools, VPNs, and remote access software.

Blocks

  • TeamViewer / AnyDesk
  • Telegram / Signal Desktop
  • Torrent clients
  • Unauthorized VPN clients

Configuration

  • Block list (40+ pre-configured)
  • Custom process rules
  • Alert vs kill mode
  • Process activity logging

Clipboard Guard

Monitors clipboard for sensitive data — credentials, PII, financial records, source code, and confidential content. Clears or blocks as configured.

Blocks

  • PII & financial data copy-paste
  • Credential exfiltration
  • Large text block copying
  • Cross-application sensitive data paste

Configuration

  • Code pattern detection
  • Auto-clear clipboard
  • Sensitive data regex rules
  • Alert on detection

Screenshot Guard

Blocks screenshot tools, screen recording software, and print-screen functionality.

Blocks

  • Print Screen / Snipping Tool
  • OBS / Camtasia recording
  • Third-party capture tools
  • Screen sharing (configurable)

Configuration

  • Block all capture methods
  • Allow specific tools
  • Watermark mode
  • Activity logging

File Watcher

Watches for suspicious file operations — large copies, sensitive file access, and bulk file movements.

Blocks

  • Bulk file copy operations
  • Sensitive directory access
  • Large file creation
  • Archive/zip creation

Configuration

  • Watch directories list
  • File size thresholds
  • Extension filtering
  • Real-time alerts

AirDrop / BT Guard

Prevents file sharing via AirDrop, Bluetooth, and other wireless transfer protocols.

Blocks

  • AirDrop file sharing
  • Bluetooth file transfer
  • Nearby Share / Quick Share
  • Wi-Fi Direct transfers

Configuration

  • Disable AirDrop completely
  • Block Bluetooth file transfer
  • Allow paired devices only
  • Alert on attempts

Print Guard

Monitors and controls printing activity. Blocks unauthorized print jobs or logs all print activity.

Blocks

  • Unauthorized printing
  • Print to file / PDF
  • Network printer access
  • Virtual printer drivers

Configuration

  • Block all / allow specific printers
  • Print logging with metadata
  • Alert on sensitive document print
  • Quota management

Encryption Guard

Auto-enables BitLocker (Windows) or FileVault (macOS). Recovery keys stored securely on BlueSentinel — not Microsoft, not Apple.

Blocks

  • Unencrypted disk access
  • Encryption disablement
  • Recovery key exposure
  • Boot-level attacks

Configuration

  • Auto-enable encryption
  • Recovery key escrow
  • Compliance reporting
  • Encryption algorithm selection

Central Management

Multi-tenant admin dashboard to manage devices, policies, groups, and remote commands.

Multi-Tenant Architecture

Each organization gets isolated data, policies, and admin users. Perfect for MSPs managing multiple clients.

RBAC Roles

Super Admin, Org Admin, Security Analyst, and Read-Only roles with granular permission control.

Policy Inheritance

Set policies at org level, override per-group, and create per-device exceptions. Changes push in real-time.

Device Enrollment

Generate enrollment tokens with expiry and max-use limits. Devices auto-register on first heartbeat.

Remote Commands

Force policy refresh, enable/disable guards, trigger scans, lock devices, or wipe agent data remotely.

Browser Protection

Force-installed Chrome extension that cannot be removed or disabled by users.

File Upload Blocking

Prevents file uploads to any website — cloud storage, email attachments, social media, code repositories.

Code Paste Detection

Detects when users paste sensitive data — source code, credentials, PII, financial records — into AI tools (ChatGPT, Claude), pastebins, or external sites.

Domain Blocking

Pre-configured list of 35+ data exfiltration domains. Add custom domains via admin dashboard.

Drag-and-Drop Prevention

Blocks drag-and-drop file transfers to browser windows, preventing bypass of upload blocking.

Anti-Tamper Protection

4-layer protection ensures the agent cannot be stopped, killed, or removed by users.

Dual Watchdog Processes

Two independent watchdog processes monitor each other and the main agent. If any dies, others restart it within seconds.

Self-Healing

If agent files are deleted or corrupted, the watchdog downloads fresh copies from the central server and reinstalls.

File Locking

Critical agent files are locked at the OS level. Users cannot delete, rename, or modify them while the agent runs.

OS Service Protection

Registered as a protected OS service (Windows Service / macOS LaunchDaemon) that auto-starts on boot.

Disk Encryption Management

Centrally manage BitLocker (Windows) and FileVault (macOS) encryption across all endpoints.

Auto-Enable Encryption

Automatically enable disk encryption on devices that don't have it. No user interaction required.

Recovery Key Escrow

Recovery keys are stored securely on BlueSentinel — not Microsoft's, not Apple's. Full control over key access.

Compliance Dashboard

See encryption status across all devices at a glance. Identify non-compliant devices instantly.

Algorithm Selection

Choose encryption algorithm and key strength per policy. AES-256 by default.