10 Guards. Zero Gaps.
Every data exit vector is covered with a dedicated, configurable guard. Block or alert — your choice.
Endpoint Protection
10 dedicated guards covering every data exit vector on the device.
USB Guard
Detects, blocks, and ejects unauthorized USB storage devices. Whitelist trusted devices by serial number.
Blocks
- USB flash drives
- External hard drives
- Phone USB tethering
- SD card readers
Configuration
- Block all / whitelist mode
- Whitelist by serial number
- Alert-only mode
- Auto-eject on detection
Network Guard
Blocks unauthorized network ports, protocols, and connections. Prevents SSH/SCP file exfiltration.
Blocks
- SSH / SCP file transfers
- FTP / SFTP uploads
- Unauthorized VPN connections
- Port-based exfiltration
Configuration
- Port whitelist / blacklist
- Protocol filtering
- Connection logging
- Alert on blocked attempt
Browser Guard
Monitors and blocks file uploads, sensitive data pasting, and data exfiltration through web browsers.
Blocks
- File uploads to cloud storage
- Sensitive data paste to ChatGPT/Pastebin
- Drag-and-drop to web apps
- Form-based data submission
Configuration
- Domain blacklist (35+ pre-configured)
- Upload blocking
- Paste detection
- Custom domain rules
Process Guard
Detects and terminates unauthorized processes. Prevents use of file transfer tools, VPNs, and remote access software.
Blocks
- TeamViewer / AnyDesk
- Telegram / Signal Desktop
- Torrent clients
- Unauthorized VPN clients
Configuration
- Block list (40+ pre-configured)
- Custom process rules
- Alert vs kill mode
- Process activity logging
Clipboard Guard
Monitors clipboard for sensitive data — credentials, PII, financial records, source code, and confidential content. Clears or blocks as configured.
Blocks
- PII & financial data copy-paste
- Credential exfiltration
- Large text block copying
- Cross-application sensitive data paste
Configuration
- Code pattern detection
- Auto-clear clipboard
- Sensitive data regex rules
- Alert on detection
Screenshot Guard
Blocks screenshot tools, screen recording software, and print-screen functionality.
Blocks
- Print Screen / Snipping Tool
- OBS / Camtasia recording
- Third-party capture tools
- Screen sharing (configurable)
Configuration
- Block all capture methods
- Allow specific tools
- Watermark mode
- Activity logging
File Watcher
Watches for suspicious file operations — large copies, sensitive file access, and bulk file movements.
Blocks
- Bulk file copy operations
- Sensitive directory access
- Large file creation
- Archive/zip creation
Configuration
- Watch directories list
- File size thresholds
- Extension filtering
- Real-time alerts
AirDrop / BT Guard
Prevents file sharing via AirDrop, Bluetooth, and other wireless transfer protocols.
Blocks
- AirDrop file sharing
- Bluetooth file transfer
- Nearby Share / Quick Share
- Wi-Fi Direct transfers
Configuration
- Disable AirDrop completely
- Block Bluetooth file transfer
- Allow paired devices only
- Alert on attempts
Print Guard
Monitors and controls printing activity. Blocks unauthorized print jobs or logs all print activity.
Blocks
- Unauthorized printing
- Print to file / PDF
- Network printer access
- Virtual printer drivers
Configuration
- Block all / allow specific printers
- Print logging with metadata
- Alert on sensitive document print
- Quota management
Encryption Guard
Auto-enables BitLocker (Windows) or FileVault (macOS). Recovery keys stored securely on BlueSentinel — not Microsoft, not Apple.
Blocks
- Unencrypted disk access
- Encryption disablement
- Recovery key exposure
- Boot-level attacks
Configuration
- Auto-enable encryption
- Recovery key escrow
- Compliance reporting
- Encryption algorithm selection
Central Management
Multi-tenant admin dashboard to manage devices, policies, groups, and remote commands.
Multi-Tenant Architecture
Each organization gets isolated data, policies, and admin users. Perfect for MSPs managing multiple clients.
RBAC Roles
Super Admin, Org Admin, Security Analyst, and Read-Only roles with granular permission control.
Policy Inheritance
Set policies at org level, override per-group, and create per-device exceptions. Changes push in real-time.
Device Enrollment
Generate enrollment tokens with expiry and max-use limits. Devices auto-register on first heartbeat.
Remote Commands
Force policy refresh, enable/disable guards, trigger scans, lock devices, or wipe agent data remotely.
Browser Protection
Force-installed Chrome extension that cannot be removed or disabled by users.
File Upload Blocking
Prevents file uploads to any website — cloud storage, email attachments, social media, code repositories.
Code Paste Detection
Detects when users paste sensitive data — source code, credentials, PII, financial records — into AI tools (ChatGPT, Claude), pastebins, or external sites.
Domain Blocking
Pre-configured list of 35+ data exfiltration domains. Add custom domains via admin dashboard.
Drag-and-Drop Prevention
Blocks drag-and-drop file transfers to browser windows, preventing bypass of upload blocking.
Anti-Tamper Protection
4-layer protection ensures the agent cannot be stopped, killed, or removed by users.
Dual Watchdog Processes
Two independent watchdog processes monitor each other and the main agent. If any dies, others restart it within seconds.
Self-Healing
If agent files are deleted or corrupted, the watchdog downloads fresh copies from the central server and reinstalls.
File Locking
Critical agent files are locked at the OS level. Users cannot delete, rename, or modify them while the agent runs.
OS Service Protection
Registered as a protected OS service (Windows Service / macOS LaunchDaemon) that auto-starts on boot.
Disk Encryption Management
Centrally manage BitLocker (Windows) and FileVault (macOS) encryption across all endpoints.
Auto-Enable Encryption
Automatically enable disk encryption on devices that don't have it. No user interaction required.
Recovery Key Escrow
Recovery keys are stored securely on BlueSentinel — not Microsoft's, not Apple's. Full control over key access.
Compliance Dashboard
See encryption status across all devices at a glance. Identify non-compliant devices instantly.
Algorithm Selection
Choose encryption algorithm and key strength per policy. AES-256 by default.