frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Offline Deterministic Security Gate

1•EldorZ•18h ago
Hi HN,

I’m working on a security tool born out of frustration with how most security controls work today.

In many environments, security happens after the fact: scan later, alert louder, hope someone reacts in time. Most tools also assume network access, dynamic updates, and trust in external services — which breaks down in regulated, air-gapped, or high-assurance environments.

I decided to explore a different approach.

Sentinel Gate

Sentinel Gate is a deterministic security gate that runs before code leaves the developer machine or CI boundary.

Key design choices:

Offline by design No call-home, no cloud dependency, no remote APIs. Can run fully air-gapped.

Deterministic outcomes The gate does not score or recommend. Artifacts either pass or are blocked.

Immutable ruleset No dynamic rule updates, no remote plugins. The ruleset is versioned and explicitly managed to avoid supply-chain surprises.

Pre-commit and CI enforcement Focused on preventing secrets leakage, CI/CD injection risks, and certain classes of logic/configuration flaws before they propagate.

The goal is simple: answer with certainty whether an artifact is allowed to exist outside a defined boundary.

This is intentionally a hard control, not a flexible scanner.

Auditor Core (related but separate)

Alongside the gate, I’m building Auditor Core, which serves a different purpose.

Auditor Core focuses on understanding and explaining systems, not blocking them:

Repository and infrastructure topology mapping

Baseline drift detection

Analysis across IaC, CI/CD pipelines, containers, Kubernetes, and cloud configs

Evidence-driven reports aimed at engineers and auditors

I keep these as two separate engines on purpose:

Gates prevent mistakes

Audits explain reality

Trying to merge both usually compromises one of them.

Trade-offs & limitations

This approach is not for everyone:

Deterministic rules mean less flexibility

Offline mode means no shared intelligence feeds

It will block things — sometimes inconveniently — by design

It’s not a replacement for dynamic testing or runtime protection

The target audience is environments where predictability and control matter more than coverage breadth.

Code note: The implementation is private at the moment. I’m intentionally validating the architecture, threat model, and assumptions before deciding what to open. Happy to discuss internals and trade-offs in the comments.

This is still evolving, and I’m actively validating assumptions.

I’d especially appreciate feedback from people working in:

regulated or air-gapped environments

CI/CD security

supply-chain security

or anyone who has strong opinions about deterministic vs adaptive controls

Happy to answer technical questions and criticism.

AI Is Eating SaaS: Building an IP Geolocation API in Two Hours

https://vpetersson.com/2026/01/09/ai-is-eating-saas-building-an-ip-geolocation-api-in-two-hours.html
1•ingve•1m ago•0 comments

X UK revenues drop nearly 60% in a year as content concerns spook advertisers

https://www.theguardian.com/technology/2026/jan/09/x-uk-revenues-drop-nearly-60-in-a-year-as-adve...
1•mindracer•2m ago•0 comments

A slim robot under $10k that can do laundry

https://www.engadget.com/home/smart-home/switchbot-came-to-ces-with-a-laundry-robot-you-might-act...
1•MattSayar•2m ago•0 comments

Blockchains and Australian Coffee Cards

https://rubenerd.com/blockchains-and-australian-coffee-cards/
1•speckx•4m ago•0 comments

Buried Talents: How Elites betray their own potential

https://edankrolewicz.substack.com/p/buried-talents
1•ikjasdlk2234•5m ago•0 comments

Ask HN: How are you monetizing ChatGPT / MCP apps today?

1•ssorokin•6m ago•0 comments

Show HN: CloudyWithAChanceOfLatency: testing the water for a net monitoring app

https://cloudywithachanceoflatency.net
1•rixed•6m ago•0 comments

Show HN: CAML-Lint – a linter for narrative/quest JSON used in game design

https://github.com/dkoepsell/CAML-lint/tree/main
1•KoeppyLoco•12m ago•0 comments

People who come off slimming jabs regain weight four times faster than dieters

https://www.bbc.com/news/articles/c050ljnrv2qo
2•breve•12m ago•0 comments

We built a list for Attack Surface Management

https://github.com/Escape-Technologies/awesome-attack-surface-management
2•Gwendal-M•12m ago•0 comments

A single system to test ideas, content, and campaigns before you risk budget

https://blpg.vect.pro
2•yevdduwi•12m ago•1 comments

Schenker Element 16 a semi-modular laptop with a repairable, customizable design

https://liliputing.com/schenker-element-16-is-a-semi-modular-laptop-with-a-repairable-customizabl...
3•7777777phil•15m ago•0 comments

Life Happens at 1x Speed

https://terriblesoftware.org/2026/01/08/life-happens-at-1x-speed/
2•xngbuilds•16m ago•0 comments

How to AI-proof your job

https://www.ft.com/content/5e2593a3-e834-4822-bbc8-7cb27086af24
2•merksittich•16m ago•0 comments

Waveshare releases 7, 8, and 10" ESP32-P4 tablet with SD card, mic, and speaker

https://www.waveshare.com/esp32-p4-wifi6-touch-lcd-7-8-10.1.htm
2•journal•17m ago•1 comments

Ed Feulner, Ed Meese and the Heritage Foundation's Exodus

https://www.wsj.com/opinion/ed-feulner-ed-meese-and-the-heritage-foundations-exodus-8ab6ae02
3•7777777phil•18m ago•0 comments

Why 4 GPUs trained slower than 1 GPU on budget clouds

https://cortwave.github.io/posts/multi-gpu/
2•cortwave•18m ago•0 comments

Modernized Go Fix

https://antonz.org/accepted/modernized-go-fix/
2•blenderob•19m ago•0 comments

Show HN: Clean HTML for Semantic Extraction

https://page-replica.github.io/pure-html-for-rag/demo/
3•nirvanist•19m ago•1 comments

SanDisk to double price of 3D NAND for enterprise SSDs in Q1 2026

https://www.tomshardware.com/pc-components/ssds/sandisk-to-double-price-of-3d-nand-for-enterprise...
2•speckx•21m ago•0 comments

A poker game written in PicoLisp for the Sensor Watch

https://thegeez.net/2026/01/05/watch_bird_poker_picolisp.html
1•fogus•21m ago•0 comments

USA TODAY mapped the potential consequences of a strike on US missile silos

https://www.usatoday.com/story/news/politics/2026/01/06/nuclear-sponge-project-methodology/874001...
2•perihelions•22m ago•0 comments

Kagi releases alpha version of Orion for Linux

https://help.kagi.com/orion/misc/linux-status.html
4•HelloUsername•24m ago•0 comments

"If Starmer is successful in banning X in Britain, I will move forward in . . ."

https://twitter.com/RepLuna/status/2009460496668426449
4•chrisjj•24m ago•1 comments

A Deep Dive into the Linux Kernel Processes and Syscall [pdf]

https://lass.cs.umass.edu/~shenoy/courses/spring20/lectures/Lec09.pdf
3•7777777phil•24m ago•0 comments

Display Size

1•kilvar•25m ago•0 comments

EU envoys provisionally approve signing of record Mercosur trade deal

https://www.reuters.com/world/americas/eu-countries-expected-clear-signing-record-mercosur-trade-...
2•saubeidl•25m ago•0 comments

Link found between gut microbes and symptoms in auto-brewery syndrome

https://today.ucsd.edu/story/what-causes-some-peoples-gut-microbes-to-produce-high-alcohol-levels
2•giuliomagnifico•25m ago•0 comments

What If Your Exhaustion Has Nothing to Do with Your Life?

https://thinkingrock.substack.com/p/what-if-your-exhaustion-has-nothing
2•djrivard•27m ago•0 comments

The Debugging Book – Tools and Techniques for Automated Software Debugging

https://www.debuggingbook.org/#
3•vismit2000•28m ago•0 comments