Skip to content

LeafCore Labs

by LeafCore Labs

SENTRIX

Sentri-X by LeafCore Labs

A production defense OS — not another SIEM dashboard.

Predict, detect, understand, respond, recover, and learn across your estate with specialist agents coordinated by Helix Neuralix.

Positioning

Not a SIEM. A defense operating system.

Sentri-X is LeafCore’s cyber adaptation of Helix Neuralix — the live agent control plane. It runs an autonomous defense loop end to end, instead of dumping alerts into another dashboard for humans to chase.

SIEM dashboards

Centralize logs and alerts. Analysts still stitch context, decide, and act.

Sentri-X

Coordinates specialist agents that predict, detect, understand, respond, recover, and learn — in production.

Defense loop

Predict
Detect
Understand
Respond
Recover
Learn

Helix Neuralix for cyber

The live agent control plane, adapted for defense.

Helix Neuralix is LeafCore’s live agent control plane. Sentri-X adapts that same topology — agents, models, loops, and memory — for cyber defense operations.

Live topology of sensors, agents, models, and defense loops
Autonomous coordination across identity, cloud, network, and endpoint signals
Decision support with graph context and specialist reasoning
Visual mission control for active threats and recovery flows

Mission Control

One plane for defense operations.

01

Live defense topology

02

Specialist agent mesh

03

Autonomous response playbooks

04

Threat knowledge graph

05

Digital twin simulation

06

Learning & feedback loops

07

Asset & vulnerability context

08

Executive briefings

Topology

Layers that keep the defense loop alive.

01

Sensors

Ingest signals from identity, cloud, network, endpoint, and application surfaces.

02

Loops

Closed defense cycles that move from prediction through recovery and learning.

03

Agents

Specialist operators that hunt, analyze, advise, and act with shared context.

04

Core

Orchestration and mission control that routes work across the mesh.

05

Models

Reasoning and routing for detection, triage, and response decisions.

06

Memory

Graph, vector, and operational memory that compounds institutional knowledge.

Specialist roster

Nineteen specialists. One orchestrator.

Domain agents cover the cyber kill chain and the operating rhythms of a modern SOC — coordinated as a single defense mesh.

Orchestrator

01

Threat Hunter

02

SOC Analyst

03

Threat Intelligence

04

Malware Analyst

05

Cloud Security

06

Identity Security

07

Network Security

08

DFIR

09

Compliance

10

Risk

11

Executive Advisor

12

Knowledge Graph

13

Learning

14

Attack Simulation

15

Response

16

Patch Intelligence

17

Asset Discovery

18

Vulnerability

19

Security Copilot

Services architecture

Ten services. Clear boundaries.

01

Gateway

Edge entry for APIs, auth handoff, and tenant routing.

02

Identity

Tenancy, roles, and access control for operators and agents.

03

Ingest

Signal intake from sensors and connected security tooling.

04

Pipeline

Normalization, enrichment, and event flow into detection.

05

Graph

Relationship memory across assets, identities, and threats.

06

Detect

Detection logic that feeds specialist understanding.

07

Agents

Runtime for the specialist mesh and orchestrator.

08

Response

Playbook execution and controlled containment actions.

09

Twin

Simulation surface for attack paths and recovery rehearsal.

10

Workers

Async jobs for heavy analysis, crawling, and long-running tasks.

Architecture

Repo-accurate stack for the Operator OS.

Sentri-X v0.1.0 · Apache-2.0 · Python 3.11+ · Node 22+

01Browser → Nginx → Next.js Operator OS (@sentri-x/web)
02Nginx → Gateway BFF (REST · GraphQL · WebSocket) → microservices
03Ingest → Redpanda → Pipeline → ClickHouse + Neo4j
04Agents → LangGraph orchestrator · 19 specialists · Neuralix canvas

Data plane

Postgres 16

Identity, tenants, LangGraph checkpoints, relational state with RLS.

ClickHouse

Analytics and enriched security events.

Neo4j

Knowledge graph, attack paths, and blast radius.

Qdrant

Vector memory and RAG for specialist context.

Redis 7

Cache, bus helpers, and Celery broker / results.

MinIO

S3-compatible object storage.

Tech stack

LayerTechnology
Monorepopnpm · Turborepo · uv · TypeScript 5.9 · Python 3.11
FrontendNext.js 16 · React 19 · Tailwind 4 · @xyflow/react · motion · cmdk
GatewayFastAPI · Strawberry GraphQL · WebSocket · auth proxy
ServicesIdentity · Ingest · Pipeline · Graph · Detect · Agents · Response · Twin · Workers
AILangGraph · LangChain · Groq · fastembed · capability-role router
DataPostgres · Redis · ClickHouse · Neo4j · Qdrant · MinIO
StreamingRedpanda (Kafka-compatible)
Shared libssx-core · sx-schemas · sx-data · sx-ai
ContractsPydantic → OpenAPI → @sentri-x/contracts
ObservabilityOpenTelemetry · structlog · Prometheus / Grafana-ready

Security & tenancy

Designed for controlled, multi-tenant defense ops.

Tenant isolation for operators, data, and agent runtimes
Role-based access across mission control and response actions
Auditable agent activity for investigation and review
Private deploy paths for environments that stay inside your perimeter
Secrets and credentials kept out of specialist prompts and logs

How it works

From sensors to autonomous recovery in three steps.

01

Connect sensors & identity

Bring in estate signals and operator access so Sentri-X can see the surface it must defend.

02

Activate the defense loop

Specialists coordinate through Helix Neuralix — predicting, detecting, understanding, and preparing response.

03

Respond, recover, learn

Mission Control executes playbooks, recovers state, and feeds outcomes back into memory and models.

SENTRIX

Run cyber defense as an operating system.

Request access to Sentri-X, or explore Helix OS to see the Neuralix control plane that powers it.

Powered by Helix Neuralix by LeafCore Labs