# Hostnames and firewall rules

What your network needs to allow for Sentilai to work.

## What the Endpoint Suite reaches

- **Your regional Gateway** — where all governed AI traffic goes. The exact hostname
  depends on your region and is resolved when the device registers, so you do not have to
  configure it by hand.
- **The platform API** — sign-in, device registration, policy, log upload.
- **The download host** — update checks.

The app tells you when something is unreachable: the tray icon gains an amber badge and a
banner names the host it cannot reach. That banner is the fastest way to give your network
team a precise answer.

## Everything is TLS

There is no plaintext path. If your network does TLS inspection with an internal
certificate authority, the machines need to trust that CA the same way they do for any
other service.

## Egress from the Gateway

The Gateway itself reaches the AI providers you have configured — Anthropic, OpenAI,
Azure OpenAI, Gemini — and any **routed remote MCP endpoints** you have registered. That
traffic leaves Sentilai's infrastructure, not your network.

## The blocklist you can hand over

**Policy → Egress blocklist** generates a list derived from your configured providers and
registered MCP endpoints, with **Download** and **Copy** buttons. See *Use the egress
blocklist*.