Skip to main content

Hostnames and firewall rules

What your network needs to allow for Sentilai to work.

What the Endpoint Suite reaches

  • Your regional Gateway — where all governed AI traffic goes. The exact hostname depends on your region and is resolved when the device registers, so you do not have to configure it by hand.
  • The platform API — sign-in, device registration, policy, log upload.
  • The download host — update checks.

The app tells you when something is unreachable: the tray icon gains an amber badge and a banner names the host it cannot reach. That banner is the fastest way to give your network team a precise answer.

Everything is TLS

There is no plaintext path. If your network does TLS inspection with an internal certificate authority, the machines need to trust that CA the same way they do for any other service.

Egress from the Gateway

The Gateway itself reaches the AI providers you have configured — Anthropic, OpenAI, Azure OpenAI, Gemini — and any routed remote MCP endpoints you have registered. That traffic leaves Sentilai's infrastructure, not your network.

The blocklist you can hand over

Policy → Egress blocklist generates a list derived from your configured providers and registered MCP endpoints, with Download and Copy buttons. See Use the egress blocklist.