Vord Reasoning Engine
Vord is Sentaro's proprietary detection engine that processes tenant events through a mesh of analytical tools. It deconstructs incoming signals into tens to over one hundred proprietary indicators, routing them to specialized expert algorithms and larger reasoning models. By combining techniques from Levenshtein distance matching to machine learning models, Vord generates a single verdict with contextual reasoning before security incidents cause damage.
Message Intent Analysis
The message vector analyzes the underlying intent and relationship structure of incoming and internal emails. Rather than searching solely for known malicious links or file attachments, the engine evaluates language patterns, payment requests, executive instructions, and sender authenticity. Messages are judged based on their fit within established communication graphs, allowing Sentaro to identify payload-free social engineering and business email compromise.
OAuth Scope Governance
Sentaro provides visibility into third-party OAuth application grants across Microsoft 365 and Google Workspace. The platform catalogs every application connected to user accounts, identifying unverified publishers, scope-level permission risks, and persistent access to emails, files, and calendars. Administrators can review scope-level risks across accounts and revoke application access directly through administrative APIs.
Domain Exposure Monitoring
The identity vector monitors domain registrations across the web to identify typosquatted and lookalike domains targeting an organization's brand or supply chain. By detecting lookalike domains shortly after registration, Sentaro flags incoming emails or OAuth applications linked to these domains before attackers can launch active phishing or business email compromise campaigns.
Behavioral User Baselining
Sentaro builds individual activity baselines for every user within a tenant rather than relying on global threshold rules. The behavioral vector evaluates login timing, device usage, session context, data movement, and mailbox configurations. Anomalous actions—such as a forwarding rule created during off-hours from an unrecognized session—are scored against the specific user's baseline for automatic mitigation.
API-Based Deployment
Sentaro integrates directly into Google Workspace and Microsoft 365 using administrative application programming interfaces. Deployment completes in four minutes without requiring endpoint agents, rules maintenance, or domain name system and MX record modifications. The system scans historical tenant data to provide threat and asset visibility within 15 minutes of connection.
Automated Incident Remediation
When threats are detected, Sentaro executes automatic remediation actions defined by administrative policies. The engine can label messages directly within user mailboxes, quarantine suspicious correspondence, revoke third-party app access, end unauthorized user sessions, and remove malicious forwarding rules. Administrators can also purge matching threat messages across all tenant mailboxes in a single action.
SaaS and Shadow AI Discovery
Sentaro inspects mailbox signup trails, verification links, and receipt data to catalog all cloud applications and artificial intelligence tools used across an organization. The platform identifies chatbots, meeting notetakers, and file-sharing utilities adopted on any network or device, including abandoned accounts and tools adopted long before Sentaro's deployment.
Consent Phishing Defense
Attackers often deploy malicious cloud applications disguised as popular software or AI assistants to trick users into granting tenant access. Sentaro evaluates application registration details and publisher verification statuses alongside message analysis. When a consent request from an unverified publisher or lookalike domain is detected, the platform revokes the grant automatically.
Sovereign EU Infrastructure
Designed for European organizations, Sentaro hosts and executes its detection engine on physical infrastructure located in Sweden. All machine learning models, weights, and inference processes operate under European Union jurisdiction. This sovereign design helps regulated businesses adhere to DORA, NIS2, and AI Act requirements regarding data control and jurisdiction.
Verdict Auditing and Explanations
Every decision generated by the platform includes explicit contextual reasoning detailing why an event was labeled as a threat. Administrators can review the specific baseline deviations, confidence scores, and technical indicators behind each verdict. This auditability helps security teams verify automated decisions and provides documentation for regulatory reporting.
Historical Tenant Analysis
Upon initial connection via cloud APIs, Sentaro evaluates existing workspace data to identify hidden historical vulnerabilities. The system surfaces historic OAuth grants, lingering shadow IT accounts, and internal mailbox threats that spread prior to platform deployment, establishing an immediate historical baseline within 15 minutes of connection.