Inspiration

Security teams rarely suffer from a lack of alerts. The real problem is that identity, financial, application, endpoint, network, insider, and AI-generated threats are often investigated separately. Analysts must manually determine whether several warnings are isolated events or parts of one coordinated attack.

I created TorinLabs Sentinel AI to turn fragmented security telemetry into one understandable, evidence-backed investigation. The goal is to help analysts move from raw signals to a defensible response while ensuring that consequential actions remain under human control.

What it does

TorinLabs Sentinel AI is an AI-assisted security investigation and fraud-detection platform.

The Build Week demonstration includes:

Drag-and-drop ingestion for JSON, CSV, LOG, and TXT sample data Preloaded identity, endpoint, application, and financial-fraud datasets Coverage across seven detection domains: Identity and account fraud Financial fraud Application security Endpoint and device security Network and security posture Insider and administrator risk AI-era fraud A unified risk score that changes as new evidence is analyzed Prioritized alerts with timestamps, severity levels, confidence scores, and supporting evidence A cross-domain investigation graph connecting identities, devices, IP addresses, transactions, and applications AI-generated incident narratives that explain why multiple signals may represent one coordinated attack Recommended remediation plans Human approve, reject, and modify controls Downloadable executive incident reports

The current version is a safe simulation. It does not alter real accounts, transactions, endpoints, applications, or infrastructure.

How we built it

I used Codex with GPT-5.6 to transform the initial security architecture into a working interactive application.

Codex helped me:

Define the product architecture and investigation workflow Build the responsive interface Implement drag-and-drop sample-log ingestion Model the seven security-detection domains Create severity, confidence, and risk-scoring interactions Build the incident and entity-correlation views Implement the human approval workflow Generate downloadable executive reports Test the navigation, investigation sequence, approval controls, and responsive layouts Refine and deploy the working application

The interface uses a TorinLabs visual system called Midnight Signal: deep navy operational surfaces with violet, cyan, and lime indicators that distinguish malicious activity, evidence confidence, and risk.

Challenges we ran into

The biggest challenge was controlling the project’s scope. Sentinel’s long-term vision includes many forms of fraud and cybersecurity detection, but building every production detector during Build Week would have produced an unfinished platform.

I focused instead on demonstrating one complete workflow: ingest telemetry, correlate evidence, prioritize an incident, explain the attack, recommend remediation, require human approval, and generate an executive report.

Another challenge was presenting complex security relationships without overwhelming the user. The information architecture had to serve both technical analysts and executives. I addressed this by separating the experience into four connected views: Overview, Incidents, Investigation, and Reports.

I also had to make the safety boundary unmistakable. Simulation labels and human-approval controls are displayed throughout the application so the demonstration never implies that live systems are being changed.

Accomplishments that we're proud of

I am proud that Sentinel is more than a static dashboard. It presents a coherent, interactive investigation from beginning to end.

The strongest accomplishments include:

Correlating five entity types into one investigation Representing seven security domains in one risk model Showing the evidence behind every major alert Requiring a human decision before simulated remediation Translating technical findings into an executive-ready report Creating a polished, responsive product experience under a short deadline Building and deploying the project as a solo founder

What we learned

I learned that effective security AI should not simply generate more alerts. It should reduce ambiguity.

A useful investigation system must explain what happened, show the supporting evidence, communicate uncertainty, connect events across different systems, and clearly distinguish recommendations from authorized actions.

I also learned how much faster Codex can make product iteration when the desired outcome and safety constraints are explicit. It helped me move between architecture, implementation, testing, visual refinement, and deployment while maintaining one coherent product direction.

What's next for TorinLabs Sentinel AI

The next phase is to move from simulated datasets to authorized, read-only integrations with identity providers, endpoint platforms, cloud environments, financial-risk systems, and security-information and event-management tools.

Future development will include:

Production-grade data normalization and detection pipelines Persistent investigations and audit histories Role-based access control Analyst collaboration and case management Configurable risk policies Expanded synthetic-identity and deepfake detection Evaluation frameworks for measuring detection accuracy and false positives Signed approval records and remediation audit trails Sandboxed integrations for testing response playbooks Human-approved connections to existing security-orchestration platforms

The long-term vision is for Sentinel to become an evidence-centered coordination layer for cybersecurity and fraud operations—helping organizations investigate faster without removing human accountability.

Built With

  • 5.6
  • openai
  • sol
Share this project:

Updates