Sentinel Hub home

For institutions

Governance that scales from one course to a whole campus

Sentinel Hub is multi-tenant from the ground up: every school, department, class, and lab gets its own isolated users, models, devices, limits, and reports. Start with a single course. Grow by adding tenants — not by renegotiating anything.

Office by office

Built for the offices that have to say yes

Procurement
One gateway account replaces a shifting roster of per-student subscriptions and personal-card reimbursements. Budgets live where they belong — as server-enforced quotas on tenants and keys, with cost estimates recorded per request — so spending questions are answered by a report, not a shoebox of receipts.
Information technology
Students work through a browser dashboard and the official WireGuard client — the industry-standard VPN protocol, not custom software. The private AI API is unreachable from the public internet, internal services stay unexposed, and provider credentials are encrypted and never touch a student machine. Suspending a key, device, or tenant takes effect across the API promptly.
Academic oversight
Administrators see who is using AI, which models, and how much capacity — filterable by date, model, key, and device. Logging is metadata-only by default: model, tokens, cost, status, request ID. Prompts and responses are not retained unless your institution explicitly enables and discloses that policy. An acceptable-use framework covers academic integrity, privacy, and prohibited uses.

The alternative

Sentinel Hub vs. enterprise chat licensing

Enterprise chat licenses are easy to buy and easy to under-use: students already have free chat models, so a seat license largely duplicates what the classroom already has. A gateway funds what coursework actually demands — API access students can build against, on models the institution chooses.

Capability Enterprise chat license Sentinel Hub gateway
Chat with frontier models Included Included — full API access
Build real applications against an API Not included OpenAI-compatible endpoints
Multiple providers behind one interface Single vendor Routes to any approved provider
Per-student and per-app limits Seat-based, not metered Quotas on keys, devices, and tenants
Local and open models Not included Ollama-hosted models, same API
Usage attributable to course and project Aggregate seats Per-key, per-device reporting
Pay only for what’s used License expires Metered per request

Trust, stated plainly

What we promise every campus

Provider credentials are encrypted and never shown to students or third-party applications — students receive Sentinel keys, not provider keys. Every application key and every enrolled device is separately revocable. Tenants cannot see each other’s data, models, devices, keys, or usage records.

Every request is checked for tenant, key, device, model, quota, and policy before it reaches a provider. Errors come back sanitized, with a request ID that lets support trace the problem without ever asking a student for a key or a prompt. Secure behavior is the easiest behavior — by design.

Start with one course