About Ephemeral Sentinel

Clarity over complexity. Answers over dashboards.

Patrick Donohue
IT Infrastructure & Cybersecurity — Spokane, WA

35 years in IT infrastructure and cybersecurity, most recently in the financial sector. Author of API-ocalypse Now: Python's Guide to Secure and Flexible Data Handling. Builder of tools that solve problems I've actually run into.

Most organizations train employees to report phishing — and then do nothing with the reports. Ephemeral Sentinel exists to fix that.

I've spent 35 years in operational environments. The phishing response failure is not hypothetical. Reporting mailboxes sit unreviewed in most places I've worked in or assessed. Analysts are stretched across more urgent priorities. End users click Report Phish and receive silence. After a few rounds of that, they stop reporting.

The problem is structural. Manual triage at scale doesn't work. There are never enough analysts and there never will be. The queue grows faster than it can be reviewed. Meanwhile, the employees who were asked to be the last line of defense have learned that their reports disappear into a void.

Existing tools address detection — blocking threats before they reach users. That's their job and they do it well. But none of them respond to the user who has already received something and is asking a question. The feedback loop stays open.

Ephemeral Sentinel closes it. Every reported email gets analyzed automatically and a plain-language explanation goes back to the person who reported it. The analysis runs locally, on infrastructure you control. Nothing is sent to a third party. Email content is processed in memory and discarded — no archive, no retention, no data liability. The analysis is deterministic: the same email always produces the same result, and every verdict can be traced to a named signal.

It won't replace your security team. It will close the one loop your security team doesn't have time to close manually — and do it consistently, for every report, regardless of how many come in.

This is the ArcForgeLabs philosophy in practice: build tools that give you clear answers rather than more surfaces to monitor. Deterministic where it can be. Transparent about what it finds and why. No vendor lock-in on analysis logic.


Also from the same shop

Surface Sentinel

A passive external reconnaissance tool. Answers the question an attacker would ask before targeting your organization: what's publicly visible about your domain? DNS, email authentication, TLS, exposed services — plain-language output, no credentials required.

Learn more →

Questions or feedback: info-sentinel@arcforgelabs.com

Built by ArcForgeLabs