Documentation

The condensed version lives here. The full reference — every flag, every config key — ships in the repo under docs/.

Install & enforcement

Install in trial (observation-only) mode:

$ curl -fsSL https://prosentriq.com/install.sh | sudo bash -s -- --key=psq_live_xxxx

Check status, then move to production when ready:

$ sudo prosentriq-ctl status
$ sudo prosentriq-ctl enable-enforcement
$ sudo prosentriq-ctl disable-enforcement
FlagUsed withPurpose
--keyinstall.shYour API key (required)
--ifaceinstall.shNetwork interface to attach to (auto-detected if omitted)
--modeinstall.shtrial (default) or production
--api-basebothPoint at a self-hosted Detection API instead of api.prosentriq.com
--state-dir / --log-dirbothOverride /etc/prosentriq / /var/log/prosentriq (mainly for testing)
--dry-runinstall.shValidate everything, make zero system changes

Detection API

Base URL: https://api.prosentriq.com (or your self-hosted instance).

RouteMethodPurpose
/v1/signupPOSTCreate an account, get an API key
/v1/account/statusGETConfirm a key and its tier/enforcement permission
/v1/account/recoverPOSTRotate a lost key (emailed, not returned in the response, when SMTP is configured)
/v1/reputation/checkPOSTScore a source IP
/v1/events/correlatePOSTFeed an observed event into threat correlation
/v1/rules/recommendPOSTGet a genetic-algorithm-recommended rule for an IP
/v1/rules/evolvePOSTRun a generation of rule evolution

Every account gets a rate limit appropriate to its tier; requests over the limit get a 429 with a Retry-After header, never a silent drop.

Architecture, in short

The kernel agent (eBPF probes, behavioral policy, genetic algorithm, honeypot, prosentriq-ctl) runs on your host and enforces locally. The Detection API (accounts, reputation scoring, Threat Hub, compliance reports) is a separate control-plane service — self-hostable, not a requirement for the agent's core loop to keep running.

Full component-by-component detail lives in docs/ARCHITECTURE.md in the repository, including how AccountManager reconciles the two.