Licence Agreement
This document describes precisely what your voucher does, how activation behaves, and what the Software does to itself when things go wrong. It is written against the actual implementation, not an aspiration.
1. The grant
A Voucher you have paid for and that has been issued to you conveys a personal, non-exclusive, non-transferable, revocable licence to install and execute one copy of the SentinelX daemon (the Software) on a number of concurrently active Nodes equal to the binding limit recorded on the Portal for that Voucher, until the earlier of the Voucher expiry date or the termination of this Agreement.
No Voucher confers any right to the source code, to the trademark beyond nominative use, or to resell, sub-licence or redistribute the Software. A single Voucher may not be published or exposed in a public repository, forum, marketplace or tutorial.
2. Activation
On first start the Software computes a Machine Fingerprint by taking the SHA-256 hash of the concatenation of, in order: the first line of the operating system machine identifier file; the MAC address of the first non-loopback network interface; and the system hostname. The first sixteen characters of that fingerprint are displayed so you can compare them with our records.
The Software then sends the Portal:
- the Voucher code you type in, and
- the Machine Fingerprint.
- If the local licence file is missing or its signature fails, the daemon logs the reason and stops.
- If the Machine Fingerprint no longer matches the bound one, the daemon logs and stops.
- If the Portal reports the Voucher as invalid, revoked or expired, the daemon logs the reason, waits 60 seconds, then stops.
- mark its own binary immutable with
chattr +i; - hash its binary, its configuration file, and a short list of security-critical host files including
/root/.ssh/authorized_keys,/etc/crontaband cron entries, and alert when any of them change or disappear; - terminate, quarantine or delete files and suspend game servers that match its malware heuristics;
- insert and remove firewall rules for blocked IP addresses;
- write state files under
/etc/sentinelx*and its own log.
If validation succeeds the Software writes a licence file to
/etc/sentinelx.lic containing the Voucher, the fingerprint and an
HMAC-SHA256 signature, with filesystem mode 0600. The signature makes local tampering
detectable: the Software refuses to start if the file has been edited.
3. The three-attempt lockout
A failed attempt is any activation where the Portal does not return
valid: true, including an empty submission and a
network failure. Because of this, we strongly recommend verifying a Voucher on the
Check Licence page before typing it in, and typing it
exactly as issued.
If the lockout is triggered accidentally, the Software is reinstalled from the repository. No other files on the host are modified by the lockout. We may, at our discretion, issue a replacement Voucher where the failure was clearly not an attempt to guess credentials.
4. Node binding and migration
A Voucher is bound to the Machine Fingerprint of the Node that activates it. Once the binding limit is reached, validation requests from a different fingerprint are refused
To move a licence, release it from the old Node by sending
/sentinelx deactivate to the SentinelX Telegram bot on that Node,
or by deleting /etc/sentinelx.lic and issuing the deactivation
request from the Portal API. The binding is then available for the new Node.
Deactivating on a Node does not disable that Node’s copy of the Software as software; it releases the licence claim so the Voucher can bind elsewhere. Re-activation on the same Node after deactivation is permitted.
5. Revalidation and revocation
After activation, the Software revalidates against the Portal every 86400 seconds (24 hours). On each revalidation:
6. Self-protection behaviour
The Software protects itself on your host and you consent to that as part of activation. It will:
These actions are performed with root privilege because the protection they provide cannot function otherwise. They can affect running services, so review the configuration and the documentation before enabling the Software on a production host. If the binary is removed while running, it will be reinstalled by systemd only if you restore it; the Software cannot restore itself.
7. Verification, tampering and circumvention
Verifying a licence signature, and any attempt to remove, disable or circumvent the validation, the self-protection or the node-binding mechanisms, is prohibited. Persistent circumvention results in revocation without refund. Where the restriction is prohibited by law, your statutory rights are unaffected.
8. Updates and versions
New versions may be released during your Term. We do not guarantee a specific release cadence, that any version will be available for your Term, or that a release will be compatible with your Panel version. A Voucher authorises running any version we provide during its Term; it does not entitle you to a particular version indefinitely.
9. Warranty and liability
The licence is granted on an as is and as available basis. To the fullest extent permitted by law we disclaim all implied warranties, including merchantability, fitness for a particular purpose and non-infringement. We do not warrant that the Software will detect, prevent or mitigate any particular threat, nor that it is error-free or uninterrupted.
Our aggregate liability under this Agreement is limited to the amount you paid for the Voucher concerned. Nothing here excludes liability that cannot lawfully be excluded, or limits any consumer guarantee that may apply to you by mandatory local law.
10. Termination
This Agreement ends automatically when the Term expires, when the Voucher is revoked, or when you materially breach it. On termination the right to run the Software ends and the Portal will refuse further validation for the Voucher.
11. Governing law
This Agreement is governed by the laws of the Republic of Indonesia and the courts of Jakarta have exclusive jurisdiction, unless a written order between us states otherwise.