Case file
October 4, 2026 ★ Featured REF/SENTINEL

Sentinel

Crisis messenger and offline situation map that keeps working when the internet and cell towers are down.

FlutterBLE24h
Wiktor Rzepka
Jakub Nowak
Kacper Doniec

Sentinel

Sentinel is a messenger and a live situation map for the moment when normal communication goes dark. If the mobile network and the internet get knocked out by a blackout or sabotage, phones running Sentinel find each other over Bluetooth Low Energy (Adhoc planned), keep copies of what they receive and hand it on to the next device in range.

Screenshot: HQ console

The idea

Most emergency apps assume there is still a network somewhere. We wanted to see how far you can get without one. Every phone becomes a small relay: it stores the packets it has seen, and whenever it meets another phone the two of them swap whatever the other one is missing. A message can reach someone a few streets away by hopping through strangers’ pockets.

That raises two hard questions, and most of the work went into answering them:

  1. Who do you trust when anyone can broadcast anything and there is no server to check with?
  2. How do you keep people safe when their messages and locations travel through other people’s phones?

What it does

  • Private chats and groups. One-on-one conversations and groups, with message content encrypted end to end. Relays carry the ciphertext but can’t read it. You join a private group by scanning a QR code.
  • Offline map of Kraków. The map tiles ship inside the app, so the map works with zero connectivity. Inside private groups you can choose to share your position with people you trust. Shared positions expire after 15 minutes.
  • Reports. Anyone can report something on the map: a blocked bridge, a fire, a water distribution point. Reports about the same place get grouped together.
  • Official alerts. Emergency services can broadcast alerts with a zone on the map. Each alert is signed, and every phone checks the signature on its own, offline. A fake alert gets rejected and isn’t passed on.
  • SOS. Hold the button and your position goes out with top priority. Everyone nearby sees a pulsing marker with the time and distance.
  • HQ console. A desktop view for a command post with the map, active SOS calls, conflicting reports, the live network topology and a log of the packets passing through.
Screenshot: map with nearby events

Fake news without a server

This is the part I like the most. In a crisis, false reports spread fast, and “lots of people said so” isn’t proof of anything. Somebody could easily create a dozen fake identities.

So Sentinel doesn’t let the crowd decide. Each device scores reports about the same place locally. When reports contradict each other (“the bridge is fine” vs. “the bridge is destroyed”), the place is marked as conflicting instead of picking a winner by vote count. Only a signed alert from the services can mark something as confirmed, and once that happens the conflicting reports are flagged as suspect.

Screenshot: conflicting reports about a bridge

On the HQ console the same conflict shows up in a side panel, and a commander can resolve it with one click. The alert is signed with their role key and sent out to the network.

Screenshot: HQ console with a conflict Screenshot: HQ console after a signed alert

Trust works as a simple chain: a ROOT key issues certificates for roles (for example a fire brigade commander), and the role key signs the alert. Every phone knows the ROOT public key, so it can check the whole chain by itself.


Privacy

We tried to make the safe option the default one:

  • You’re invisible on the network until you decide to turn visibility on.
  • Locations are only shared inside private groups, only if you opt in, and they expire.
  • The Bluetooth tag is random on every app start.
  • The first message from a stranger lands in a separate “requests” box, so nobody can just start talking to you.
Screenshot: private group Screenshot: alerts list

What’s next

What we have works end to end, but it’s a hackathon build. To make it usable for real we’d need:

  • running in the background and storing keys in Keychain / Keystore,
  • adhoc connection, ble as a secondary option,
  • range tests in the field and fixed relay nodes,
  • a pilot with a local municipality and fire brigade,
  • LoRa links between districts and an internet gateway for when the connection comes back,
  • identity tied to mObywatel (“one citizen, one key”), key revocation and hiding metadata.