Security & Compliance

Enterprise Security, Built In

SENTINEL-X is designed from the ground up for enterprise security requirements — so your CISO can say yes.

Certifications & Compliance

SOC2 Type II

Annual third-party audit of our security, availability, and confidentiality controls.

GDPR Compliant

Full data subject rights, DPA available, EU data residency option.

ISO 27001

Information security management system certified by accredited body.

HIPAA Ready

BAA available for healthcare customers. PHI never stored in our systems.

Security Architecture

🔒

Encryption at Rest & Transit

AES-256 encryption for stored data. TLS 1.3 for all data in transit. Keys managed via AWS KMS / GCP KMS.

🔒

RBAC & SSO

Role-based access control with custom roles. SAML 2.0 and OIDC SSO integrations for Okta, Azure AD, Google Workspace.

🔒

Audit Logs

Immutable, tamper-evident audit logs for every action. Exportable for compliance reviews and incident investigation.

🔒

VPC & On-Premise Deployment

Deploy SENTINEL-X entirely within your own VPC or on-premise. No data leaves your infrastructure.

🔒

Penetration Testing

Annual third-party penetration tests. Results available to Enterprise customers under NDA.

🔒

Incident Response

99.9% uptime SLA. 24/7 security monitoring. Breach notification within 72 hours as required by GDPR.

Data Handling Practices

We never train our models on your data.
Evaluation run data is isolated per tenant with cryptographic separation.
You can delete all your data at any time — deletion is immediate and irrecoverable.
EU data residency is available for GDPR-sensitive deployments.
Sub-processors are listed in our DPA and reviewed quarterly.
Data retention defaults to 90 days; configurable to 1 day in Enterprise.

Security questions? Talk to our team.

We're happy to provide our security questionnaire, SOC2 report, or pen test results under NDA.

Contact Security Team