Trust

What we do, and what we do not claim.

Specific, checkable, and no further.

This page states practices that are built and tested, says plainly what is not claimed, and points to the legal documents whose status is shown honestly.

Payment on the provider's page

Card details are entered only on the payment provider's own hosted pages. Sentinel never receives, stores or asks for them, and never will by email.

One-time links are stored as digests

Verification and invitation links work once and expire. Only a keyed digest of each link is stored, never the link itself.

Your estate is yours

Each organisation's data is separated by tenant on every read and write, and the separation is exercised by tests on every change.

A billing problem never switches protection off

A failed payment or an ended subscription limits what you can add. Monitoring, your evidence, incidents, logs and Guard state keep working and are retained.

Roles are per organisation

Owner, commander, analyst and viewer apply to one organisation. Someone who owns their own account has no authority over another's, and an organisation always keeps at least one owner.

Changes are recorded

Team changes, billing events and acceptance of legal documents are written to an audit record.

Not claimed

The limits of this page.

  • No security certification or audit attestation is claimed.
  • No compliance standard is claimed to be met.
  • No guarantee of uptime or of detection is made on this page.

Legal documents

Their status is shown, never assumed.

A document is shown as binding only when an approved version has been published. Until then each page says it is under review.

Terms of ServicePrivacy Notice