A security platform has to hold itself to a higher standard.
How we secure Sentriaguard XDR, how we handle customer data (spoiler: we don't touch it), and how to report a vulnerability.
Six controls, verifiable end-to-end.
Sentriaguard XDR runs entirely inside customer infrastructure. No outbound telemetry, no vendor callbacks, no cloud analytics.
All at-rest encryption uses customer KMS (HashiCorp Vault, AWS KMS, Azure Key Vault, or on-prem HSM). Sentriaguard never holds decryption keys.
SSO/SAML, SCIM provisioning, mandatory MFA, and per-role attribute-based access on every API surface.
Local LLM inference with full reasoning traces retained inside the customer perimeter for audit and replay.
Minimal container images, read-only root filesystems, seccomp/AppArmor profiles, and signed release artifacts (Sigstore + SLSA L3).
Signed SBOM shipped with every release. Dependencies pinned, vetted, and mirrored to customer-controlled registries.
How we operate.
Sentriaguard staff cannot access customer telemetry. Diagnostic bundles are opt-in, redacted client-side, and encrypted to a per-support-ticket public key.
Peer-reviewed pull requests, mandatory static analysis, dependency scanning, and reproducible builds. Release candidates undergo third-party penetration testing quarterly.
24/7 on-call. Customer-affecting security incidents disclosed within 72 hours with post-incident report, timeline, and remediation plan.
Background-checked engineering staff. Least-privilege access to internal systems. Annual security training and red-team exercises.
Aligned with the frameworks your auditors care about.
Sentriaguard maintains a control matrix mapping platform capabilities to each framework. Available under NDA on request.
Report a vulnerability.
We welcome coordinated disclosure from security researchers. First response within 24 hours, remediation ETA within 5 business days.
Our commitments to researchers.
- • No legal action for good-faith research.
- • Public credit unless you request anonymity.
- • Bug bounty for critical findings in production endpoints.
- • Fixes shipped in coordinated disclosure window.
Need a security or compliance package?
SOC 2 letter, pen-test summary, control matrix, DPA — request via sales.
