Security & Trust

A security platform has to hold itself to a higher standard.

How we secure Sentriaguard XDR, how we handle customer data (spoiler: we don't touch it), and how to report a vulnerability.

Platform controls

Six controls, verifiable end-to-end.

Air-gapped by design

Sentriaguard XDR runs entirely inside customer infrastructure. No outbound telemetry, no vendor callbacks, no cloud analytics.

Customer-owned keys

All at-rest encryption uses customer KMS (HashiCorp Vault, AWS KMS, Azure Key Vault, or on-prem HSM). Sentriaguard never holds decryption keys.

Zero-trust access

SSO/SAML, SCIM provisioning, mandatory MFA, and per-role attribute-based access on every API surface.

Provenance-verified AI

Local LLM inference with full reasoning traces retained inside the customer perimeter for audit and replay.

Hardened runtime

Minimal container images, read-only root filesystems, seccomp/AppArmor profiles, and signed release artifacts (Sigstore + SLSA L3).

SBOM & supply chain

Signed SBOM shipped with every release. Dependencies pinned, vetted, and mirrored to customer-controlled registries.

Practices

How we operate.

Data handling

Sentriaguard staff cannot access customer telemetry. Diagnostic bundles are opt-in, redacted client-side, and encrypted to a per-support-ticket public key.

Software development

Peer-reviewed pull requests, mandatory static analysis, dependency scanning, and reproducible builds. Release candidates undergo third-party penetration testing quarterly.

Incident response

24/7 on-call. Customer-affecting security incidents disclosed within 72 hours with post-incident report, timeline, and remediation plan.

Personnel security

Background-checked engineering staff. Least-privilege access to internal systems. Annual security training and red-team exercises.

Compliance mapping

Aligned with the frameworks your auditors care about.

ISO 27001 alignedSOC 2 Type II (in progress)GDPRHIPAA alignedPCI DSS mappingNIST 800-53

Sentriaguard maintains a control matrix mapping platform capabilities to each framework. Available under NDA on request.

Coordinated disclosure

Report a vulnerability.

We welcome coordinated disclosure from security researchers. First response within 24 hours, remediation ETA within 5 business days.

PGP: 0xA1B2 C3D4 5E6F 7890
Safe harbor

Our commitments to researchers.

  • • No legal action for good-faith research.
  • • Public credit unless you request anonymity.
  • • Bug bounty for critical findings in production endpoints.
  • • Fixes shipped in coordinated disclosure window.

Need a security or compliance package?

SOC 2 letter, pen-test summary, control matrix, DPA — request via sales.