Trust & Security

Security controls built around visibility, evidence, and customer oversight.

SentinelCore helps organizations assess AI-related risk while maintaining clear boundaries between validated capabilities, customer responsibilities, and future roadmap features.

Current safeguards

SentinelCore Volume 1 security controls

Tenant isolation

Customer organizations, incidents, reports, and evidence records are separated by tenant scope.

Hashed API credentials

SentinelCore stores protected API-key representations rather than retaining customer credentials in plaintext.

Protected web traffic

Public SentinelCore services use HTTPS to protect information while it travels between approved systems.

Audit and incident evidence

Security decisions, triggered rules, incidents, status changes, and reporting evidence can be recorded for review.

Controlled pilot onboarding

Pilot integrations use agreed systems, approved test cases, limited credentials, and defined customer responsibilities.

Monitor-only starting mode

Volume 1 pilots normally begin by observing and reporting risk without automatically interrupting production activity.

Pilot data handling

Use controlled and approved information.

Public demonstrations should use synthetic examples only. Confidential company data should not be submitted through the shared public demo.

Customer pilot data handling, retention expectations, approved integrations, credentials, access responsibilities, and reporting requirements are documented before onboarding begins.

Private API credentials should be delivered through an approved secure method and should never be published in documentation, source code, screenshots, or public webpages.

Transparency

What SentinelCore cannot currently promise

  • SentinelCore does not guarantee prevention of every AI security incident.
  • SentinelCore does not currently provide universal automatic discovery across every cloud, model, application, or device.
  • SentinelCore does not autonomously remediate customer systems without approved integration and policy controls.
  • SentinelCore Volume 1 is not presented as SOC 2, ISO 27001, HIPAA, FedRAMP, or regulatory certification.
  • Public demo visitors must not submit passwords, confidential records, personal health information, payment data, or trade secrets.
Security reporting

Report a suspected SentinelCore security issue.

Please provide a clear description, affected service, reproduction steps, and potential impact. Do not include unnecessary personal or confidential information.

security@inyanzasystems.com