Regulatory intelligence is built on trust. Sentinaly is designed so that your data is protected at every stage - from creation to storage - using industry-leading security standards. This page describes the technical and organizational measures we apply.
End-to-end encryption
All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Encryption keys are managed through a dedicated key-management service with strict rotation and access policies, in line with GDPR Articles 25 and 32 and ISO/IEC 27018.
Strict data isolation
Each customer's information is held in a logically isolated environment. Tenant boundaries are enforced at the storage, application and model layers so that data from one organization is never visible to, or used to serve, another.
User-controlled access
You decide who can see what. Granular, role-based permissions, single sign-on support and detailed audit logs give administrators full control over access to workspaces, modules and outputs.
Certifications and compliance
- SOC 2 Type I and Type II - independently audited controls for security, availability and confidentiality.
- ISO 27001 - certified information security management across our infrastructure.
- GDPR & DIFC Data Protection Law - privacy-by-design and privacy-by-default across our Services.
- ISO/IEC 27018 - protection of personal data in public cloud environments.
Data residency and sub-processors
Customer data is hosted on enterprise cloud infrastructure (AWS, Microsoft Azure and Google Cloud) in regions agreed with each customer. A current list of sub-processors and hosting regions is available on request.
Incident response
We maintain a documented incident-response process with continuous monitoring, defined escalation paths and customer notification within the timeframes required by applicable law, including the 72-hour GDPR breach notification window.
Data subject requests and deletion
We support customers in fulfilling data subject requests and delete or return customer data at the end of the contractual relationship, subject to legally required retention. See our Privacy Policy for details on personal data handling.
Security enquiries
To request our security documentation, a Data Processing Agreement or to report a vulnerability, contact contact@sentinaly.com.