Security & compliance posture
Where we actually are.
We are a small company selling into regulated institutions. The temptation is to imply more certification than we hold. This page is the antidote: current state, what triggers the next step, and what to ask us instead in the meantime.
The short version
Sentinel holds no third-party security certification today. Not SOC 2, not ISO 27001. If a certificate is a hard procurement gate for you, we are not yet a fit, and we would rather tell you now than three meetings in.
Certification status
What triggers the audit
The first design-partner contract. A SOC 2 observation window costs real money and takes months, and running it before a single institution has committed would be spending a founder’s runway on a certificate rather than on the product. When a partner signs, the audit starts, and the dates get published here and owned.
If you are that partner and the timing matters to you, say so — it is a legitimate thing to negotiate into the agreement.
What we do have
None of this substitutes for an audit. It is what a security team can evaluate directly, today, without taking our word for it.
What to ask us instead
A questionnaire designed around certificates will not tell you much about a company this size. These questions will:
- “What leaves our network?” In a self-hosted deployment, nothing operational. Make us walk the data flow and point at the boundary.
- “Show us an evidence bundle and let us verify it ourselves.” The tooling is already public. If it does not verify, that is a finding you can generate without us in the room.
- “What does the product not do?” The security stages detect known attack families. They are defence in depth and not a solved problem, and we publish the measured numbers rather than a footnote.
- “What happens when the gate is unreachable?” A fair question for anything inline, and one we would rather answer precisely than confidently.
- “Who is accountable, and what is the escalation path?” One person. You will have their number.
If something on this page is out of date, it is a bug. Tell us and we will fix it.
Design partners
Bring your security questionnaire anyway.
We would rather work through it and mark the honest gaps than have you discover them later. The gaps are the reason the first three partnerships are priced as partnerships.