Skip to content

Privacy

What we hold, and what we refuse to hold.

A security product that is vague about its own data handling is asking for a trust it has not earned. This is the whole picture, including the parts that are inconvenient.

Last updated
14 February 2026
Controller
SentryLLM Labs Ltd
Regions
eu-central-1, us-east-1
Training on your data
Never
01

What this covers

This describes what happens to information when you use the SentryLLM marketing site, the sandbox scanner, and the console. It is written to be read, not to be defensible in isolation. Where the legal position and the plain reading differ, we have tried to say so.

SentryLLM Labs is the data controller for account information and the data processor for trace content that customers send us.

02

What we collect and why

CategoryExamplesWhyKept for
AccountName, work email, company, hashed passwordTo create a workspace and let you back into itLife of the account, then 30 days
SessionOpaque token, issue and expiry timeTo keep you signed in without re-authenticating each request14 days
Trace contentSpans, payload excerpts, findings, verdictsThis is the product. It is your data and you decide how much of it leaves your environmentYour retention setting, 7 to 90 days
Design partner enquiryEmail, company, description of your agent stackSo we can reply to you24 months, or until you ask us to delete it
Server logsIP address, user agent, request path, timestampDebugging and abuse prevention30 days

Payload capture is configurable. In the strictest mode the collector hashes payloads before they leave your network, and what we store is a fingerprint plus metadata. Detections still run, in your process, on the plain text.

03

The public sandbox scanner

Text you paste into the demo on the home page is evaluated in memory and thrown away. It is not written to a database, not logged, and not used to improve anything. The response you get back is generated from the same rule set that runs in production and nothing about it is retained.

The scanner inside the console behaves differently on purpose. That one writes a real run into your workspace, because the point of it is to produce a trace you can open in the inspector.

05

Who else touches it

We keep the list of subprocessors short deliberately, and every one is published on the security page with its role and region. We do not sell data, we do not share it with advertisers, and we do not use customer traces to train models. Not our models, not anybody else's.

We will notify customers at least 30 days before adding a subprocessor that processes trace content, which gives you time to object before it happens rather than after.

06

Where it lives

Managed cloud runs in eu-central-1 and us-east-1. You pick one at workspace creation and we do not move data between them, including for backups and including for support. If you need somewhere else, the self-hosted collector puts the whole thing inside your own boundary.

07

Your rights

Access, correction, erasure, portability, restriction, and objection. Email privacy@sentryllm.ai and we will action it within 30 days, usually much sooner because there are not many of us and the queue is short.

You can export your workspace yourself at any time from the console without asking us. If you would rather delete everything, that is a single request and we confirm in writing when the backups have rolled off.

08

If something goes wrong

We will tell affected customers within 72 hours of confirming an incident, with what we know at the time rather than waiting for a complete picture. The first notice will be incomplete and we would rather send it anyway.

Our disclosure policy for researchers is on the security page, along with the address to use and what we consider in scope.