Privacy
What we hold, and what we refuse to hold.
A security product that is vague about its own data handling is asking for a trust it has not earned. This is the whole picture, including the parts that are inconvenient.
- Last updated
- 14 February 2026
- Controller
- SentryLLM Labs Ltd
- Regions
- eu-central-1, us-east-1
- Training on your data
- Never
What this covers
This describes what happens to information when you use the SentryLLM marketing site, the sandbox scanner, and the console. It is written to be read, not to be defensible in isolation. Where the legal position and the plain reading differ, we have tried to say so.
SentryLLM Labs is the data controller for account information and the data processor for trace content that customers send us.
What we collect and why
| Category | Examples | Why | Kept for |
|---|---|---|---|
| Account | Name, work email, company, hashed password | To create a workspace and let you back into it | Life of the account, then 30 days |
| Session | Opaque token, issue and expiry time | To keep you signed in without re-authenticating each request | 14 days |
| Trace content | Spans, payload excerpts, findings, verdicts | This is the product. It is your data and you decide how much of it leaves your environment | Your retention setting, 7 to 90 days |
| Design partner enquiry | Email, company, description of your agent stack | So we can reply to you | 24 months, or until you ask us to delete it |
| Server logs | IP address, user agent, request path, timestamp | Debugging and abuse prevention | 30 days |
Payload capture is configurable. In the strictest mode the collector hashes payloads before they leave your network, and what we store is a fingerprint plus metadata. Detections still run, in your process, on the plain text.
The public sandbox scanner
Text you paste into the demo on the home page is evaluated in memory and thrown away. It is not written to a database, not logged, and not used to improve anything. The response you get back is generated from the same rule set that runs in production and nothing about it is retained.
The scanner inside the console behaves differently on purpose. That one writes a real run into your workspace, because the point of it is to produce a trace you can open in the inspector.
Legal basis
- Contract, for anything required to give you the account and service you signed up for.
- Legitimate interest, for server logs, abuse prevention, and replying to an enquiry you sent us.
- Consent, for the design partner mailing list, which you can withdraw with one reply.
- Legal obligation, for the small amount of billing records we are required to retain.
Where it lives
Managed cloud runs in eu-central-1 and us-east-1. You pick one at workspace creation and we do not move data between them, including for backups and including for support. If you need somewhere else, the self-hosted collector puts the whole thing inside your own boundary.
Your rights
Access, correction, erasure, portability, restriction, and objection. Email privacy@sentryllm.ai and we will action it within 30 days, usually much sooner because there are not many of us and the queue is short.
You can export your workspace yourself at any time from the console without asking us. If you would rather delete everything, that is a single request and we confirm in writing when the backups have rolled off.
If something goes wrong
We will tell affected customers within 72 hours of confirming an incident, with what we know at the time rather than waiting for a complete picture. The first notice will be incomplete and we would rather send it anyway.
Our disclosure policy for researchers is on the security page, along with the address to use and what we consider in scope.