Skip to content

Security and credentials

Our posture, with dates attached.

Two of these are finished, one is in an observation window, and one has not started. A trust page that cannot tell you which is which is not a trust page.

Last updated
14 February 2026
SOC 2 Type II
Report expected May 2026
Last pen test
November 2025
Subprocessors
4
01

Where we actually are

SOC 2 Type II observation window closes in April 2026 and the report should be available in May. ISO 27001 is scoped and not yet started. We are telling you this rather than putting two badges in a footer, because a badge with no date on it is a claim about the past.

Penetration testing is annual against the managed cloud and the collector, most recently by an external firm in November 2025. The summary letter is available under NDA and the two medium findings from it were closed in December.

If a vendor page shows you a certification logo without a date and a scope, ask for both. We would rather you did that to us as well.

02

How the product is built to fail safely

  • Detections run in your process. If our cloud is unreachable, your guardrails keep working and spans queue locally.
  • The collector is fail-open for tracing and fail-closed for enforcement, and that choice is configurable per project.
  • Payloads can be hashed or redacted at the edge before anything leaves your network.
  • Every enforcement override is recorded with the operator, the timestamp, and the span it applied to.
03

Credentials and controls

ControlStatusEvidence
SOC 2 Type IIObservation window open, report expected May 2026Auditor letter on request
ISO 27001Scoped, not startedRoadmap item for H2 2026
External penetration testCompleted November 2025, findings closedSummary letter under NDA
Encryption in transitTLS 1.3 everywhere, no downgrade pathContinuous, external scan
Encryption at restAES-256, customer-managed keys on AssuranceCloud provider attestation
Access controlSSO with SAML, enforced MFA for staff, least privilege by defaultQuarterly access review
BackupsEncrypted, daily, 35 day rolling, restore tested quarterlyRestore log on request
04

Subprocessors

That is the whole list. We add to it slowly and we notify customers 30 days before anything joins it that would process trace content.

VendorRoleRegionTouches trace content
Amazon Web ServicesHosting and managed Postgreseu-central-1, us-east-1Yes
CloudflareEdge network and DDoS protectionGlobal anycastIn transit only
PostmarkTransactional emailUnited StatesNo
StripeBilling for paid plansUnited States and IrelandNo
05

Responsible disclosure

Send findings to security@sentryllm.ai. Include enough detail to reproduce and give us a way to reach you. We acknowledge within one working day, give you an assessment within five, and we will not send a lawyer after anybody acting in good faith.

In scope: the console, the marketing site, the collector, and the SDK. Out of scope: denial of service, social engineering our staff, and reports generated by a scanner with no manual verification attached.

We do not run a paid bounty yet. We do credit researchers publicly if they want it, and we have sent a fair number of very good bottles of wine.

06

Asking us things

Security questionnaires go to security@sentryllm.ai and we answer them ourselves rather than routing them through sales. Typical turnaround is four working days for a standard questionnaire, longer if yours has nine hundred rows, which some of them do.