Trust
Trust & Security
Last updated: 2026-06-29
Security is central to Senthorion. This page describes how we design, operate, and continuously improve the security of our platform. We intentionally avoid publishing implementation details that could aid attackers.
1. Our security approach
Senthorion is a multi-tenant cybersecurity platform. We build security into product design, infrastructure, and day-to-day operations. Our controls are proportionate to the sensitivity of customer data and the threats our customers face.
We review and improve our security program as the platform, regulatory landscape, and threat environment evolve.
2. Platform safety
We apply secure-by-design principles across the Senthorion application, APIs, workers, and supporting services. Security considerations are integrated into development, deployment, and change management.
Organization administrators can review security-relevant settings within the product, including authentication options, access controls, and integration permissions.
3. Authentication and access control
Access to the Service requires authenticated accounts. We support modern authentication practices, including multi-factor authentication (MFA), and apply controls designed to mitigate credential stuffing, brute-force attacks, and unauthorized access.
Senthorion is organization-scoped by design. Customer data is logically separated and accessible only to authorized users within the owning organization, subject to role-based access controls configured by that organization.
4. API keys and credential safety
API keys, worker tokens, and integration credentials are sensitive secrets. Customers should store them securely, rotate them regularly, and limit scope to the minimum required.
We recommend configuring security contacts within your organization so the appropriate individuals receive alerts about credential exposure, suspicious activity, or other account safety events.
If you believe a Senthorion credential has been exposed, revoke and rotate it immediately and contact security@senthorion.com.
5. Password and session safety
We enforce password policies designed to reduce the risk of account compromise, including checks against commonly breached or weak passwords where appropriate.
Sessions are protected with industry-standard mechanisms. We monitor for anomalous sign-in activity and apply safeguards to reduce session hijacking risk.
6. Encryption
Traffic between users and Senthorion is encrypted in transit using industry-standard TLS. Customer data at rest is protected using encryption provided by our cloud infrastructure providers and additional application-level protections where appropriate.
7. Infrastructure and operational security
Our operational security practices include:
- Least-privilege access for internal systems and production environments.
- Segregation of development, staging, and production environments.
- Secrets management through dedicated secure configuration channels.
- Logging, monitoring, and alerting suited to detecting and investigating unusual activity.
- Vulnerability management and patch processes for platform components.
- Backup and recovery procedures appropriate to service continuity requirements.
8. Data lifecycle
We retain customer data in accordance with product configuration, plan terms, and contractual obligations. For more information about data handling and retention, see our Privacy Policy.
9. AI safety
When AI-assisted features are enabled, we apply safeguards designed to reduce exposure of sensitive information before requests are sent to AI providers. Customer data is not used to train third-party foundation models without authorization.
10. Compliance
Senthorion includes in-product compliance workflows aligned with recognized industry frameworks. Formal external attestations and certifications are pursued through staged audit programs and announced when achieved.
Customers requiring specific compliance documentation (such as a DPA or subprocessor list) may contact legal@senthorion.com or privacy@senthorion.com.
11. Responsible disclosure
We welcome responsible reports of potential security vulnerabilities. If you believe you have found a security issue affecting Senthorion:
- Email security@senthorion.com with a clear description, steps to reproduce, affected URLs or components, and potential impact.
- Allow reasonable time for us to investigate and remediate before public disclosure.
- Do not access, modify, or delete data belonging to other customers.
- Do not perform denial-of-service attacks, social engineering against our staff or customers, or physical security testing.
- Do not exploit a vulnerability beyond what is necessary to demonstrate the issue.
We aim to acknowledge valid reports within five business days. We may recognize researchers who report qualifying issues in good faith, at our discretion.
12. Incident response
We maintain internal incident response procedures to investigate suspected security events. If an incident materially affects customer data, we notify impacted customers and regulators as required by law and contractual obligations.
13. Report a security concern
For security vulnerabilities, suspected abuse, or platform safety concerns, contact security@senthorion.com.
For general support: support@senthorion.com.
Please do not publicly disclose unresolved security issues until we have had an opportunity to review and address them.