SentriesAI
← SentriesAISECURITY & PRIVACY
SECURITY & PRIVACY

Security is a feature,
not a checklist.

We built SentriesAI to protect people from attackers. That means we also have to protect SentriesAI from attackers — and from ourselves. Here's exactly how we do it, layer by layer.

TLS 1.3
In transit
AES-256
At rest
argon2id
Password hashing
EU
Data residency
Looking for legal privacy policy? → privacy policy
DEFENSE IN DEPTH

Four rings of defense.

No single control is enough. We design every layer to contain failures in the layers above it. An attacker who gets past the perimeter still has three more rings to fight through — each progressively harder.

PERIMETERAPPLICATIONAUTHDATAYOURDATA
STORAGE & ENCRYPTION

Data core

If everything else fails, data stays protected.

MEASURES
→PostgreSQL encryption at rest (AES-256) via Neon
→TLS 1.3 for all traffic — HTTP redirects to HTTPS strictly
→Email content never stored — only verdict, URL hash, and scan timestamp
→Scan history auto-purges after 90 days on free plan, configurable on paid
→Full GDPR data export available to every user via self-serve endpoint
TECH STACK
PostgreSQLNeonTLS 1.3AES-256
YOUR DATA

Exactly what we keep.

No vague "we collect usage data" language. Here's the complete list — what, where, and for how long.

What we store
·Email address (for login)
·Password hash (argon2id, irreversible)
·Scan history: URL + verdict + timestamp
·Settings and notification preferences
What we don't store
·Email body content or attachments
·Passwords in any recoverable form
·Payment card numbers (handled by Stripe)
·Your Gmail address book or contacts
Where we store it
·PostgreSQL database in EU (Frankfurt region)
·Redis cache in EU for session data only
·Sentry EU for error tracking (PII scrubbed)
·Stripe EU for payment processing
How long we keep it
·Scan history: 90 days (free) / configurable (paid)
·Account data: until you delete it
·Audit logs: 30 days for security investigations
·Deleted accounts: fully purged within 24 hours
THIRD PARTIES

Every company that touches your data.

We keep this list short on purpose. Six vendors, each with a specific job and exactly what they see from your account.

VENDOR
PURPOSE
REGION
DATA SHARED
Anthropic Claude
LLM analysis for Layer 7 reasoning
US (API)
URL + page content for threat-classified pages only
Google OAuth
Gmail account connection
Global
gmail.readonly scope — never write
Stripe
Payment processing
EU
Card details handled by Stripe — we never see them
Neon PostgreSQL
Primary database
EU (Frankfurt)
Scan history, user accounts, settings
Cloudflare
DDoS protection, DNS
Global edge
Request metadata only — no payloads
Sentry
Error tracking
EU
Stack traces with PII scrubbed
RESPONSIBLE DISCLOSURE

Found a vulnerability?

Security researchers who report issues responsibly get our gratitude and public credit. Here's how the process works.

01

You find something

A vulnerability, a data exposure, a misconfiguration. Anywhere on our platform — web app, API, extension, mobile apps.

02

Email us privately

security@sentriesai.com · PGP key available. We respond within 24 hours of receipt on business days. Please don't post publicly until we've had a chance to fix it.

03

We investigate and fix

You'll get a confirmation within 24h and a timeline within 72h. Critical issues are fixed and deployed in under a week.

04

Public acknowledgment

With your permission, we'll credit you in our security acknowledgments page and publish a post-mortem once the fix is live.

SECURITY CONTACT
security@sentriesai.com
PGP key available on request · Response within 24 hours on business days
FREQUENTLY ASKED

Security questions.

Questions about security?

Security inquiries go to security@sentriesai.com. General questions and feedback go to our regular support.

Contact securityPrivacy policy →