Privacy Policy

Last updated: February 18, 2026

1. Introduction

Sentrafort, Inc. (“Sentrafort,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, retain, and safeguard information when you visit our website at sentrafort.com, use our cloud security platform, or interact with us through any other channel.

This policy applies to all users of the Sentrafort platform, including administrators, team members, and any individual whose personal data is processed in connection with our services. By accessing or using our services, you acknowledge that you have read, understood, and agree to the practices described in this policy. If you are using the Sentrafort platform on behalf of an organization, you confirm that you are authorized to accept this policy on behalf of that organization.

Sentrafort acts as a data processor on behalf of our enterprise customers with respect to the cloud infrastructure data, security findings, and configuration metadata that customers submit to or scan through the platform. For personal data of our customers' end-users that may appear in scan results, our customers are the data controllers, and we process such data in accordance with our Data Processing Agreement (“DPA”). For personal data we collect directly from you (such as account registration data), Sentrafort acts as the data controller.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account, subscribe to a plan, or contact our support team, you provide us with information such as your full name, business email address, job title, company name, billing address, phone number, and payment method details. If you participate in surveys, webinars, or request a product demo, we may collect additional details relevant to that interaction, such as your company size, cloud environment, and security priorities.

When you configure cloud account integrations (AWS, Azure, GCP), you provide read-only credentials, role ARNs, or OAuth tokens that enable Sentrafort to perform security scans on your behalf. These credentials are encrypted at rest and in transit and are used exclusively to deliver our services.

2.2 Usage and Interaction Data

We automatically collect data about how you interact with the Sentrafort platform, including pages visited, features used, security scan configurations, dashboard filter preferences, alert acknowledgments, and search queries. We also record the frequency, timing, and duration of your sessions. This data helps us understand product engagement, identify usability issues, and improve our security analytics capabilities.

For customers using our Vigil runtime protection module, we collect telemetry data from deployed agents, including agent health metrics, policy evaluation counts, and enforcement actions. This telemetry data does not include the content of your workloads but may include metadata such as resource identifiers and event timestamps.

2.3 Technical and Device Data

When you access our website or platform, we automatically collect technical data including your IP address, browser type and version, operating system, device type, screen resolution, referring URL, and language preferences. We also collect network-level information such as connection type and approximate geographic location derived from your IP address. This information is used for security monitoring, fraud prevention, and service optimization.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service delivery: To provide, operate, and maintain the Sentrafort cloud security platform, including running security scans, generating findings, producing compliance reports, and delivering real-time alerts.
  • Account management: To create and manage your account, process subscription upgrades and downgrades, handle billing and invoicing, and verify your identity when you contact support.
  • Product improvement: To analyze usage patterns, diagnose technical issues, test new features, and improve the performance, reliability, and user experience of our platform.
  • Security operations: To detect and prevent fraud, abuse, unauthorized access, and other security threats to both the Sentrafort platform and our customers' connected environments.
  • Communications: To send transactional emails such as password reset confirmations, billing receipts, scan completion notifications, and critical security alerts. With your consent, we may also send product updates, educational content, and marketing materials.
  • Customer support: To respond to your inquiries, troubleshoot issues, provide technical guidance, and deliver onboarding assistance.
  • Legal compliance: To comply with applicable laws, regulations, legal processes, or governmental requests, including tax reporting, anti-money laundering requirements, and export control obligations.
  • Aggregated analytics: To generate anonymized, aggregated insights about cloud security trends, misconfiguration prevalence, and threat landscape intelligence. These insights never contain personally identifiable information and may be used in published research or marketing materials.
  • Contractual obligations: To enforce our Terms of Service, process Data Processing Agreement requests, and manage enterprise contract obligations.

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes. We do not use your cloud security scan data to train machine learning models for other customers or any purpose unrelated to delivering our services to you.

5. Data Sharing & Third Parties

We share your personal data only with trusted third parties who require it to help us operate, improve, and deliver our services. All sub-processors are bound by contractual obligations that require them to protect your data to standards equivalent to or exceeding those described in this policy. We maintain an up-to-date list of sub-processors and will notify customers of any changes at least 30 days in advance.

Our current sub-processors include:

Sub-ProcessorPurposeLocation
Amazon Web Services (AWS)Cloud hosting, data storage, compute infrastructureUS, EU
Stripe, Inc.Payment processing, subscription billing, invoicingUS
Twilio SendGridTransactional and marketing email deliveryUS
Datadog, Inc.Application performance monitoring, logging, error trackingUS, EU
Auth0 (Okta)Authentication, SSO, and identity managementUS, EU

We may also disclose your information if required to do so by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a lawful government request. In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections described in this policy.

6. International Data Transfers

Sentrafort is headquartered in the United States and operates infrastructure globally. Your personal data may be transferred to, stored in, and processed in countries other than your country of residence, including the United States, where data protection laws may differ from those in your jurisdiction.

For transfers of personal data from the EEA, United Kingdom, or Switzerland to the United States, Sentrafort relies on Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Implementing Decision (EU) 2021/914) and, for UK transfers, the UK International Data Transfer Addendum. Sentrafort is not currently a participant in the EU-U.S. Data Privacy Framework; if we complete a DPF self-certification in the future, we will update this policy and our DPA accordingly.

Our DPA includes the SCCs as an annex, and copies are available upon request. We also conduct transfer impact assessments to evaluate and mitigate risks associated with international data transfers, including supplementary measures such as encryption and access controls.

Customer data is currently stored and processed in the United States. Regional data residency (for example, EU or Asia-Pacific storage) is on our roadmap and is not yet available. If regional residency is a requirement for your organization, please contact privacy@sentrafort.com and we will share current status and timelines.

7. Data Security

We implement comprehensive technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security program is designed to meet the requirements of enterprise customers operating in regulated industries.

Encryption: All data in transit is protected using TLS 1.3 with forward secrecy. Data at rest is encrypted using AES-256 encryption. Cryptographic keys are managed through AWS Key Management Service (KMS) with automatic key rotation. Database backups and log archives are encrypted using separate key hierarchies.

Certifications and audits: Sentrafort's SOC 2 Type II audit is planned for Q3 2026. Until the audit completes and the report issues, Sentrafort does not hold SOC 2 Type II certification; the controls that will be examined by the auditor are documented and operationally active today. The planned audit scope covers security, availability, and confidentiality trust service criteria. Sentrafort will publish the issued report (under NDA) to enterprise customers when available. For the canonical certification roadmap, see the Security page.

Penetration testing: We engage independent security firms to conduct comprehensive penetration testing of our platform at least annually, with additional targeted assessments following significant infrastructure changes. Findings are remediated on a risk-prioritized basis, with critical and high severity issues addressed within 48 hours.

Access controls: Access to customer data is restricted to authorized personnel on a need-to-know basis, enforced through role-based access control (RBAC), multi-factor authentication (MFA), and just-in-time privileged access management. All access to production systems is logged and reviewed. Employee access is revoked immediately upon termination or role change.

Infrastructure security: Our platform runs on isolated, hardened infrastructure within AWS. We employ network segmentation, web application firewalls, intrusion detection systems, and 24/7 security monitoring. Tenant data is logically isolated using row-level security controls, ensuring that no customer can access another customer's data.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods vary by data type:

Data TypeRetention Period
Account and profile dataDuration of subscription + 90 days
Security scan findings and reportsPer customer-configured retention policy (default: 12 months)
Audit logs7 years (regulatory compliance)
Billing and transaction records7 years (tax and financial regulations)
Support tickets and communications3 years after resolution
Platform usage analytics24 months (aggregated, then anonymized)
Server and access logs12 months
Marketing consent recordsDuration of consent + 3 years

Upon termination of your subscription, you may export your data within 90 days using our built-in export functionality or by submitting a request to support@sentrafort.com. After the 90-day post-termination period, your data will be securely deleted from our production systems. Backup copies may persist in encrypted backup archives for up to an additional 30 days before being purged through our automated backup rotation process.

Enterprise customers may negotiate custom retention periods and data deletion schedules as part of their service agreement. Contact your account manager for details.

9. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data. Sentrafort is committed to honoring these rights in accordance with applicable data protection laws, including the GDPR, UK GDPR, and CCPA/CPRA.

  • Right of access: You may request a copy of the personal data we hold about you, along with information about how it is processed, the purposes of processing, and the categories of recipients.
  • Right to rectification: You may request that we correct inaccurate or incomplete personal data. You can also update most account information directly through the platform settings.
  • Right to erasure: You may request that we delete your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent, or where processing is unlawful. Certain data may be retained where required by law or for the establishment, exercise, or defense of legal claims.
  • Right to data portability: You may request a copy of your personal data in a structured, commonly used, machine-readable format (JSON or CSV), and you have the right to transmit that data to another controller without hindrance.
  • Right to restrict processing: You may request that we restrict the processing of your personal data while we verify its accuracy, while we assess a request to erase data, or if processing is unlawful but you oppose erasure.
  • Right to object: You may object to the processing of your personal data where we rely on legitimate interests as the legal basis, including profiling based on those interests. You may also object to the processing of your data for direct marketing purposes at any time.
  • Right to withdraw consent: Where processing is based on your consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
  • Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe your data protection rights have been violated.

To exercise any of these rights, please submit a request to privacy@sentrafort.com or use the “Privacy Request” form in your account settings. We will respond to verified requests within 30 days (or sooner where required by law). We may request additional information to verify your identity before fulfilling a request. We will not discriminate against you for exercising your privacy rights.

11. Children's Privacy

The Sentrafort platform is a business-to-business enterprise security service and is not directed at individuals under the age of 16. We do not knowingly collect or solicit personal data from anyone under the age of 16. If we learn that we have collected personal data from a child under the age of 16 without verification of parental consent, we will take immediate steps to delete that information.

If you are a parent or guardian and believe that your child has provided personal data to Sentrafort, please contact us immediately at privacy@sentrafort.com so that we can take appropriate action. In jurisdictions where the age of digital consent is higher than 16 (e.g., 18 in certain EU member states), we apply the higher threshold.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information. This section supplements the rest of this Privacy Policy with information required by California law.

Categories of personal information collected: Over the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA: identifiers (name, email, IP address), commercial information (subscription and billing history), internet or electronic network activity (usage data, log data), professional or employment-related information (job title, company), and inferences drawn from the above categories.

No sale or sharing of personal information: Sentrafort does not sell your personal information as defined by the CCPA. We do not share your personal information for cross-context behavioral advertising purposes. We do not use or disclose sensitive personal information for purposes other than those permitted under the CCPA.

Your California rights: As a California resident, you have the right to: (a) request disclosure of the categories and specific pieces of personal information we have collected about you; (b) request deletion of your personal information; (c) request correction of inaccurate personal information; (d) opt out of the sale or sharing of personal information (though we do not engage in these activities); and (e) not be discriminated against for exercising your rights. To submit a verifiable consumer request, please email privacy@sentrafort.com or call our toll-free number at 1-800-SENTRA-1. We will verify your identity by matching information you provide with information we have on file.

You may designate an authorized agent to make a request on your behalf. We may require the authorized agent to provide a valid power of attorney or other proof of authorization, and we may verify your identity directly. We will respond to verifiable consumer requests within 45 days. If we require additional time (up to an additional 45 days), we will inform you of the reason and the expected completion date.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. When we make changes, we will update the “Last updated” date at the top of this page.

For material changes that significantly affect your privacy rights or the way we process your personal data, we will provide prominent notice at least 30 days before the changes take effect. This notice may be provided via email to the address associated with your account, through an in-app banner notification, or both. Material changes include, but are not limited to, new categories of personal data collected, new purposes for processing, changes in sub-processors, or changes to your privacy rights.

Your continued use of the Sentrafort platform after the effective date of a revised Privacy Policy constitutes your acceptance of the revised policy. If you do not agree with the changes, you should discontinue using our services and contact us to request deletion of your personal data. We maintain an archive of prior versions of this policy, which is available upon request.

14. Data Protection Officer

Sentrafort has appointed a Data Protection Officer (DPO) to oversee our compliance with data protection laws and to serve as the primary point of contact for data subjects and supervisory authorities on matters relating to the processing of personal data.

You may contact our Data Protection Officer for any questions, concerns, or requests related to this Privacy Policy or our data protection practices:

Data Protection Officer

Sentrafort, Inc.

Email: dpo@sentrafort.com

Address: 548 Market St, Suite 35000, San Francisco, CA 94104, USA

For general privacy inquiries and data subject requests, you may also contact our privacy team at privacy@sentrafort.com. If you are located in the European Economic Area, you also have the right to contact your local data protection supervisory authority. A list of supervisory authorities is available on the European Data Protection Board website.

Questions about your privacy?

Contact our privacy team at privacy@sentrafort.com or our DPO at dpo@sentrafort.com.