Security at Sentrafort

We practice what we preach. Security is not just our product — it is fundamental to how we build, deploy, and operate our platform.

Certifications & Compliance

SOC 2 Type II
Audit Planned Q3 2026
ISO 27001
Aligned Architecture
GDPR
Data Handling Practices
HIPAA
Framework Implemented

Encryption

  • TLS 1.3 for all data in transit
  • AES-256 encryption for data at rest
  • Customer-managed encryption keys (BYOK) for Enterprise
  • End-to-end encryption for sensitive configuration data

Access Control

  • Role-based access control (RBAC) with 8 configurable roles
  • Multi-factor authentication (MFA) required for all accounts
  • SSO integration (SAML 2.0, OIDC)
  • Principle of least privilege enforced across infrastructure

Infrastructure

  • AWS-hosted infrastructure with encrypted storage
  • Multi-region deployment with automated failover
  • Network segmentation and micro-segmentation
  • Regular infrastructure patching within 24-hour SLA

Monitoring & Response

  • 24/7 security monitoring of production infrastructure
  • Automated threat detection and alerting
  • Incident response plan with defined SLAs
  • Regular red team exercises and penetration testing

Responsible Disclosure

If you discover a security vulnerability in our platform, we encourage responsible disclosure. Please report issues to security@sentrafort.com. We respond to all reports within 24 hours.