Outside-in architecture
Discovery uses public service-reachability signals. The separate DAST crawler uses bounded HTTP GET checks only; it does not perform port scanning or authenticated testing.
A transparent overview of how Sentryx observes public infrastructure, handles monitoring data, and supports vendor security reviews.
Outside-in monitoring · No agents · No internal access required
Sentryx is designed to answer the questions an external observer can answer: what is exposed, what changed, and what deserves attention.
Discovery uses public service-reachability signals. The separate DAST crawler uses bounded HTTP GET checks only; it does not perform port scanning or authenticated testing.
Sentryx does not require source-code access, VPN access, administrator passwords, or agent installation to start monitoring a public domain.
Core service workloads run in Google Cloud's Singapore region. Current architecture details are available during a vendor security review.
Collection is scoped to the service, and Sentryx does not assess IAM permissions, cloud policies, internal segmentation, source code, secrets, employee endpoints or lateral movement.
When traffic is proxied through Cloudflare, Sentryx observes the public edge and externally visible behavior. The origin may not be identifiable unless it is separately exposed.
Our outside-in model keeps the product useful for public exposure while limiting the access it needs to operate.
For the full privacy context, see the Privacy Policy. Deletion requests and security questions can be sent to support@sentryxmonitor.com.
We keep the current status visible and can provide additional context for a vendor or security review.
| Area | Current status |
|---|---|
| SOC 2 | Not currently certified |
| ISO 27001 | Not currently certified |
| Data processing agreement | Available by request |
| Vendor security review | Available |
| Responsible disclosure | Available |
| Subprocessors | Current provider list available on request |
The public product surface does not imply identity controls or integrations that have not been documented. Confirm current availability and scope during procurement.
| Capability | Public status |
|---|---|
| SSO / SAML | Confirm current availability |
| MFA | Confirm current availability |
| RBAC | Confirm current availability |
| Audit logs | Confirm current availability |
| API / webhooks | Confirm current availability |
| Incident integrations | Confirm current availability |
| Terraform / SCIM | Confirm current availability |
Start with a public domain and learn what a customer, partner, or attacker can observe.