Security & trust

Security starts with how Sentryx operates.

A transparent overview of how Sentryx observes public infrastructure, handles monitoring data, and supports vendor security reviews.

Outside-in monitoring · No agents · No internal access required

Architecture

Visibility without privileged access.

Sentryx is designed to answer the questions an external observer can answer: what is exposed, what changed, and what deserves attention.

01

Outside-in architecture

Discovery uses public service-reachability signals. The separate DAST crawler uses bounded HTTP GET checks only; it does not perform port scanning or authenticated testing.

02

No sensitive credentials required

Sentryx does not require source-code access, VPN access, administrator passwords, or agent installation to start monitoring a public domain.

03

Defined data location

Core service workloads run in Google Cloud's Singapore region. Current architecture details are available during a vendor security review.

04

Controlled collection, honest boundaries

Collection is scoped to the service, and Sentryx does not assess IAM permissions, cloud policies, internal segmentation, source code, secrets, employee endpoints or lateral movement.

Cloudflare and reverse proxies

When traffic is proxied through Cloudflare, Sentryx observes the public edge and externally visible behavior. The origin may not be identifiable unless it is separately exposed.

Data handling

Know what Sentryx can access.

Our outside-in model keeps the product useful for public exposure while limiting the access it needs to operate.

May process

  • Public DNS, TLS, HTTP, uptime, and service observations
  • Domains, assets, monitors, findings, and alert settings you configure
  • Account, workspace, support, and product-usage information
  • Operational logs needed to keep the service reliable and secure

Does not require

  • Private network access or VPN credentials
  • Source code, production databases, or internal application access
  • Administrator passwords or installed agents
  • Secrets that are not part of the public surface you ask us to monitor
Data residencyGoogle Cloud · Singapore region
RetentionOnly as needed for operation and legal obligations
Account deletionRequest deletion through support

For the full privacy context, see the Privacy Policy. Deletion requests and security questions can be sent to support@sentryxmonitor.com.

Review readiness

Clear answers for procurement teams.

We keep the current status visible and can provide additional context for a vendor or security review.

AreaCurrent status
SOC 2Not currently certified
ISO 27001Not currently certified
Data processing agreementAvailable by request
Vendor security reviewAvailable
Responsible disclosureAvailable
SubprocessorsCurrent provider list available on request
\n
Enterprise review

Make the important questions explicit.

The public product surface does not imply identity controls or integrations that have not been documented. Confirm current availability and scope during procurement.

CapabilityPublic status
SSO / SAMLConfirm current availability
MFAConfirm current availability
RBACConfirm current availability
Audit logsConfirm current availability
API / webhooksConfirm current availability
Incident integrationsConfirm current availability
Terraform / SCIMConfirm current availability
Start outside-in

See your attack surface without opening your network.

Start with a public domain and learn what a customer, partner, or attacker can observe.