Security and data handling

SentriCap works with sensitive finance data, so security is part of the product specification, not an afterthought.

How to read this page. The controls below describe SentriCap's production architecture and the handling we commit to for an engagement. They are not independently audited or certified, and SentriCap makes no certification claim. Where a control matters to your engagement, ask for its current state in writing.

How data flows

Every stage is scoped to your engagement and ends with a human decision.

Data flow: your export, to private intake, to isolated workspace, to control engine, to evidence-backed alerts, to human reviewer. Every stage is scoped to your engagement and ends with a human decision.

Intended production architecture

Each control is labeled by current status: Planned, Production requirement, or Human controlled.

Production requirement

Tenant isolation

No query path may return records across tenant boundaries, enforced in the database.

Planned

Row level security

Row-level policies decide access against the authenticated identity, not the application.

Production requirement

Private file storage

Exports stored in private buckets with no public URLs; access via short-lived credentials.

Planned

US-region infrastructure

Application, database and storage hosted in US regions, with configurable regional data residency as a future production requirement.

Production requirement

Server-side secret handling

Credentials and API keys exist only in server-side configuration, never in the client bundle.

Planned

Least-privilege access

Personnel receive the narrowest access needed, time-bounded to the engagement.

Planned

Audit logging

Append-only record of access, disposition changes and exports, available to the customer.

Production requirement

Data minimization

Only fields needed for the agreed controls are requested in the export specification.

Planned

Configurable retention & deletion

Retention period agreed up front, with deletion of exports on request and confirmation issued.

Human controlled

Human-controlled decisions

Whether to hold, query, recover or accept a payment is decided by your people.

Human controlled

Exposure vs. confirmed loss

Potential exposure is reported separately from confirmed issues your team establishes.

What SentriCap does not do

SentriCap is decision-support software. It does not initiate bank payments or autonomously approve, reject or block financial transactions.

  • It does not connect to banking rails and cannot release or stop a payment run.
  • It does not decide that a payment is fraudulent. It shows which control triggered and on what evidence.
  • It does not guarantee that fraud or error will be prevented. It improves the chance that an exception is seen and reviewed in time.

Discuss the data handling for your scan

The export specification, retention period and access arrangements are agreed before any data is shared. Start by scoping a scan and we will work through it with you.