Security and data handling
SentriCap works with sensitive finance data, so security is part of the product specification, not an afterthought.
How to read this page. The controls below describe SentriCap's production architecture and the handling we commit to for an engagement. They are not independently audited or certified, and SentriCap makes no certification claim. Where a control matters to your engagement, ask for its current state in writing.
How data flows
Every stage is scoped to your engagement and ends with a human decision.
Your export
You export structured files from your own systems.
Private intake
Files land in a private, access-controlled intake — no public URLs.
Isolated workspace
Data is scoped to a single tenant identifier for your engagement only.
Control engine
Deterministic, explainable controls run against your data.
Evidence-backed alerts
Each exception links back to the records that triggered it.
Human reviewer
Your team decides what happens next. Nothing is actioned automatically.
Intended production architecture
Each control is labeled by current status: Planned, Production requirement, or Human controlled.
Tenant isolation
No query path may return records across tenant boundaries, enforced in the database.
Row level security
Row-level policies decide access against the authenticated identity, not the application.
Private file storage
Exports stored in private buckets with no public URLs; access via short-lived credentials.
US-region infrastructure
Application, database and storage hosted in US regions, with configurable regional data residency as a future production requirement.
Server-side secret handling
Credentials and API keys exist only in server-side configuration, never in the client bundle.
Least-privilege access
Personnel receive the narrowest access needed, time-bounded to the engagement.
Audit logging
Append-only record of access, disposition changes and exports, available to the customer.
Data minimization
Only fields needed for the agreed controls are requested in the export specification.
Configurable retention & deletion
Retention period agreed up front, with deletion of exports on request and confirmation issued.
Human-controlled decisions
Whether to hold, query, recover or accept a payment is decided by your people.
Exposure vs. confirmed loss
Potential exposure is reported separately from confirmed issues your team establishes.
What SentriCap does not do
SentriCap is decision-support software. It does not initiate bank payments or autonomously approve, reject or block financial transactions.
- It does not connect to banking rails and cannot release or stop a payment run.
- It does not decide that a payment is fraudulent. It shows which control triggered and on what evidence.
- It does not guarantee that fraud or error will be prevented. It improves the chance that an exception is seen and reviewed in time.
Discuss the data handling for your scan
The export specification, retention period and access arrangements are agreed before any data is shared. Start by scoping a scan and we will work through it with you.