AC-3
Access Enforcement
PostgreSQL row-level security is enabled and forced on every tenant-owned table. Cross-tenant access is tested in CI.
Sentinel GRC trust center
This page distinguishes implemented safeguards from planned work. Claims link to evidence in the repository and automated test suite.
AC-3
PostgreSQL row-level security is enabled and forced on every tenant-owned table. Cross-tenant access is tested in CI.
SC-28
Uploaded documents use AES-GCM envelope encryption with tenant-bound associated data and per-upload data keys.
SI-12
A least-privilege database function removes expired uploads, engagements, and OSINT cache records according to the data policy.
SA-11
CI runs tests, type checks, dependency audits, Bandit, Semgrep, and secret scanning. The current backend suite contains 95 passing tests.
CA-7
Read-only GitHub and AWS checks map live observations to controls and append immutable tenant-scoped evidence. No live customer connection is claimed yet.
AI-GRD-1
Generated control citations are rejected unless the cited ID was present in the exact retrieval context.