← Public demo

Sentinel GRC trust center

Platform safeguards

This page distinguishes implemented safeguards from planned work. Claims link to evidence in the repository and automated test suite.

6/6controls implemented

Platform controls

AC-3

Access Enforcement

Implemented

PostgreSQL row-level security is enabled and forced on every tenant-owned table. Cross-tenant access is tested in CI.

SC-28

Protection of Information at Rest

Implemented

Uploaded documents use AES-GCM envelope encryption with tenant-bound associated data and per-upload data keys.

SI-12

Information Management and Retention

Implemented

A least-privilege database function removes expired uploads, engagements, and OSINT cache records according to the data policy.

SA-11

Developer Testing and Evaluation

Implemented

CI runs tests, type checks, dependency audits, Bandit, Semgrep, and secret scanning. The current backend suite contains 95 passing tests.

CA-7

Continuous Monitoring

Implemented

Read-only GitHub and AWS checks map live observations to controls and append immutable tenant-scoped evidence. No live customer connection is claimed yet.

AI-GRD-1

Grounded Generation

Implemented

Generated control citations are rejected unless the cited ID was present in the exact retrieval context.

Draft platform evidence only. This is not a certification or independent audit opinion.