Sentrix

Security

How we protect your compliance data.

The controls Sentrix operates continuously: encryption, least-privilege access, read-only integrations, incident response and responsible disclosure.

Sentrix handles evidence from your most sensitive systems. We take that seriously. This page documents the controls we operate, how your data is hosted and how to reach our security team. Our posture is public, not hidden behind a sales call.

The controls we operate. Continuously. Not at audit time.

Encryption everywhere

All data is encrypted at rest and in transit. Customer compliance data is encrypted at the database level, with encryption keys managed separately from the data.

Read-only integrations

Every integration uses read-only OAuth scopes. We request the minimum permissions required to collect evidence and nothing more. Scopes are documented for every integration in the connection wizard.

Access control

Strict least-privilege access internally. Role-based access with MFA enforced for all Sentrix employees. Privileged access requires just-in-time approval with full audit logging, and administrative access to production is gated by hardware security keys and time-limited session tokens. Customer environments are isolated by design.

Penetration testing

External and internal penetration testing is performed annually by an independent firm, covering the application and its underlying infrastructure. Findings are remediated on a severity-tiered timeline. An executive summary is available to customers under NDA.

Vulnerability management

Continuous vulnerability scanning on all cloud infrastructure. Dependency scanning on every code commit. Patches are prioritized by severity.

Incident response

Documented incident response plan tested annually. 24/7 on-call rotation for security events. Customers are notified without undue delay of any incident affecting their data, consistent with Law 25 and PIPEDA obligations.

Employee security

Background checks for all employees with access to customer data. Quarterly security awareness training and a phishing simulation program. Mandatory annual policy acknowledgment, with completion tracked in — naturally — Sentrix.

Business continuity

Automated backups, tested for recoverability. A documented business continuity plan is tested regularly.

Supply chain security

All third-party dependencies are reviewed before adoption. Sub-processors are assessed against Sentrix vendor risk criteria. Material sub-processor changes are communicated to customers with 30 days' notice.

Encryption at rest and in transit

All customer data stored within Sentrix is encrypted at rest with industry-standard algorithms recognized across NIST, ISO 27001 and SOC 2 frameworks. Encryption keys are managed separately from the data, with rotation schedules and strict separation between customer environments.

Data in transit between your browser, Sentrix application servers and any connected third-party system is protected by TLS; unencrypted connection attempts are rejected. These controls apply to the full data path, including API calls made by automated compliance workflows and scheduled evidence collection tasks.

Sentrix does not store passwords, service account credentials or OAuth refresh tokens in application databases. Read-only OAuth integrations authenticate through short-lived access tokens issued directly by the connected platform. If a token is revoked, Sentrix loses access immediately: there is nothing to breach on our side.

Read-only OAuth integrations

When you connect Sentrix to platforms such as Microsoft 365, Google Workspace, AWS or Microsoft Entra ID, the integration uses OAuth 2.0 with the minimum permission scopes required to read compliance-relevant signals. Sentrix never requests write access, never stores your platform passwords and never caches credentials beyond the authenticated session. Each integration scope is documented in the platform connection wizard so your IT security team can review it before authorizing access.

This architecture is deliberate. A read-only integration model means Sentrix cannot modify your source systems, cannot be used as a pivot point to alter configurations, and dramatically reduces the blast radius of any hypothetical compromise. Your compliance evidence is pulled, not pushed, and the source of truth always remains with you.

Data hosting

Customer compliance data — including uploaded evidence, control assessments, audit trails and user records — is hosted in Canada. This matters to organizations subject to PIPEDA, Québec's Law 25, provincial public-sector privacy legislation and sector-specific requirements in financial services and healthcare, as well as to customers in the United States and Europe that must document where a processor keeps their data.

Data Processing Agreements are available to all customers and include explicit provisions for data hosting, sub-processor disclosure and breach notification. The current sub-processor list is published in our Privacy Policy; affected customers are notified at least 30 days before a new sub-processor is added.

Security control summary

Control areaImplementation
Encryption at restIndustry-standard encryption, managed keys, separation per customer
Encryption in transitTLS enforced, no plaintext fallback
Credential storageNo passwords or OAuth refresh tokens stored; read-only short-lived tokens only
IntegrationsOAuth 2.0, minimum read-only scopes, documented before connection
Internal accessLeast privilege, RBAC, MFA for all employees, just-in-time privileged access with audit logging
Data hostingCanada; DPA available on request
Penetration testingAnnual, external and internal, by an independent firm; summary under NDA
Sub-processorsAssessed against vendor risk criteria; 30 days' notice of material changes

Security questionnaires

Send your vendor security questionnaire through our contact form and the security team will answer it. The practices on this page and the sub-processor list in the Privacy Policy are the basis of every response.

Responsible disclosure

We run a coordinated vulnerability disclosure program that covers this site and the app.sentrix.ca platform. The responsible disclosure policy sets out the scope, the rules of engagement, our response times and the legal safe harbor granted to good-faith researchers. Reports go to security@sentrix.ca, the address published in our security.txt file.

Frequently asked questions

Does Sentrix store our passwords or platform credentials?
No. Sentrix does not store passwords, service account credentials or OAuth refresh tokens in its application databases. Read-only OAuth integrations authenticate through short-lived access tokens issued directly by the connected platform. If you revoke a token from your identity provider, Sentrix loses access immediately; there is nothing to breach on our side.
Can Sentrix change anything in our systems?
No. Every integration uses OAuth 2.0 with the minimum read-only scopes needed to collect compliance-relevant signals. Sentrix never requests write access, so it cannot modify your source systems or be used as a pivot point to alter configurations. Each scope is documented in the connection wizard so your security team can review it before authorizing access.
Where is our compliance data hosted?
Customer compliance data — uploaded evidence, control assessments, audit trails and user records — is hosted in Canada. A Data Processing Agreement confirming the hosting and sub-processor terms is available on request for enterprise procurement reviews, and material sub-processor changes are communicated to customers with 30 days' notice.
How do I report a security vulnerability?
Write to security@sentrix.ca before any public disclosure, with a description of the vulnerability, reproduction steps and any relevant evidence. Our responsible disclosure policy details the scope, the rules of engagement, our response times and the protection granted to good-faith researchers. We do not offer bug bounty payments at this time.
Can we send Sentrix our vendor security questionnaire?
Yes. Send your own questionnaire through the contact form and the security team will answer it; the practices described on this page and the sub-processor list in the Privacy Policy are the basis of every response. A Data Processing Agreement is available to all customers and covers hosting, sub-processor disclosure and breach notification.

Let's talk about your compliance program.

Last updated: 2026-09-17