Security overview
Last updated: August 12, 2026
SentinelOps is designed to provide accountable control over consequential AI-agent actions.
Core controls
Organizations are isolated in PostgreSQL. Operator sessions are revocable, roles are enforced server-side, sensitive actions can require MFA, and agent credentials are hashed and rotatable.
Governance evidence
Policy decisions, approvals, release governance, and integration lifecycle events are appended to a tenant-scoped hash chain. GitHub draft creation and publication are independently governed.
Responsible disclosure
Report suspected vulnerabilities to security@sentinelops.ai. Do not include secrets or exploit details in public issues. We will acknowledge reports and coordinate remediation.
Pilot limitations
The pilot is not certified for SOC 2, ISO 27001, HIPAA, or PCI DSS. Customers should complete security review, data-processing terms, backup validation, and incident-response planning before production use.
Questions? Contact security@sentinelops.ai.