A security management platform should itself be secure.

Sentrel is designed to protect sensitive ISMS information through controlled access, encrypted secrets, auditability, secure deployment patterns and clear separation of services.

Security claims should be factual and specific.

Sentrel may hold risk assessments, audit findings, security evidence, supplier information and credentials used to connect external systems. The product architecture therefore treats security as a core design concern.

Role-based access

Functionality and sensitive records can be restricted according to user responsibility, with more granular permissions introduced as deployments mature.

Credential protection

Connector secrets are designed to be encrypted at rest and not displayed back in plain text after saving.

Network separation and HTTPS

In the documented Docker deployment model, the database operates on a private container network while the web application is published through a reverse proxy protected by HTTPS.

Document and approval integrity

Controlled files can be fingerprinted using SHA-256 so approval records can reference the exact version reviewed.

Audit logging

Important administrative and governance actions can be logged with timestamp, user and affected record.

Shared responsibility

Self-hosted environments give customers control over hosting, backups, network restrictions and certificates, while also making them responsible for host maintenance, security updates and backup protection.

Launch note: independent certifications, penetration testing claims and other formal security assurances should only be published once they are established and evidenced.

Talk to us about Sentrel security

Discuss deployment architecture, access control, connector permissions and your security requirements.

Book a demo →