Security
Built for the security review
Sentlyx handles the data that you most want to protect. So we built it to keep that data on your devices, in your region and under your control, and to show you exactly what it can and cannot see.
- By default, raw values never leave the laptop.Detection and masking run on the device.
- Your data stays in its home region.Each region is a separate copy of the service.
- Every admin action is in the audit log.Admins cannot change or delete it.
Data flow
What leaves the laptop
The agent checks each prompt on the device before it goes to an AI app. It replaces sensitive values with placeholders, and only the masked text goes to Sentlyx.
Metadata mode
DefaultSentlyx stores the user, the device, the app, the rule, the action, the time and a masked sample. It does not store the prompt text.
Full-prompt mode
An option for investigations. The laptop encrypts the full prompt with your key before it sends it. Only people with the Investigator role can read it, and each view goes into the audit log.
On the device
The agent
The agent is a native service that your device management tool installs and controls.
Detection on the device
Fixed detectors (patterns, checksums, entropy) and a small model find secrets, personal data, source code and your own terms. The raw values stay in memory on the device.
A device identity in hardware
Each device makes its own key. On Windows, the key is in the TPM and cannot be exported. Sentlyx signs a short-lived certificate for that key, valid for 30 days.
Mutual TLS
The agent talks to its home region only over mutual TLS with its device certificate. The service refuses a device without a certificate from that region. A revoked device is refused at its next request.
A signed policy
Your policy reaches the device as a signed bundle. The signing key is in AWS KMS in your region. The agent refuses a bundle with a bad signature or an older version, also from its own disk.
Inspection only for AI apps
If you turn on traffic inspection, the agent decrypts only the AI domains in your policy. All other traffic passes with no change. The agent never reads the clipboard.
Tamper alerts
You get an alert when an agent stops sending heartbeats, when a part of it is turned off, or when it starts again after an unexpected stop. Remove local admin rights with your device management tool, so that users cannot stop the agent.
Data residency
Your data stays in your region
Each customer selects one home region at setup. Each region is a full, separate copy of the service: its own servers, databases, keys and decision model. No customer data moves between regions.
India
AvailableAWS Mumbai (ap-south-1). Backups in AWS Hyderabad (ap-south-2), so all data stays in India.
Europe
PlannedA separate region for customers in Europe, the Middle East and Africa.
Americas
PlannedA separate region for customers in North and South America.
Only two parts are global: this website, and a login router that maps each email domain to its home region. The router stores the domain and the region, and nothing else. Each region has its own device certificate authority, so a device certificate from one region does not work in another.
In the cloud
The service
Encryption
All connections use TLS 1.2 or later. All data stores encrypt data at rest, with the keys of the AWS stores in AWS KMS. Secrets, such as the keys of your authenticator app and SSO, are encrypted with a key of your region.
Separation of customers
Each row of customer data carries the customer ID, and the database enforces the separation with row-level security. A request for one customer cannot read the rows of another.
Our own model
Our own model makes each decision, in your region, and it gets only the masked prompt. We do not use your data to train models for other customers.
Retention that you set
You set how long Sentlyx keeps each type of data, for example 30 days for prompt text and 1 year for events. The data is deleted when its time ends.
Infrastructure as code
The whole service is defined in code and checked against AWS security rules before each change. The databases accept connections only from the service.
Your SIEM
Send events and admin activity to Splunk, Microsoft Sentinel, IBM QRadar or a webhook, so that your security team sees Sentlyx with the rest of its alerts.
Admin access
Who can see what
Single sign-on
Admins sign in with SAML or OIDC, for example Microsoft Entra ID, Okta or Google. You can make SSO the only way in, with one emergency owner account for when the identity provider is down.
A second factor always
Without SSO, each admin must use an authenticator app. Sensitive actions, such as changing SSO or reading a prompt, need a fresh sign-in.
Roles
Admin, Analyst, Investigator and Auditor. Only the Investigator role can read full prompts. Your identity provider can set the roles from its groups.
Sessions
A session ends after 30 minutes with no activity or after 12 hours; you can change both. An admin gets an email after a sign-in from a new browser.
An audit log of everything
Each admin action, each sign-in and each view of a prompt goes into the audit log, with the IP address and the browser. Nobody can change or delete it, and it goes to your SIEM.
Access by Sentlyx staff
Our staff get access only when the work needs it. When we change your account, for example to extend a trial, the change shows in your audit log.
Limits
What Sentlyx cannot see
No control is complete. These are the limits that you should plan for.
Personal devices
A phone or a personal laptop has no agent. Use your device policies and network controls for these.
Local administrators
A local administrator can stop any agent. Sentlyx then sends an alert. Remove local admin rights to prevent it.
Apps that refuse inspection
Some apps and command-line tools refuse a local certificate. For these, select block or monitor only.
AI features on shared domains
Some AI features share a domain with normal work, such as Microsoft 365 or Google Workspace. A block of the whole domain blocks the work too.
Work in the vendor's cloud
Agents that run in the AI vendor's cloud, such as cloud coding tasks, do not pass the device.
Detection is not perfect
Sentlyx can miss data or flag data that is not sensitive. Start in monitor-only mode, and tune the policy before you block.
Privacy and legal
Monitoring that respects people
Many countries require a notice before an employer monitors its staff, and some require the consent of a works council. The agent shows its own notice to each user, and you set the text. You can start in monitor-only mode, collect metadata only, and keep the data for a short time.
For your data, Sentlyx is your processor. Our data processing agreement sets our duties, and our privacy policy explains the data that we control ourselves. Ask us for the agreement and the terms.
Subprocessors for customer data
| Company | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, databases, keys, email | Your home region |
| ClickHouse Cloud | The event database | Your home region, on AWS |
| Google Workspace | Email for support requests | Google data centers |
The DPA has the details. We tell customers 30 days before we add one.
Report an issue
Found a security problem?
Write to us with the steps to reproduce it. Please do not access data that is not yours, and give us time to fix the problem before you publish it.