Security & Trust

Security controls for governed AI agent execution.

Sentinel SCA is built to help teams verify agent identity, evaluate actions before execution, preserve tenant-scoped evidence, and review operational activity with traceable governance records.

Read Buyer Brief Developer Docs

At A Glance

AreaCurrent Implementation
Cryptographic identityEd25519 agent keys with generated keypair and customer-provided public key enrollment.
Signed governanceSigned agent requests are verified before Sentinel records a governance decision.
Tenant isolationUsers, agents, audit events, evidence exports, and billing state are scoped by organization.
Replay-aware controlsTimestamp and signature checks reduce stale or duplicated request risk.
Audit integrityGovernance decisions include hashes, timestamps, and exportable evidence context.
Billing securityPaddle webhook signatures are enforced before subscription lifecycle changes are processed.
Readiness/health, /live, and /ready support deployment and monitoring checks.
No Identity, No Action

Agents must be known and cryptographically verifiable before governed actions are accepted.

Tenant-Scoped Evidence

Customer audit timelines and evidence ZIP exports stay bound to the authenticated organization.

Role-Based Access

Owner, admin, auditor, and viewer roles separate management access from evidence-only access.

Billing Integrity

Unsigned or invalid Paddle webhooks are rejected before entitlement state can change.

Operational Controls

Global protocol freeze, readiness checks, and request IDs support incident response.

Enterprise Review

Architecture, API docs, tenant isolation tests, SLA draft, and DR docs are available for review.

Enterprise Security Review Package

Current Status

ItemStatus
Protocol runtimeOperational
Tenant isolation smoke coverageImplemented
Paddle webhook signature enforcementImplemented
Customer BYOK agent enrollmentImplemented
Third-party security auditPlanned for Enterprise readiness
SOC 2 / ISO 27001Roadmap item, not yet certified

Security Contact

For security review, enterprise evaluation, or responsible disclosure, contact Sentinel SCA through the contact flow.

Contact Sentinel SCA Watch Guided Demo