Trust Center — maintained by The Sentinel Flow

Enterprise trust, in plain terms.

The Sentinel Flow is an AI-assisted trade audit and refund intelligence platform. This Trust Center summarizes how the platform protects your data, governs AI, and supports enterprise procurement reviews. Status labels distinguish what is live today from what is on the roadmap. Nothing on this page constitutes an independent certification.

Data

Per-tenant siloing, RLS, and encryption at rest and in transit.

AI

Human-in-the-loop, deterministic financials, evidence-first.

Governance

Auditable claim lifecycle and Workforce approvals queue.

Security overview

Application, data, and access controls that protect every workspace.

Open Security Center

TLS in transit & encryption at rest

Implemented

TLS 1.2+ for all requests; managed encrypted storage for uploads and database records.

Row-level security on customer data

Implemented

Every tenant table is scoped by RLS; server functions enforce owner checks.

Secrets isolated server-side

Implemented

Payment, AI, and storage credentials are Worker secrets — never in the browser bundle.

Third-party penetration test

Planned

External assessment scoped for the year following general availability.

AI governance

How AI is used, where humans decide, and what AI never does.

AI Transparency

Human-in-the-loop for customer-impacting actions

Implemented

Explicit human approval is required before any external action. No unattended execution path exists.

Deterministic financial calculations

Implemented

Recovery amounts, duty-free savings, and exposure math are computed deterministically.

Evidence attached to every recommendation

Implemented

Each opportunity ships with source fields, HTS/agreement references, and calculation basis.

No training on customer documents

Implemented

Customer uploads are not used to train foundation models.

Privacy

What we collect, how we use it, and how customers stay in control.

Privacy Policy

Per-tenant data siloing

Implemented

Data belongs to the workspace; no cross-tenant pooling.

Export and deletion on request

Implemented

Workspace owners may request export or deletion from support at any time.

Named subprocessor list

Implemented

Full subprocessor list published in the Privacy Policy.

In-product self-serve data export

In Progress

Expanding in-app export beyond claims to full workspace archives.

Availability

Runtime posture and how we operate the service.

Managed serverless edge runtime

Implemented

Application runs on a globally distributed edge platform with automatic failover.

Managed Postgres with backups

Implemented

Daily backups and point-in-time recovery via the managed database provider.

Application-level monitoring

Implemented

Error and performance instrumentation for on-call response.

Public status page

Planned

External status page targeted for general availability.

Infrastructure

Where the platform runs and how it is bounded.

Cloudflare Workers (edge SSR + server functions)

Implemented

Bundled server logic on a global edge runtime.

Managed Postgres via Supabase

Implemented

Primary data store, auth, and file storage with RLS.

Region controls for regulated customers

Planned

Region-pinned deployments considered for enterprise contracts.

Enterprise controls

Governance features available to workspace administrators.

Review approvals & audit trail

Implemented

Workflow actions route through an approvals queue with reviewer identity captured.

Claim lifecycle with stage history

Implemented

Every claim carries an auditable stage-by-stage history.

Role-based workspace access

Implemented

Workspace access is scoped and requires authenticated identity.

SAML SSO for enterprise plans

Planned

SAML SSO enablement targeted for enterprise contracts.

SCIM provisioning

Planned

Directory-driven user lifecycle on the enterprise roadmap.

Public API access

Planned

No customer-facing API is available today. Data can be exported as CSV and claim packages.

Pre-liquidation shipment monitoring

Planned

No ACE, AMS, carrier or EDI integration exists today. Analysis runs on documents you upload.

Compliance roadmap

Current posture and the roadmap toward independent attestation.

Security & privacy practices documented

Implemented

This Trust Center, Security Center, and Privacy Policy.

SOC 2 Type I readiness

In Progress

Controls being aligned with SOC 2 Type I readiness; no certification claimed today.

SOC 2 Type II certification

Planned

Sequenced after Type I readiness completes.

ISO 27001 alignment

Planned

Considered based on enterprise customer demand.

DPA available on request

Implemented

Data Processing Addendum available for enterprise contracts on request.

Incident response

How we classify, respond to, and communicate about incidents.

Incident Response

Severity-tiered response process

Implemented

SEV-1 through SEV-4 with defined response and notification handling.

Direct customer notification

Implemented

Affected customers receive direct notification for SEV-1/SEV-2 impacts.

Blameless post-incident reviews

Implemented

Documented root cause, timeline, and follow-up for material incidents.

Contact security

For DPA requests, security questionnaires, or vulnerability reports, reach the security team directly.