Security
Last updated: June 2026
Security posture
Sentus is designed to respond quickly under real operating load. Customer data is logically scoped by company, role, and request context. The goal is simple: resident, owner, and operator data should remain protected while the platform stays responsive.
Buyers should evaluate the platform the same way they would evaluate any system touching owner statements, bank details, resident communication, vendor coordination, and audit-sensitive workflows: does it protect data, preserve evidence, and stay reliable under day-to-day operating pressure? That is the standard this page is meant to answer.
That same standard matters to property managers, ownership groups, and investor-backed operators for a simple reason: one weak security decision can turn into reporting risk, legal exposure, and owner mistrust very quickly.
Resident-data isolation
We use company-scoped authorization, per-company data constraints, and request-level access checks to reduce the risk of cross-customer data exposure.
- Customer operational records in covered workflows are tied to a company scope.
- Authorization checks validate role and company context on protected operational requests.
- Sensitive workflows deny access when it is unclear which company a request belongs to.
- Internal operations and audit views are kept separate from the views customers see.
Authentication and sessions
Sentus uses one-time-code sign-in and time-limited sessions. Session length, role, and company are enforced on the server rather than left to the browser.
Abuse prevention and platform hardening
Public forms and high-risk workflows use challenge gates, request throttling, duplicate suppression, and contextual rate limits to reduce brute-force, spam, and scripted abuse.
- Risk checks run before sensitive workflows execute.
- Forms and demos use anti-automation checks before lead capture or session creation.
- Operational requests require sign-in and a company and role check, and high-risk routes are rate limited.
Secrets and change control
Keys and other secrets are kept out of the codebase and out of source control. Production changes pass automated checks and review before they are released.
In plain terms: the platform is designed so a hurried deployment, a weak form, or noisy attack traffic does not become your owners' problem later.
Auditability and evidence
Sentus is built around operational traceability. Sensitive workflows are designed to leave an evidence trail that supports legal review, dispute resolution, implementation governance, and internal incident response.
- AI-assisted recommendations are logged and positioned as advisory, not autonomous legal judgment.
- Live control status is published in the Trust Center.
- Buyer-specific security questions can be sent to security@sentus.ai; the team will identify which current evidence can support that review.
Compliance posture
Sentus maintains a SOC 2-aligned control framework with documented, published evidence. We have not yet engaged an independent auditor; certification is planned.We do not claim active SOC 2 certification today. We do maintain documented controls, procedures, and evidence intended to support formal assessment work and customer diligence.
Sentus relies on infrastructure and payment providers that maintain their own independent SOC 2 Type II attestations, and PCI DSS where applicable. Those certifications belong to our providers, not to Sentus.
Responsible disclosure
If you discover a security vulnerability, report it to security@sentus.ai. Please do not disclose it publicly before the team has addressed it.