Security
Last updated: June 2026
Security posture
Built on an edge-native application architecture designed for low-latency operations and scoped execution. Sentus is designed for low-latency operations, scoped execution, and clear separation between customer environments. The goal is simple: resident, owner, and operator data should remain protected while the platform stays responsive under real operating load.
Buyers should evaluate the platform the same way they would evaluate any system touching owner statements, bank details, resident communication, vendor coordination, and audit-sensitive workflows: does it protect data, preserve evidence, and stay reliable under day-to-day operating pressure? That is the standard this page is meant to answer.
That same standard matters to property managers, ownership groups, and investor-backed operators for a simple reason: one weak security decision can turn into reporting risk, legal exposure, and owner mistrust very quickly.
Selected infrastructure and delivery stack
We do not position vendor logos as the product. We do disclose the core delivery stack used to run Sentus so procurement, legal, security, and ownership stakeholders can evaluate the platform with more precision.
This is the same category of edge-security and application-delivery posture used by compliance-sensitive and fintech platforms that prioritize speed, resilience, and tighter security review standards.
- Cloudflare for edge compute, storage, workflow orchestration, and site delivery.
- SignalWire for PSTN and SMS routing.
- ElevenLabs for Sophia voice orchestration.
- Doppler for secrets management.
- Stripe for payments and payouts.
Resident-data isolation
We use company-scoped authorization, per-company data constraints, and request-level access checks to reduce the risk of cross-customer data exposure.
- Every customer record is tied to a company scope.
- Authorization checks validate role and company context on each request.
- Sensitive workflows are designed to fail closed when scope is ambiguous.
- Internal operations and audit views are kept separate from the views customers see.
Authentication and sessions
Sentus uses OTP-based authentication and scoped session controls. Session lifetime, role scope, and company scope are all part of the access contract rather than left to front-end state alone.
Abuse prevention and platform hardening
Public forms and high-risk workflows use challenge gates, request throttling, duplicate suppression, and contextual rate limits to reduce brute-force, spam, and scripted abuse.
- Risk controls are applied at the edge before sensitive workflows execute.
- Forms and demos use anti-automation checks before lead capture or session creation.
- Operational APIs are protected by authentication, scope checks, and route-level limits.
Secrets and change control
Secrets are managed outside the codebase and are not stored in source control. Production changes are expected to pass typed validation, scoped review, and deployment gates before they are promoted.
In plain terms: the platform is designed so a hurried deployment, a weak form endpoint, or a noisy public attack surface does not become your owners' problem later.
Auditability and evidence
Sentus is built around operational traceability. Sensitive workflows are designed to leave an evidence trail that supports legal review, dispute resolution, implementation governance, and internal incident response.
- AI-assisted recommendations are logged and positioned as advisory, not autonomous legal judgment.
- Security, compliance, and procurement stakeholders can review public trust artifacts before deeper diligence.
- Machine-readable trust evidence is published through the Trust Center.
Compliance posture
Sentus maintains a SOC 2-aligned control framework with documented, published evidence. We have not yet engaged an independent auditor; certification is planned. We do not claim active SOC 2 certification today. We do maintain documented controls, procedures, and evidence intended to support formal assessment work and customer diligence.
The infrastructure Sentus runs on carries its own current attestations: Cloudflare, Stripe, SignalWire, ElevenLabs, and Doppler each maintain SOC 2 Type II reports, with ISO 27001 and PCI DSS Level 1 where applicable. Those certifications belong to our providers — we cite them as inherited infrastructure controls, not as Sentus certifications.
Responsible disclosure
If you discover a security vulnerability, report it to [email protected]. We acknowledge security reports within 48 hours and ask that vulnerabilities not be publicly disclosed before remediation.