Trust Center

Trust evidence for serious operators, not checkbox theater.

Security, legal, procurement, ownership, and investor review should all see the same current evidence.

Live control status and honest evidence for the people evaluating whether Sentus is ready to operate inside a real portfolio.

Live control statusPublic diligence artifactsAI governance transparency
11Controls implemented or procedure-complete
15AICPA TSP controls in scope
SOC 2-alignedCurrent posture
PlannedIndependent audit
AICPA Trust Services Criteria

Live control status, grouped by review category.

Status reflects the current state as of the last registry update. Partial means partial. We do not claim active SOC 2 certification on this page, and ownership and procurement teams should be able to see that plainly.

Common Criteria - Control Environment

2 controls
CC1.4

Commitment to Competence — Security awareness training and background checks

Owner: CEO

Policy Declared
CC1.5

Accountability — External penetration test / VAPT evidence

Owner: CEO

In Progress

Common Criteria - Security (Access)

6 controls
CC6.1

Logical Access — Restrict user access

Owner: engineering

Implemented
CC6.2

User Access Review — Quarterly recertification

Owner: CEO

Procedure Complete
CC6.3

Access Changes — Audit trail for role modifications

Owner: engineering

Partial
CC6.6

Logical Access — Restrict logical access via session hygiene + HSTS + clickjacking

Owner: engineering

Implemented
CC6.7

Data in Transit — TLS 1.2+ / HSTS

Owner: engineering

Implemented
CC6.8

Change Management — PR review + CI gates

Owner: engineering

Implemented

Common Criteria - Security (Monitoring)

3 controls
CC7.1

System Monitoring — Anomaly detection

Owner: engineering

Implemented
CC7.2

System Monitoring — Anomaly response

Owner: engineering

Implemented
CC7.3

Incident Response — Documented runbook

Owner: CEO

Procedure Complete

Common Criteria - Security (Logging)

1 controls
CC2.1

Logging — Audit trail on sensitive operations

Owner: engineering

Partial

Availability

2 controls
A1.1

Availability — Load testing evidence

Owner: engineering

Implemented
A1.2

Availability — Backup + recovery

Owner: engineering

Procedure Complete

Processing Integrity

1 controls
PI1.1

Processing Integrity — Input validation at boundaries

Owner: engineering

Partial

Confidentiality

1 controls
C1.1

Confidentiality — Secrets management + rotation

Owner: engineering

Implemented

Privacy

1 controls
P4.2

Privacy — Retention + deletion

Owner: engineering

Policy Declared
Documented Procedures

Evidence-backed operating procedures.

The public trust center groups the operating procedures legal, security, and procurement reviewers usually ask to see first.

IR

Incident Response

NIST 800-61r2-aligned. Four severity tiers, six phases, per-incident containment playbooks, and tabletop cadence.

AR

Access Review

Quarterly recertification enumerates admin users, roles, and last-login. CEO sign-off required each cycle.

SD

Schema Discovery

Maps database tables to business entities. Used during quarterly access reviews and external audit prep.

PM

Post-Mortem Template

Blameless five-section template with mandatory timeline, root cause, contributing factors, and prevention fields.

Public Evidence

Start diligence with what is verifiable today.

These public resources establish the current baseline. Buyer-specific questions can then be handled against the workflows and evidence actually in scope.

SEC

Security overview

Public now

Company-scoped access, sign-in controls, change control, and the current compliance posture.

CTL

Control status

Public now

The implemented, partial, planned, and not-applicable controls shown on this page.

PRV

Privacy and service providers

Public now

How Sentus uses information and the categories of service providers involved in delivery.

FAQ

Procurement FAQ

Public now

Straight answers to the security and legal questions buyers commonly raise first.

AI Governance + Housing Decisions

AI assists; property managers remain responsible for housing decisions.

Sentus uses AI in communications and operational assistance. The controls and evidence available for review depend on the workflow being evaluated. Buyers should evaluate automated review controls against the workflows included in their own implementation.

Sophia assists - she does not decide. Final consequential housing decisions remain with the property manager, and the canonical public description of AI use lives in the Privacy Policy.

✓

Human decision-making

Final consequential housing decisions remain with the property manager.

✓

Published AI use

The Privacy Policy explains where AI is used and how to ask for a person instead.

✓

Company-scoped access

Access is evaluated against the authenticated company and role context.

✓

Workflow-specific review

Buyers should verify the controls that apply to the workflows included in their evaluation.

Why This Matters

Command is credible only if the public trust evidence is explicit.

The trust page is not a generic security brochure. It is the public evidence layer that lets buying committees evaluate control, governance, and implementation risk.

+

Audit-ready workflow evidence across the public Trust Center and procurement routes

+

AI use and human decision-making described through the canonical Privacy Policy

+

Company-scoped access controls and OTP-based sign-in referenced consistently across the website

+

SOC 2 posture described exactly as it is: aligned controls with an auditor not yet engaged — never presented as certified

+

Ownership and procurement can review the same evidence stack before the deeper diligence call begins

Contact

Questions about compliance or security?

Security reports and legal or compliance inquiries are reviewed through the contact paths below.

To report a vulnerability, email security@sentus.ai with subject [VULN]. Please do not disclose publicly before we have addressed it.