Trust Center

Trust evidence for serious operators, not checkbox theater.

Security, legal, procurement, ownership, and investor review should all see the same current evidence.

Live control status, honest evidence, and machine-readable artifacts for the people evaluating whether Sentus is ready to operate inside a real portfolio.

Live control statusMachine-readable artifactsFair Housing AI transparency
11 Controls implemented or procedure-complete
15 AICPA TSP controls in scope
SOC 2-aligned Current posture
Audit in progress Independent audit status
AICPA Trust Services Criteria

Live control status, grouped by review category.

Status reflects the current state as of the last registry update. Partial means partial. We do not claim active SOC 2 certification on this page, and ownership and procurement teams should be able to see that plainly.

Common Criteria - Control Environment

2 controls
CC1.4

Commitment to Competence — Security awareness training and background checks

Owner: CEO

Policy Declared
CC1.5

Accountability — External penetration test / VAPT evidence

Owner: CEO

In Progress

Common Criteria - Security (Access)

6 controls
CC6.1

Logical Access — Restrict user access

Owner: engineering

Implemented
CC6.2

User Access Review — Quarterly recertification

Owner: CEO

Procedure Complete
CC6.3

Access Changes — Audit trail for role modifications

Owner: engineering

Partial
CC6.6

Logical Access — Restrict logical access via session hygiene + HSTS + clickjacking

Owner: engineering

Implemented
CC6.7

Data in Transit — TLS 1.2+ / HSTS

Owner: engineering

Implemented
CC6.8

Change Management — PR review + CI gates

Owner: engineering

Implemented

Common Criteria - Security (Monitoring)

3 controls
CC7.1

System Monitoring — Anomaly detection

Owner: engineering

Implemented
CC7.2

System Monitoring — Anomaly response

Owner: engineering

Implemented
CC7.3

Incident Response — Documented runbook

Owner: CEO

Procedure Complete

Common Criteria - Security (Logging)

1 controls
CC2.1

Logging — Audit trail on sensitive operations

Owner: engineering

Partial

Availability

2 controls
A1.1

Availability — Load testing evidence

Owner: engineering

Implemented
A1.2

Availability — Backup + recovery

Owner: engineering

Procedure Complete

Processing Integrity

1 controls
PI1.1

Processing Integrity — Input validation at boundaries

Owner: engineering

Partial

Confidentiality

1 controls
C1.1

Confidentiality — Secrets management + rotation

Owner: engineering

Implemented

Privacy

1 controls
P4.2

Privacy — Retention + deletion

Owner: engineering

Policy Declared
Documented Procedures

Evidence-backed operating procedures.

The public trust center groups the operating procedures legal, security, and procurement reviewers usually ask to see first.

IR

Incident Response

NIST 800-61r2-aligned. Four severity tiers, six phases, per-incident containment playbooks, and tabletop cadence.

docs/soc2/procedures/incident-response.md
AR

Access Review

Quarterly recertification enumerates admin users, roles, and last-login. CEO sign-off required each cycle.

docs/soc2/procedures/access-review.md
SD

Schema Discovery

Maps database tables to business entities. Used during quarterly access reviews and external audit prep.

docs/soc2/procedures/schema-discovery.md
PM

Post-Mortem Template

Blameless five-section template with mandatory timeline, root cause, contributing factors, and prevention fields.

docs/soc2/procedures/postmortem-template.md
Machine-Readable Evidence

Ingest directly into your compliance tool.

Downloads and live artifacts stay available from the public trust route so diligence can begin before a custom security packet is requested.

SSP

OSCAL SSP

OSCAL 1.1.2 / FedRAMP-compatible

System Security Plan covering 11 AICPA TSP controls wired to shipped evidence. Vanta, Drata, and FedRAMP can ingest directly.

Download sentus-ssp.json
BOM

Software BOM

CycloneDX - live endpoint

Public SBOM listing all dependencies and license data. Refreshed on every production deployment.

View Live SBOM
SLSA

Supply-Chain Attestation

SLSA Build Level 3

Every production push emits signed SLSA Build L3 provenance and CycloneDX SBOM via GitHub OIDC. Verifiable offline.

gh attestation verify <artifact> --owner Sentus-Ai
Fair Housing + AI Transparency

Every Sophia call is scanned for discrimination risk.

Our fair-housing-compliance worker processes every voice transcript and chat message in real time. Risk levels range from none to critical. High or critical findings trigger an automatic alert to the legal queue and an append-only audit entry.

Sophia assists - she does not decide. Final housing decisions remain with the licensed property manager. All AI recommendations are advisory and logged for auditability.

Seven protected classes monitored

Race, color, national origin, religion, sex, familial status, disability - per Fair Housing Act

Real-time scan on every transcript

Processed before transcripts enter the PM dashboard

Append-only audit log

Never deleted - exportable for auditors on request

AI decisions are advisory only

Human PM approval required for all housing-decision workflows

Why This Matters

Command is credible only if the public trust surface is explicit.

The trust page is not a generic security brochure. It is the public evidence layer that lets buying committees evaluate control, governance, and implementation risk.

+

Audit-ready workflow evidence across the public Trust Center and procurement routes

+

Fair Housing-aware transcript scanning called out explicitly in the live trust narrative

+

Company-scoped access controls and OTP-based sign-in referenced consistently across the website

+

SOC 2 posture described as audit in progress, not falsely presented as certified

+

Ownership and procurement can review the same evidence stack before the deeper diligence call begins

Contact

Questions about compliance or security?

Security reports acknowledged within 48 hours. Legal and compliance inquiries within one business day.

To report a vulnerability, email [email protected] with subject [VULN]. Please do not disclose publicly before we have addressed it.