Commitment to Competence — Security awareness training and background checks
Owner: CEO
Trust Center
Security, legal, procurement, ownership, and investor review should all see the same current evidence.
Live control status, honest evidence, and machine-readable artifacts for the people evaluating whether Sentus is ready to operate inside a real portfolio.
Status reflects the current state as of the last registry update. Partial means partial. We do not claim active SOC 2 certification on this page, and ownership and procurement teams should be able to see that plainly.
Owner: CEO
Owner: CEO
Owner: engineering
Owner: CEO
Owner: engineering
Owner: engineering
Owner: engineering
Owner: engineering
Owner: engineering
Owner: engineering
Owner: CEO
Owner: engineering
Owner: engineering
Owner: engineering
Owner: engineering
Owner: engineering
Owner: engineering
The public trust center groups the operating procedures legal, security, and procurement reviewers usually ask to see first.
NIST 800-61r2-aligned. Four severity tiers, six phases, per-incident containment playbooks, and tabletop cadence.
docs/soc2/procedures/incident-response.md Quarterly recertification enumerates admin users, roles, and last-login. CEO sign-off required each cycle.
docs/soc2/procedures/access-review.md Maps database tables to business entities. Used during quarterly access reviews and external audit prep.
docs/soc2/procedures/schema-discovery.md Blameless five-section template with mandatory timeline, root cause, contributing factors, and prevention fields.
docs/soc2/procedures/postmortem-template.md Downloads and live artifacts stay available from the public trust route so diligence can begin before a custom security packet is requested.
System Security Plan covering 11 AICPA TSP controls wired to shipped evidence. Vanta, Drata, and FedRAMP can ingest directly.
Download sentus-ssp.jsonPublic SBOM listing all dependencies and license data. Refreshed on every production deployment.
View Live SBOMEvery production push emits signed SLSA Build L3 provenance and CycloneDX SBOM via GitHub OIDC. Verifiable offline.
gh attestation verify <artifact> --owner Sentus-Ai Our fair-housing-compliance worker processes every voice transcript and chat message in real time. Risk levels range from none to critical. High or critical findings trigger an automatic alert to the legal queue and an append-only audit entry.
Sophia assists - she does not decide. Final housing decisions remain with the licensed property manager. All AI recommendations are advisory and logged for auditability.
Race, color, national origin, religion, sex, familial status, disability - per Fair Housing Act
Processed before transcripts enter the PM dashboard
Never deleted - exportable for auditors on request
Human PM approval required for all housing-decision workflows
The trust page is not a generic security brochure. It is the public evidence layer that lets buying committees evaluate control, governance, and implementation risk.
Audit-ready workflow evidence across the public Trust Center and procurement routes
Fair Housing-aware transcript scanning called out explicitly in the live trust narrative
Company-scoped access controls and OTP-based sign-in referenced consistently across the website
SOC 2 posture described as audit in progress, not falsely presented as certified
Ownership and procurement can review the same evidence stack before the deeper diligence call begins
Security reports acknowledged within 48 hours. Legal and compliance inquiries within one business day.
To report a vulnerability, email [email protected] with subject [VULN]. Please do not disclose publicly before we have addressed it.