Security
Your library stays yours.
How Sentinel RF keeps each operation's documents apart, who can sign in, what reaches a model, and what happens to your data when you leave. The same commitments are in the privacy policy and the data processing addendum, which govern.
Your documents stay in your operation.
- Each operation's documents and indexed content are isolated by tenant. The isolation is enforced in the retrieval layer, the part that decides which pages an answer can draw on.
- Automated cross-tenant leakage tests run on every code change, so a change that would let one operation's content reach another's answers fails before it ships.
- Chats, watch lists, saved studies and reports belong to the operation that made them. A chat can be shared inside your operation; nothing can be shared across operations.
Sign-in, seats and roles.
- Every person signs in with their own seat. Credentials are never shared, and a new user sets their own password from an emailed link; no password is ever sent by email.
- Two-factor sign-in with an authenticator app, a passkey or recovery codes, and admin seats are required to have one.
- One active session per person. A session on a machine you mark as trusted lasts thirty days; otherwise it ends in twenty four hours.
- Owner, admin and member roles inside your operation, and a separately gated operations role for our staff. Support access to your account is read-only and is recorded in your own audit log.
What reaches a model, and what does not.
- Answering a question sends the relevant excerpts of your documents and your question to a model inference provider through a routing service. We require provider options with no-logging data policies: prompts and outputs are not retained by the provider or used to train its models.
- Your documents are used only to answer your own operation's questions. They are not used to train any model.
- Our operational logs are designed not to record document content or conversation text.
- We never ask for, store or use your manufacturer-portal credentials. Documents arrive through channels your operation controls: upload, and your private email-in address.
Infrastructure.
- Data is encrypted in transit (TLS). Uploaded documents are stored in United States object storage.
- Access to production systems is restricted to authorized personnel, on a least-privilege basis, with key-based authentication.
- Rate limiting, input validation and structured audit logging.
- The platform is actively monitored for health and reliability, with automated offsite backups.
Your data, on your terms.
- Export your data from the admin console at any time.
- After a cancellation we keep your data for 30 days in case you come back, then permanently delete your documents and indexed content. Residual copies in operational logs and backups age out on their own retention schedules.
- If a personal data breach affects your data, we notify you without undue delay, and in any case within 72 hours of becoming aware of it.
- A small set of subprocessors provides hosting, content delivery and storage, payments, transactional email, inference routing and error monitoring. The current list is available on request at [email protected], and we give at least 30 days' notice by email before adding or replacing one that processes customer personal data.
Contract work and reviews.
For government or utility work that requires data to stay inside a defined boundary, a private deployment tier runs the same product with inference inside your own boundary.
On written request, once a year, we provide a written summary of our security measures and complete a reasonable security questionnaire. To ask, or to report a security concern, email [email protected].
Questions before a pilot?
Tell us what your procurement or IT review needs, and we will answer it in writing.