SECURITY & COMPLIANCE TRUST CENTER

Security Built into Every Layer

At SentinelNHI, we protect your organization's most sensitive SaaS credentials by adhering to a strict Zero-Secret-Storage model and defense-in-depth engineering.

Zero Secret Storage

We never inspect, record, or store plaintext API tokens, SSH private keys, or OAuth client secrets. Our scanners inspect only identity metadata, granted permission scopes, and activity timestamps.

100% Agentless Architecture

No daemon processes, host agents, or sidecars run on your workloads. Sentinel interacts strictly through official read-only SaaS vendor APIs, eliminating supply-chain agent risk.

Cryptographic Immutability

All audit events, remediation actions, and compliance evidence dossiers are cryptographically signed with SHA-256 and archived in tamper-resistant Cloudflare R2 object storage.

Compliance Framework Attestation

Engineered to streamline compliance with the most stringent global cybersecurity mandates.

EU Regulation 2022/2554Financial Entities

DORA Article 28 Compliance

Mandates that financial entities continuously identify and evaluate all ICT third-party dependencies. SentinelNHI automatically inventories every third-party OAuth app and machine integration, tracking ownership, data access breadth, and contractual sponsor status.

Automated Audit Dossier:Available on Scale Tier
EU Directive 2022/2555Critical Infrastructure

NIS2 Article 21 Supply Chain Security

Enforces cybersecurity risk-management measures regarding the security of supply chains and relationships with direct suppliers. Sentinel detects third-party integrations from unverified publishers and alerts on abnormal scope expansions.

Supply Chain Verification:Available on All Tiers
Underwriting DossiersCommercial Underwriters

Cyber Insurance Warranty Verification

Provides verifiable proof of regular credential rotation, departed-employee token deprovisioning, and least-privilege scope trimming, helping policyholders avoid claim denial following an incident.

Underwriting Proof Package:Instant 1-Click Export
Industry StandardGlobal Enterprises

SOC 2 Type II & ISO/IEC 27001 Alignment

Our infrastructure is deployed in SOC 2 Type II and ISO 27001 certified data centers. Continuous automated scanning, immutable event logging, and role-based access control are enforced throughout our architecture.

Security Whitepaper:Available Upon NDA

Responsible Disclosure Program

If you believe you have discovered a vulnerability in SentinelNHI or our underlying infrastructure, please contact our security team immediately at security@tkoresearch.com. We operate a safe-harbor policy for security researchers.

PGP Fingerprint: 4A8B 91F2 E34C 7D90 12A5 B89C 334F 8901