Skip to main content
Security & Compliance

Your data stays in Australia.
Your evaluations stay tamper-evident.

Sentrify is designed for regulated industries where data residency, evidence integrity, and access control are non-negotiable. Every architectural decision reflects that.

Infrastructure

AWS ap-southeast-2 (Sydney) — sole region

All evaluation data, evidence documents, and audit logs are hosted exclusively on AWS ap-southeast-2. No cross-region replication. Data never leaves Australian territory.

Encrypted in transit and at rest

All traffic travels over TLS 1.2 or higher. Data at rest uses AWS default encryption. No plaintext storage of sensitive artefacts.

Secrets via AWS SSM SecureString

Credentials, API keys, and connection strings are stored in AWS Systems Manager Parameter Store as SecureString values. No secrets in source code or environment variables.

Authentication via AWS Cognito; SAML 2.0 / OIDC

User authentication is handled by AWS Cognito. Enterprise customers can federate via SAML 2.0 or OIDC, using their existing identity provider.

Evaluation Integrity

SHA-256 evidence content integrity

Every evidence document is SHA-256 hashed at ingest. The hash is stored alongside the content and validated before each evaluation run — any modification is detected before evaluation begins.

Integrity-hashed evaluation reports

TrustScore™ reports are integrity-hashed at generation. Any post-generation modification is detectable, providing a tamper-evident record for regulators and auditors.

Immutable audit log

The audit log is append-only and tamper-evident. Every state transition, user action, and system event is recorded with actor, timestamp, and tenant context.

4-role RBAC with tenant isolation

Platform Admin, Admin, Manager, and User roles are enforced at the API layer. Every database query is scoped by tenantId — cross-tenant data access is architecturally prevented.

Governance Standards

Sentrify's control library is aligned to the following frameworks. Alignment means our 94 controls map to each framework's requirements — it does not constitute certification unless explicitly stated.

ISO 42001 Annex AAPRA CPS 234APRA CPS 230Privacy Act 1988ASIC RG 273TEQSA AI GovernanceNHMRC
Security details

Want the full security details? Talk to our team.

We can provide a security pack, answer infrastructure questions, and walk through our data handling practices for your compliance review.

Request a Demo →
Sentrify

AI Trust Infrastructure for regulated industries. Deploy AI with confidence through machine-verifiable trust, continuous assurance, and audit-ready governance.

🇦🇺 Data hosted in Australia · AWS ap-southeast-2
Stay updated

Product updates and Australian AI-regulation insights. No spam.

© 2026 Sentrify Pty Ltd. All rights reserved.

AI Trust Infrastructure · sentrify.ai