Why Sentrify
AI Trust Infrastructure is not a governance dashboard.
GRC tools track compliance. AI governance dashboards show metrics. Sentrify does something different: it makes your AI deployments auditable, defensible, and continuously assured — at every layer, for every stakeholder.
Why existing tools leave a gap.
10 dimensions. Two alternatives. One AI Trust Infrastructure.
| Dimension | Traditional GRC Tools | Generic AI Governance Tools | Sentrify |
|---|---|---|---|
| Control evaluation | Manual, periodic checklist | Dashboard config, no structured execution | Continuous automated assurance across 94 controls |
| Traditional tools rely on point-in-time self-assessments that can be weeks stale before the next review cycle. Generic AI governance tools surface dashboards but leave control evaluation to manual configuration. Sentrify runs structured, framework-native control evaluation on every submission — continuously, not periodically. | |||
| Evidence integrity | File upload, no authenticity guarantee | Metadata attachment only | SHA-256-keyed evidence content; tamper-evident audit log |
| SHA-256 keying detects any post-submission modification — the hash is recorded at ingest and verified on every access. The audit log records every access event, not just upload events, so a regulator can trace the full chain of custody for each document. | |||
| Scoring transparency | Score aggregated by vendor formula | Weighted dashboard metrics, black box | Deterministic TrustScore™ — pure math, no LLM in scoring path |
| Every TrustScore is dimension-weighted, fully reproducible, and traceable to the exact control decisions that produced it. LLM calls are used only during control evaluation — never during scoring. The same inputs always produce the same score, which matters when a regulator asks you to explain a number. | |||
| Framework specificity | Generic IT-GRC controls, not AI-aware | Pre-built AI risk categories (static) | Framework-native; versioned immutable assurance packs per industry |
| Controls are authored against a specific framework version and published as immutable assurance packs. When standards change, a new pack version is published and future evaluations reference it explicitly. Prior evaluations retain their meaning because they are permanently pinned to the pack version they ran against. | |||
| Evaluation depth | Checklist responses | Single-layer LLM evaluation | 4-layer pipeline: rules + LLM + evidence check + adversarial probe packs |
| Each control passes through 4 evaluation layers: deterministic rules (L1), LLM-assisted reasoning (L2), evidence document validity (L3), and adversarial probe packs (L4). The adversarial layer executes versioned red-team probe packs as a structured fourth pass — producing a pack-versioned record alongside each control decision, not a free-text assessment. | |||
| Governance routing | Manual escalation via email | Risk flag + notification | Risk-tiered automated routing to named human approvers; no auto-approval |
| Sentrify routes governance approvals to named humans — it never approves on behalf of governance. Risk tier determines which committee receives the submission; quorum-based endorsement gives governance leads a defensible record. Rejection always requires a mandatory comment and triggers a revise-and-resubmit cycle. | |||
| Data residency | Varies / US-primary SaaS | US-primary, optional region | AWS ap-southeast-2 exclusively; Australian data residency by design |
| All storage, processing, and LLM inference run inside AWS ap-southeast-2. No data leaves the region. This matters for regulated Australian industries subject to TEQSA, APRA CPS 234, and OAIC Privacy Act obligations — the architecture is designed for Australian data residency, not retrofitted for it. | |||
| Response to framework change | Re-audit entire programme manually | Update dashboard config | Publish a new pack version; all prior evaluations remain versioned |
| When a framework standard evolves, a new assurance pack version is published. All prior evaluations remain permanently pinned to the pack version they ran against — historical reports retain their meaning even after the standard changes. Only new evaluations reference the new version. | |||
| Audit readiness | PDF export of dashboard state | Report download | Integrity-hashed reports; immutable evidence chain; reproducible scores |
| A regulator or auditor can independently verify any historical report because the evidence content (SHA-256), the control decisions, and the TrustScore math are all preserved and linked. The report itself carries an integrity hash, so any post-generation modification is detectable. | |||
| Human-in-the-loop | Optional sign-off field | Approval status flag | Named committee workflow; quorum-based endorsement; rejection requires mandatory comment |
| Every evaluation routes to named committee members who endorse — not just flag — the outcome. A governance lead records the final decision. Rejection always triggers a mandatory comment and a revise-and-resubmit cycle, not a silent denial. The full decision trail is preserved in the immutable audit log. | |||
Traditional tools rely on point-in-time self-assessments that can be weeks stale before the next review cycle. Generic AI governance tools surface dashboards but leave control evaluation to manual configuration. Sentrify runs structured, framework-native control evaluation on every submission — continuously, not periodically.
SHA-256 keying detects any post-submission modification — the hash is recorded at ingest and verified on every access. The audit log records every access event, not just upload events, so a regulator can trace the full chain of custody for each document.
Every TrustScore is dimension-weighted, fully reproducible, and traceable to the exact control decisions that produced it. LLM calls are used only during control evaluation — never during scoring. The same inputs always produce the same score, which matters when a regulator asks you to explain a number.
Controls are authored against a specific framework version and published as immutable assurance packs. When standards change, a new pack version is published and future evaluations reference it explicitly. Prior evaluations retain their meaning because they are permanently pinned to the pack version they ran against.
Each control passes through 4 evaluation layers: deterministic rules (L1), LLM-assisted reasoning (L2), evidence document validity (L3), and adversarial probe packs (L4). The adversarial layer executes versioned red-team probe packs as a structured fourth pass — producing a pack-versioned record alongside each control decision, not a free-text assessment.
Sentrify routes governance approvals to named humans — it never approves on behalf of governance. Risk tier determines which committee receives the submission; quorum-based endorsement gives governance leads a defensible record. Rejection always requires a mandatory comment and triggers a revise-and-resubmit cycle.
All storage, processing, and LLM inference run inside AWS ap-southeast-2. No data leaves the region. This matters for regulated Australian industries subject to TEQSA, APRA CPS 234, and OAIC Privacy Act obligations — the architecture is designed for Australian data residency, not retrofitted for it.
When a framework standard evolves, a new assurance pack version is published. All prior evaluations remain permanently pinned to the pack version they ran against — historical reports retain their meaning even after the standard changes. Only new evaluations reference the new version.
A regulator or auditor can independently verify any historical report because the evidence content (SHA-256), the control decisions, and the TrustScore math are all preserved and linked. The report itself carries an integrity hash, so any post-generation modification is detectable.
Every evaluation routes to named committee members who endorse — not just flag — the outcome. A governance lead records the final decision. Rejection always triggers a mandatory comment and a revise-and-resubmit cycle, not a silent denial. The full decision trail is preserved in the immutable audit log.
Assurance you can defend.
Five capabilities that set the infrastructure apart.
Deterministic TrustScore™
Pure math — zero LLM in the scoring path. Every score is dimension-weighted, fully reproducible, and traceable to the exact control results that produced it.
Engine + versioned assurance packs
A domain-neutral evaluation engine paired with framework packs that are versioned and immutable once published. Every evaluation references the exact pack version it ran against — no ambiguity when standards change.
"What to Test" generator
An AI-recommended test plan generated from each system's risk profile before evaluation starts. Teams know exactly what to evaluate — no guesswork, no blank-page planning.
Adversarial testing built in
Versioned adversarial probe packs are bound to controls and executed as a fourth evaluation layer — structured red-teaming that produces a traceable, pack-versioned record alongside the control evaluation.
Immutable evidence chain
SHA-256-keyed evidence content, integrity-hashed evaluation reports, and tamper-evident audit logs. Built from the ground up to survive regulatory review and legal scrutiny.
Proof, not promises.
Three principles Sentrify is built around — each one verifiable in the product.
We never ask for blind trust.
TrustScore™ is pure math — every dimension-weighted score is fully reproducible and traceable to the exact control results that produced it. If a score drops, you see precisely which control drove it. There is no black-box formula, no vendor-only algorithm.
We never gatekeep deployment.
Sentrify assures your AI is ready for scrutiny; your team decides when to ship. The platform surfaces evidence, scores, and governance outcomes — it does not hold a veto over your release. Assurance and deployment decisions are deliberately separate.
We never auto-approve governance.
Every approval routes to a named human in your governance chain. Committee members endorse outcomes; a governance lead records the final decision. Sentrify routes and records — it never decides. Rejection always requires a mandatory comment and a revise-and-resubmit cycle.
Ready to deploy AI you can defend?
See TrustScore™ and the full evidence chain in action.