Enterprise trust, in plain terms.
The Sentinel Flow is an AI-assisted trade audit and refund intelligence platform. This Trust Center summarizes how the platform protects your data, governs AI, and supports enterprise procurement reviews. Status labels distinguish what is live today from what is on the roadmap. Nothing on this page constitutes an independent certification.
Data
Per-tenant siloing, RLS, and encryption at rest and in transit.
AI
Human-in-the-loop, deterministic financials, evidence-first.
Governance
Auditable claim lifecycle and Workforce approvals queue.
Security overview
Application, data, and access controls that protect every workspace.
TLS in transit & encryption at rest
ImplementedTLS 1.2+ for all requests; managed encrypted storage for uploads and database records.
Row-level security on customer data
ImplementedEvery tenant table is scoped by RLS; server functions enforce owner checks.
Secrets isolated server-side
ImplementedPayment, AI, and storage credentials are Worker secrets — never in the browser bundle.
Third-party penetration test
PlannedExternal assessment scoped for the year following general availability.
AI governance
How AI is used, where humans decide, and what AI never does.
Human-in-the-loop for customer-impacting actions
ImplementedExplicit human approval is required before any external action. No unattended execution path exists.
Deterministic financial calculations
ImplementedRecovery amounts, duty-free savings, and exposure math are computed deterministically.
Evidence attached to every recommendation
ImplementedEach opportunity ships with source fields, HTS/agreement references, and calculation basis.
No training on customer documents
ImplementedCustomer uploads are not used to train foundation models.
Privacy
What we collect, how we use it, and how customers stay in control.
Per-tenant data siloing
ImplementedData belongs to the workspace; no cross-tenant pooling.
Export and deletion on request
ImplementedWorkspace owners may request export or deletion from support at any time.
Named subprocessor list
ImplementedFull subprocessor list published in the Privacy Policy.
In-product self-serve data export
In ProgressExpanding in-app export beyond claims to full workspace archives.
Availability
Runtime posture and how we operate the service.
Managed serverless edge runtime
ImplementedApplication runs on a globally distributed edge platform with automatic failover.
Managed Postgres with backups
ImplementedDaily backups and point-in-time recovery via the managed database provider.
Application-level monitoring
ImplementedError and performance instrumentation for on-call response.
Public status page
PlannedExternal status page targeted for general availability.
Infrastructure
Where the platform runs and how it is bounded.
Cloudflare Workers (edge SSR + server functions)
ImplementedBundled server logic on a global edge runtime.
Managed Postgres via Supabase
ImplementedPrimary data store, auth, and file storage with RLS.
Region controls for regulated customers
PlannedRegion-pinned deployments considered for enterprise contracts.
Enterprise controls
Governance features available to workspace administrators.
Review approvals & audit trail
ImplementedWorkflow actions route through an approvals queue with reviewer identity captured.
Claim lifecycle with stage history
ImplementedEvery claim carries an auditable stage-by-stage history.
Role-based workspace access
ImplementedWorkspace access is scoped and requires authenticated identity.
SAML SSO for enterprise plans
PlannedSAML SSO enablement targeted for enterprise contracts.
SCIM provisioning
PlannedDirectory-driven user lifecycle on the enterprise roadmap.
Public API access
PlannedNo customer-facing API is available today. Data can be exported as CSV and claim packages.
Pre-liquidation shipment monitoring
PlannedNo ACE, AMS, carrier or EDI integration exists today. Analysis runs on documents you upload.
Compliance roadmap
Current posture and the roadmap toward independent attestation.
Security & privacy practices documented
ImplementedThis Trust Center, Security Center, and Privacy Policy.
SOC 2 Type I readiness
In ProgressControls being aligned with SOC 2 Type I readiness; no certification claimed today.
SOC 2 Type II certification
PlannedSequenced after Type I readiness completes.
ISO 27001 alignment
PlannedConsidered based on enterprise customer demand.
DPA available on request
ImplementedData Processing Addendum available for enterprise contracts on request.
Incident response
How we classify, respond to, and communicate about incidents.
Severity-tiered response process
ImplementedSEV-1 through SEV-4 with defined response and notification handling.
Direct customer notification
ImplementedAffected customers receive direct notification for SEV-1/SEV-2 impacts.
Blameless post-incident reviews
ImplementedDocumented root cause, timeline, and follow-up for material incidents.
Trust resources
Contact security
For DPA requests, security questionnaires, or vulnerability reports, reach the security team directly.
- Security: security@thesentinelflow.com
- Privacy: privacy@thesentinelflow.com
- Procurement: enterprise@thesentinelflow.com