Trust Centre
Every question your security team will ask, answered here.
A question you had to ask us is a defect. This page is where we log, answer, and publish them — including the ones where the honest answer is “not yet”.
What Sentinel does and does not do
The scope is deliberately narrow. Everything outside it is stated here rather than left to be discovered during a security review.
What does Sentinel scan?
Live todayPublic, internet-facing signals for domains you have authorized: HTTPS availability, TLS certificates, HTTP security headers, DNS records, SPF and DMARC email-authentication records, and public domain-registration (RDAP) status.
What will it not scan?
Live todayAnything requiring credentials, anything intrusive, and anything you have not authorized. Sentinel performs no exploitation, no credential use, no denial-of-service testing, and no intrusive vulnerability validation. Scan classes S2 and above are outside V1 entirely.
Can it affect production?
Live todayThe checks are passive and low-impact reads — the same requests any visitor's browser makes, on a schedule. There is no write path to your systems.
Does it replace penetration testing, EDR, or a SOC?
Live todayNo. Sentinel is external monitoring with evidence and a verified remediation loop. It complements a human-led penetration test; it does not replace one, and it is not endpoint protection, SIEM, or a 24/7 SOC.
Does it scan source code?
Not yetNot yet. Repository security (Sentinel Code) is a planned controlled beta and is not available today. No repository is connected and no source code is processed.
Evidence and findings
Findings are meant to be inspected, not trusted.
How do I know your findings are real?
Live todayEvery customer-visible finding links to the observation that produced it: the detector and its version, the target, the timestamp, and the retained data itself. Each evidence record carries a SHA-256 hash covering that content, so later modification is detectable. No evidence, no finding.
Open any finding in the portal and expand its Evidence panel.
What if a finding is wrong?
Live todayChallenge it. A disputed finding is suspended from your risk score while it is under review, and both the challenge and the written outcome stay on the record. Target response is 2 business days.
How is AI used?
Live todayIt is not, in any customer-visible output. Every finding, score, claim, report sentence, and receipt in the product today is produced by deterministic code from recorded observations. If that changes, any AI-assisted output will be labelled and will remain incapable of creating a finding without deterministic evidence behind it.
Does customer data train models?
Live todayNo models are used, so no customer data trains any model. This will remain contractually prohibited if AI assistance is introduced.
Verified fixes and shareable proof
A fix is not closed because work happened. It closes when a rescan proves it.
What is a Verified Fix Receipt?
Live todayA signed record of one verified change: what was exposed, the evidence before, the approved action, the rescan result, the evidence after, and the change in risk. It is issued only when a rescan confirms the finding is gone.
Can a recipient verify a receipt themselves?
TargetAnyone holding a receipt identifier can verify it on the public verification page or through the JSON endpoint, without an account. Verification re-derives the content hash and checks the platform signature. Offline verification without contacting us requires an asymmetric key and an open-source verifier — planned, not yet available.
What happens if a receipt is wrong?
Live todayIt can be revoked, with a reason, and the verification page reflects that immediately. Receipts are never silently edited.
Do receipts expire?
Live todayYes — each carries a freshness window. A receipt describes a verified moment, never a permanent state, and the verification page says so once the window has passed.
Data, privacy, and deletion
What is stored, where it goes, and how to get it back or remove it.
What data does Sentinel hold?
Live todayAccount and identity data, the assets you authorize, check results and the evidence derived from them, findings, alerts, reports, receipts, audit events, and access logs. Evidence is redacted before storage to strip secrets, tokens, and personal data.
Which subprocessors are used?
Live todayResend for outbound alert email when enabled. Public DNS resolvers and RDAP registries are queried for lookups but receive no customer data beyond the domain being checked. The current deployment is a single operator-managed server.
How does export work?
Live todayYour whole graph — assets, authorizations, findings with evidence lineage, claims with control mappings, alerts, reports, and snapshots — exports as documented JSON on request. No fee, no exit friction.
How does deletion work?
Live todayDeleting an organization removes its members, assets, checks, results, findings, alerts, snapshots, reports, receipts, and authorization records. Audit entries are deliberately retained: they are the record of what scanning was authorized, and editing them would break the tamper-evident chain. They age out wholesale on a 24-month retention schedule.
Where is data stored?
Not yetIn the region of the deployment you are onboarded to. In-region and private-deployment options for specific jurisdictions are planned and are not claimed as available today.
Our own security
We hold ourselves to what we monitor for you.
How secure is Sentinel itself?
Live todaySessions are httpOnly, SameSite, hash-stored, capped by both idle and absolute lifetimes, and revocable. Cross-origin state changes are rejected. Security headers including a content-security policy are set on every route. Login is rate limited. Administrative actions are recorded in a tamper-evident hash-chained audit log that can be independently re-verified.
Has an independent penetration test been done?
Not yetNot yet. An independent penetration test and retest are required before commercial general availability, and the summary will be published here when it exists. There is no test to point to today.
Do you run Sentinel against your own domain?
TargetYes — that is the point. The self-check runs the production check modules and scoring formula against our own domain, and the deployment must clear the threshold before customer-facing claims are made.
Live status: /status
How do I report a vulnerability?
Live todayEmail security@9keys.io. The policy, scope, and response targets are published at /security and in /.well-known/security.txt.
Commercial, support, and exit
Pricing basis, support expectations, and how to leave.
How does pricing work?
TargetPublished plans with an instant quote for standard scope. Pricing is labelled as pilot pricing until per-customer costs are measured — we will not publish a validated price we cannot stand behind.
What is the support model?
TargetEmail support with a first-response target of one business day for standard plans; enterprise response is contract-specific. These are targets, not a contractual SLA, until measured.
What certifications do you hold?
Not yetNone today. SOC 2 and ISO 27001 are on the roadmap with readiness work planned; we will not imply certification before a certificate is issued.
What happens on exit?
Live todayFull export in a documented format, then verified deletion. No exit fee and no lock-in.
Are remediation services independent of findings?
Live todayYes, structurally. The remediation channel is not an input to severity, confidence, or scoring, and self-fixes, partner fixes, and 9Keys Cyber fixes receive identical verification and identical receipts.
Still have a question?
Send it to hello@9keys.io. Anything asked more than once gets answered on this page.