SENTINEL / TRUST CENTER
Security and responsible disclosure
Practical safeguards for official-source verification, described clearly without absolute guarantees or unsupported certifications.
Connection and browser protections
Production access uses HTTPS with HTTP Strict Transport Security. Browser responses apply Content Security Policy, frame-embedding protection, MIME-type protection, a restrictive permissions policy and a privacy-conscious referrer policy.
Server-side credentials
Credentials used to reach configured official services remain on the application server. They are not shipped in browser assets or returned in public API responses.
Verification data and caching
Verification records, history responses and generated reports are marked for private, no-store handling and excluded from public indexing. Public informational pages use separate cache and indexing rules.
Abuse protection and safe failures
Verification requests are bounded and validated, with rate limiting enabled in production. Public errors use limited response categories and do not expose access tokens, credentials, stack traces or raw internal exceptions.
Tracking and evidence transparency
SENTINEL currently uses no Google Analytics, Meta Pixel, Hotjar or advertising trackers. Every verification source retains its own role, operating mode, timestamp and evidence boundary.
Responsible security disclosure
If you believe you have identified a security issue affecting SENTINEL Company Intelligence, please report it responsibly to security@sentinelentity.com.