Back to Membership
Security & Trust

You're trusting us with the keys
to your digital life.

Here's exactly how we hold them.

01

Zero-knowledge vault

We use a client-side encrypted password vault — 1Password Business or Bitwarden Enterprise tier depending on your household configuration. Vault contents are encrypted on your device before they ever leave it. Sentinel operators cannot read vault contents without an explicit, time-bound, audit-logged share initiated by you. We never hold master passwords or the secret key that encrypts your vault.

How it works You grant a scoped, expiring share when we need access to a specific credential. The share expires automatically. Every open and close is logged.
02

Dual-control access

No single Sentinel operator can access a client's secrets alone. Every privileged action — credential access, device management, account configuration — requires two-person approval. One operator initiates. A second, independent operator approves. The action is logged with both names, a timestamp, and a stated reason. Neither party can bypass this requirement.

Why this matters Dual control eliminates the single point of human failure. If one operator were ever coerced, compromised, or careless, the second approval gate stops the action cold.
03

Background-checked, NDA-bound operators

Every Sentinel operator is background-checked via Checkr or an equivalent national screening service before they are assigned to any client. Each operator signs a client-specific NDA before your onboarding begins — not a blanket company NDA, a document that names you and your household. The obligation to protect your information is personal, documented, and legally binding.

04

Encryption everywhere

AES-256 encryption at rest, TLS 1.3 in transit — for every system that touches client data. This is not a configuration option or a tier feature. It is the baseline for everything Sentinel operates.

  • Client records: AES-256 at rest
  • All communications: TLS 1.3 in transit
  • Vault contents: client-side encryption (zero-knowledge by design)
  • Backup archives: encrypted before transmission
05

Full audit logging

Every access to your data is logged: operator name, action taken, timestamp, and a stated reason. Logs are append-only and cannot be modified after the fact. You can request a full copy of your audit log at any time, without notice, without explanation. We will provide it.

Your right You own the log. Email us at any time and receive your complete access history within one business day.
06

What Sentinel never touches

Some categories of data are outside our scope by design — not by oversight. We do not access, store, or request the following under any membership tier:

  • Bank account credentials — we work with shared bookmarks and 2FA, never passwords
  • Investment account credentials or brokerage login details
  • Medical records or health information
  • Private messages or email contents

If a task requires temporary access to something outside normal scope, you grant it explicitly — and revoke it when the task is complete. No persistent access to sensitive systems.

07

Cyber liability insurance

Sentinel carries a cyber liability policy for the business. Coverage is in force from the start of your membership. This is not a feature listed on a pricing page — it is a requirement of operating a service that holds privileged access. Details of the coverage tier are available on request.

08

Offboarding — clean exit, verified

When a membership ends, Sentinel's access ends completely — not eventually. Within 72 hours of cancellation:

  • Every credential we held a share to is rotated
  • Every device enrolled in management is removed
  • Every access token, admin right, and management profile is revoked
  • A written attestation is issued to you confirming the above

The attestation is signed and dated. Keep it. If anything is ever in question, it's your evidence.