Information Security
LAST UPDATED · JULY 2026Security is our practice, so we hold ourselves to it. This page describes how we protect our own systems and client data, and how to report a vulnerability. We treat every report seriously and act on it quickly.
Our security posture
We operate on least-privilege access, enforce multi-factor authentication across our systems, and encrypt data in transit and at rest. Our environment is monitored continuously, and we align our controls with recognized frameworks including NIST CSF, ISO 27001, and SOC 2.
Handling client data
Client data is segregated, access-controlled, and handled strictly under the terms of each engagement. We collect only what an engagement requires, retain it only as long as needed, and return or destroy it on request or at the end of the relationship.
Reporting a vulnerability
If you believe you have found a security issue affecting Sentiark, email security@sentiark.com with steps to reproduce. Please give us a reasonable window to investigate and remediate before public disclosure. We do not pursue legal action against researchers who act in good faith and avoid privacy violations or service disruption.
Incident response
We maintain documented incident response procedures with defined roles and escalation paths. In the event of an incident affecting client data, we contain, investigate, and notify affected parties in line with contractual and legal obligations.
Responsible disclosure scope
This policy covers Sentiark-owned domains and infrastructure. Please do not test client systems, run automated scans that degrade service, or access data beyond what is needed to demonstrate a finding. Social engineering and physical attacks are out of scope.
Reporting an issue or have a security question? Email security@sentiark.com and our team will respond directly.