Skip to content
Sentyn
How it works
Sentyn console · acme-prod
Owner coverage89.1%
Open findings174
Connectors4 active
IdentitySourceOwnerRisk
prod-ci-deployerAWS IAMunknowncritical
gha-release-tokenGitHubassignedhigh
lambda-audit-roleAWS IAMconfirmedmedium
evidence: redactedblast_radius: computedsync: read-only
Find. Understand. Fix.

See machine identities, their owners, their access, and the safest next step.

Learn more
Workflow
How Sentyn works
Four-step workflow
What is a machine identity?
Connector maturity
Security architecture
Integrations
Connectors
AWS IAM
GitHub
Azure Entra
Kubernetes
Start
See Sentyn
Book a product demo
See demo steps
View the owner screen
See report exports
Book a product demo
See the product with safe sample data. We clearly label features that are still in beta.
Product
Sentyn console · acme-prod
Owner coverage89.1%
Open findings174
Connectors4 active
IdentitySourceOwnerRisk
prod-ci-deployerAWS IAMunknowncritical
gha-release-tokenGitHubassignedhigh
lambda-audit-roleAWS IAMconfirmedmedium
evidence: redactedblast_radius: computedsync: read-only
Product console

See what exists, who owns it, what it can access, why it is dangerous, and what to fix first.

Learn more
Capabilities
Console
Overview
Inventory
Ownership
Findings
Access reviews
Capabilities
Workflow
Discover
Assign owner
Triage finding
Preview fix
Export proof
Services
Assessments
Cloud assessment
Infra and CI/CD review
AI agent review
Audit evidence package
Ask about an assessment
Tell us which systems and machine identities you need help reviewing.
Use cases
Teams
Cloud security
Privileged review
Multi-account visibility
Blast radius
Teams
Identity
Unknown owner cleanup
Owner conflicts
Attestation
Teams
Audit / GRC
Board prep
Compliance evidence
Connector review
Lifecycle
Five-step loop
Discover
Assign
Prioritize
Preview
Prove
Book a product demo
See how Sentyn handles the machine access problem your team has.
Resources
Learn
Knowledge center
Resources
Security & trust
Use cases
Docs
Security & trust
Security model
Connectors
Deployment
Trust packs
Company
About
Principles
What we are not
Enterprise teams
Contact
Contact
Get started
Book a product demo
Security review
Assessment inquiry
Book a product demo
See Sentyn with safe sample data and clear labels for beta features.
Contact
Book a product demo
Sentyn

Security for service accounts, API keys, cloud roles, workloads, and agents. Built around ownership, access, risk, and evidence.

Book a product demo

Product

OverviewConsole tourPlatformPricing

Services

Cloud assessmentInfra reviewAI agentsAudit package

Use cases

Cloud securityIdentityAudit / GRCLifecycle

Resources

ResourcesSecurity & trustSecurity modelAboutContact
© 2026 Sentyn. All rights reserved.
SecurityPricingsentyn.io

Security & trust

See exactly how Sentyn protects your data

Learn what Sentyn reads, what it never stores, how customer data stays separated, and which features are still in beta.

Read the FAQ
Knowledge center

What we collect

Metadata and redacted evidence only. Read-only connector sync.

  • IAM role and policy metadata
  • GitHub app, PAT, and deploy key metadata
  • Service account external IDs and connector source
  • Owner signals with evidence JSON
  • Redacted secret fingerprints and locations
  • Relationship graph edges for blast radius
  • Append-only audit events

What we never store

Fail-closed redaction before persistence, API, exports, and logs.

  • Raw secret values or API key plaintext
  • Private keys or certificate private material
  • Connector credential payloads after write
  • Provider write tokens beyond read-only scope
  • Behavioral detection profiles or NHIDR models

Security model

How Sentyn handles tenancy, credentials, secrets, audit, and connector trust.

Tenant isolation

PostgreSQL row-level security on every tenant table. API never trusts tenant IDs from request bodies. Cross-tenant negative tests required for new features.

Credential envelope

Connector credentials encrypted through a KMS abstraction. API returns status only. Logs and responses never echo credential payloads.

Redaction pipeline

Secrets stripped before persistence, API responses, reports, logs, and webhooks. Tests use fake secrets and assert full values never appear.

Append-only audit

Sensitive writes fail closed if audit append fails. Tenant-scoped events for connector setup, owner assignment, and export actions.

Read-only connectors

Discovery connectors require least-privilege read scopes only. Permission manifests must exist before any real credential is accepted.

Honest maturity labels

Beta, demo, fixture, and future production labels come from backend maturity evidence. No connector is presented as live-proven until a successful real-source sync records that proof.

What each connector can read

The product shows whether a connector is beta or demo-only. Permission guides and collected-data details are reviewed separately for each connected system and are not yet complete for every connector.

  • 31 configurable beta providers and 3 demo fixtures in the current catalog
  • Beta providers require live proof before any production-ready claim
  • Data collection and permission scope are provider-specific
  • Connector permission resources

Where Sentyn can run

The demo can run locally with Docker. A beta private runner can read approved system details inside your cloud network and send only safe identity data to Sentyn.

  • Health endpoints for API, worker, and database
  • Environment variables documented per service
  • Private runner for VPC-only connector egress

Security review material

Review connector permissions, security controls, deployment notes, and proof of what each feature has passed.

Ask for the current security material before connecting a system.

Safe report downloads

Reports include only your organization’s data, remove secret values, and keep a permanent record of important actions.

  • Category landscape for procurement

Further reading

  • Sentyn FAQ for GRC teams
  • Review checklist
  • Category landscape
  • Connector permission docs

Security review call?

We walk through the security model, trust packs, and what Sentyn never stores with your identity and GRC teams.

Email our team