- What is Sentyn?
- Sentyn is an ownership-first machine identity security console. It discovers IAM roles, service accounts, tokens, and automation identities read-only, assigns owners with evidence, maps blast radius, and exports audit-ready proof without storing raw secrets.
- What problem does Sentyn solve?
- Organizations inherit thousands of machine identities with unclear owners, excessive privilege, and no evidence trail for auditors. Sentyn names identities, surfaces unknown owners as findings, and packages proof in the same workflow security teams use to triage risk.
- How is Sentyn different from a secrets manager?
- Secrets managers store and rotate credentials. Sentyn inventories and governs machine identities across cloud and CI/CD, stores only redacted evidence, and never replaces HashiCorp Vault, AWS Secrets Manager, or CyberArk vault functions.
- Which connectors are production-ready?
- None are currently claimed as production-ready or live-proven. The executable catalog contains 31 configurable beta providers and 3 demo fixtures. Beta means the setup and pipeline exist; production proof requires a successful real-source sync and provider-specific validation.
- Does Sentyn write to cloud providers?
- Discovery is read-only by design. Remediation workflows can generate, approve, reject, retest, and roll back plans, but provider writes remain gated behind explicit flags and entitlements rather than running automatically by default.
- What evidence does Sentyn export for audits?
- Inventory snapshots, ownership status, finding evidence panels, relationship graph metadata, and append-only audit events. Exports are tenant-scoped and redacted.
- What is machine identity security?
- Machine identity security governs non-human credentials and automation principals: IAM roles, service accounts, API keys, OAuth apps, CI tokens, and workload identities. It covers inventory, ownership, least privilege, blast radius, and lifecycle accountability.
- Who is Sentyn for?
- Cloud security, identity engineering, platform security, and GRC teams that need to understand machine identities, accountable owners, access paths, risk, and the evidence behind each decision.