AI Sentri
    Security at AI Sentri

    Security

    AI Sentri handles governance data, and we take that seriously. The frameworks your organisation builds, the leadership and employee information tied to them, the control metadata that maps to real decisions, that's not generic business content. It needs to be protected properly.

    Data residency

    Everything lives in the UK. Our database runs on Supabase hosted in the UK, and our serverless functions run in Vercel's EU West 2 region (London). Your data doesn't leave UK infrastructure.

    Isolation and access control

    We use Supabase's Row Level Security across the database. Access is enforced at the database layer, not just the application layer, so even if something went wrong at the application level, the data access rules still hold. Each organisation's data is isolated from every other.

    Encryption

    All data is encrypted in transit via TLS and at rest using AES-256. Passwords are salted and hashed rather than stored in any readable form, and the secrets the platform needs server-side are held in an encrypted secret store rather than in ordinary database columns.

    Authentication

    Authentication is handled through Supabase, supporting email and password or magic link sign-in. Multi-factor authentication with an authenticator app is available and can be enabled per user. Team owners and admins can see which of their members have turned it on.

    Backups and recovery

    We run regular backups with point-in-time recovery, which means we can restore the database to any specific moment rather than just the last scheduled snapshot.

    Infrastructure security

    Our infrastructure runs on Supabase, which holds SOC 2, HIPAA, and ISO 27001 certifications. Supabase works with external security experts to conduct regular penetration testing. DDoS protection runs at the CDN level through Cloudflare, with additional brute force protection and rate limiting applied on top.

    What data AI Sentri holds

    AI Sentri stores governance and operational data about your AI estate: system inventory records, ownership and approval trails, policy documents, risk register entries, ROI figures, governance posture scores, and the evidence your organisation generates through its review cycles.

    That does include personal data, and we would rather be plain about it than reassuring. We hold the name and email address of everyone with an account, and the names your team records against systems, policies, risks and KPIs as owners, sponsors and approvers. It is workplace contact and accountability information, so a subject access request would reach it, and we will help you answer one.

    What we do not hold is your customers' data, or special category data such as health or biometrics. The product is not built to store it and it should not be put there.

    Who else touches your data

    These are the only third parties involved in running the product. We do not sell data, and we do not share it with anyone not on this list.

    ProviderPurposeRegion
    SupabaseDatabase, authentication and serverless functionsUK (London)
    VercelApplication hosting and deliveryEU West (London)
    ResendTransactional email, such as invitations and notificationsEU / US
    Google AnalyticsTraffic measurement on the public marketing site only, never inside the productEU / US

    No payment card details are taken through the platform at all. Plans are invoiced directly, so there is no card data to store or process.

    Who can see what, and getting your data out

    • •Roles. Owners and admins manage members and settings; everyone else works within the organisation without those rights. Each organisation is a separate boundary in the database.
    • •Joining is by invitation. An invitation is bound to the address it was sent to and to the role it was issued with; neither can be altered by the person accepting it.
    • •Deletions are recorded. Removing records writes an audit entry, and that record survives the deletion of the thing it describes.
    • •Leaving. Deleting an organisation removes its data. You can export your estate, roadmap and action plan to PDF at any point before that, and we will help you get a fuller export if you ask.

    How we test our own security

    We ask our customers to evidence their AI governance, so we hold ourselves to the same standard. This work is continuous rather than an annual event.

    • •Automated static analysis. Our code is scanned continuously for security defects, with findings raised against the specific line that caused them.
    • •In-depth reviews. We run periodic reviews across the whole codebase, covering tenant isolation, access control, authentication and the public surfaces. Candidate findings are independently checked before they are accepted, so what we act on is verified rather than assumed.
    • •Fixes are proven, not presumed. Anything touching data access is reproduced first, fixed, then re-tested against a staging copy of the production database before it is promoted. We confirm the legitimate paths still work, not only that the problem is closed.
    • •The database is the boundary. Access rules live in the database rather than only in the application, and they are re-tested whenever they change.

    We do not publish the detail of individual findings. Describing an open weakness in public helps the wrong people first. If you are evaluating us and need more than this page offers, ask and we will go through specifics under NDA.

    Reporting a vulnerability

    If you believe you have found a security issue, email sales@lashandigital.co.uk with enough detail to reproduce it. We will acknowledge your report, keep you updated while we work on it, and credit you if you would like us to. We will not pursue legal action over good-faith research that respects other customers' data and does not degrade the service for them.

    AI Sentri certifications

    We don't currently hold our own SOC 2 or ISO 27001 certification. The platform is built on infrastructure that carries those certifications, and we've designed our own practices to align with those standards. Formal certification at the application level is on the roadmap. If you're in a procurement process that requires documentation, get in touch and we'll tell you what we can provide.

    Questions

    If you're doing a security review or want to understand how your data is handled, reach out and we'll give you a straight answer.

    sales@lashandigital.co.uk

    Before you start

    Questions about security

    Where is our data stored?

    In the UK. Data residency matters for governance records because they frequently contain commercially sensitive detail about systems, vendors and incidents, and because customers increasingly ask the question during due diligence.

    Are you ISO 27001 or SOC 2 certified?

    Not at application level, and we would rather say so than imply otherwise. The platform runs on infrastructure that carries SOC 2, ISO 27001 and HIPAA certification, and our own practices are designed to align with those standards. Formal certification of our own application is on the roadmap.

    How is access controlled?

    Row-level security in the database means one team cannot read another team’s records even if an application bug tried to let them, rather than access being enforced only in the interface. Multi-factor authentication is available to every account and we strongly recommend enabling it.

    Do you train AI models on our governance data?

    No. Your governance records are yours. They are not used to train models, and they are not shared with other customers.

    What happens to our data if we leave?

    You can export it, and we keep it available for export for thirty days after an account ends. After that period it may be permanently deleted — which is why we recommend exporting before you cancel rather than after.

    More in the full FAQ, or ask us directly.

    Your Privacy Matters

    We use cookies to provide essential functionality, analyse usage, and improve your experience. Under GDPR, you have the right to choose which cookies you allow. Strictly necessary cookies cannot be disabled. Privacy Policy