Sento is designed to process business communications, knowledge sources, CRM/context data, and Customer-configured actions. This page describes Sento's security approach at a level that does not depend on unverified certification or technology claims. Where a signed Security Addendum contains a more specific commitment, that signed commitment controls for the relevant Customer.
1. Security principles
Sento's security program is designed around the following principles:
- least-privilege access and role-appropriate authorization;
- logical separation of Customer workspaces appropriate to the production architecture;
- secure authentication and credential handling;
- protection of data in transit and at rest appropriate to the sensitivity and risk of the processing;
- logging and monitoring of security-relevant events;
- vulnerability and dependency management;
- backup and recovery controls appropriate to the applicable Service configuration;
- incident response and legally/contractually required Customer notification;
- vendor and Subprocessor risk management; and
- minimization of Customer Content in logs, troubleshooting, and support workflows.
2. Customer responsibilities
Customers must protect their credentials and API keys, use least-privilege permissions for connected systems, maintain supported configurations, review access granted to Authorized Users, and apply human approval or other safeguards to material automated actions where appropriate to the use case.
3. Security incidents
Where the DPA applies, Sento handles Personal Data breaches under the DPA and applicable law. A legally required processor-to-controller notice is based on Sento becoming aware of a qualifying Personal Data breach and does not depend on completion of a final root-cause analysis.
4. Vulnerability reporting
Security concerns should be reported through Sento's published security/contact channel. Sento may request information reasonably necessary to reproduce, assess, and remediate a reported issue. A vulnerability-reporting channel does not by itself create authorization to access data, disrupt the Service, evade access controls, or conduct testing prohibited by the Terms.
5. Certifications and assurance
Sento does not represent that it holds SOC 2, ISO 27001, PCI DSS, HIPAA, or another certification/attestation unless Sento expressly identifies a current status and its scope in writing. The absence of such a statement means no such certification is contractually represented.
6. Enterprise security commitments
Enterprise Customers may receive a Security Addendum describing agreed technical and organizational measures. Specific algorithms, retention windows, RPO/RTO values, audit commitments, or certification statuses are binding only when expressly stated in an executed agreement or published by Sento as a current verified commitment.