Solutions References Company About Certificates Security Careers Partners Contact Get a Quote
TR EN RU AR DE

Our Security Approach

SENTIQ's information security practices are built on an independently audited ISO/IEC 27001 Information Security Management System. Below are the technical and organisational controls that protect our systems, our services and our customers' data.

ISO/IEC 27001 ISO 9001 KVKK Compliant GDPR Compliant

Governance & Certification

Information security is run within a certified management system framework.

  • ISO/IEC 27001 Information Security Management System certificate
  • ISO 9001 Quality Management System certificate
  • Independent audit by an accredited certification body
  • Periodic internal audit, management review and corrective action cycle

Data Protection & Regulation

Personal data is processed in line with applicable national and international law.

  • Data controller obligations under Turkish Law No. 6698 (KVKK)
  • Processing aligned with EU General Data Protection Regulation (GDPR) principles
  • Data is stored in secure environments within Türkiye
  • Purpose limitation, data minimisation and defined retention periods

Encryption

Data is encrypted both in transit and at rest.

  • Encryption in transit: all web traffic is served over HTTPS/TLS
  • Encryption at rest: databases and file storage
  • Backups are stored in encrypted form

Access Control

System access is limited to authenticated people holding only the privileges they need.

  • Multi-factor authentication (MFA) on administrative accounts
  • Role-based access control (RBAC) and least-privilege principle
  • Regular review of granted permissions
  • Prompt revocation of access for departing personnel

Infrastructure & Network Security

Hosting infrastructure is protected by network-level filtering and a current patching policy.

  • Network filtering and DDoS mitigation at the hosting provider level
  • Regular application of operating system and component updates
  • Browser security headers: X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy

Backup & Business Continuity

Backup and recovery processes run against the risk of data loss and service interruption.

  • Regular, automated backups
  • Backups verified through restore testing
  • Backups kept in a separate, encrypted environment

Security Testing & Verification

Control effectiveness is verified regularly within the certification framework.

  • Periodic internal audits under ISO/IEC 27001
  • Surveillance audits by the certification body
  • Corrective action and re-assessment cycle for findings
  • Regularly updated risk assessment

Incident Response & Vulnerability Reporting

Security incidents follow a defined process, and there is an open channel for external reports.

  • Defined security incident response process and incident logging
  • Notification to the Authority and affected individuals within KVKK-mandated timeframes for personal data breaches
  • Vulnerability reports: info@sentiqly.com
  • Good-faith reports are reviewed and the reporter receives a response

Scope & Transparency

This page is written to describe our security practices accurately and without overstatement. We are equally explicit about the assurances we do not hold:

We do not hold a SOC 2 (Type I / Type II) attestation report. Our independent security assurance rests on ISO/IEC 27001 certification.

We do not hold an independent third-party penetration test report. Control verification is carried out through ISO/IEC 27001 internal audits and surveillance audits.

Our infrastructure does not include a dedicated Web Application Firewall (WAF) layer. Network-level protection is provided by our hosting provider's filtering and DDoS mitigation capabilities.

For your vendor assessment processes we can complete detailed information security questionnaires and share additional documentation and evidence under a non-disclosure agreement.

Get in touch for vendor security assessments, information security questionnaires or non-disclosure agreement requests.

Contact Us Last updated: August 2026