SENTIQ's information security practices are built on an independently audited ISO/IEC 27001 Information Security Management System. Below are the technical and organisational controls that protect our systems, our services and our customers' data.
Information security is run within a certified management system framework.
Personal data is processed in line with applicable national and international law.
Data is encrypted both in transit and at rest.
System access is limited to authenticated people holding only the privileges they need.
Hosting infrastructure is protected by network-level filtering and a current patching policy.
Backup and recovery processes run against the risk of data loss and service interruption.
Control effectiveness is verified regularly within the certification framework.
Security incidents follow a defined process, and there is an open channel for external reports.
This page is written to describe our security practices accurately and without overstatement. We are equally explicit about the assurances we do not hold:
We do not hold a SOC 2 (Type I / Type II) attestation report. Our independent security assurance rests on ISO/IEC 27001 certification.
We do not hold an independent third-party penetration test report. Control verification is carried out through ISO/IEC 27001 internal audits and surveillance audits.
Our infrastructure does not include a dedicated Web Application Firewall (WAF) layer. Network-level protection is provided by our hosting provider's filtering and DDoS mitigation capabilities.
For your vendor assessment processes we can complete detailed information security questionnaires and share additional documentation and evidence under a non-disclosure agreement.
Get in touch for vendor security assessments, information security questionnaires or non-disclosure agreement requests.
Contact Us Last updated: August 2026