Security
How CRA Sentinel is built
CRA Sentinel holds a description of the software you ship and a record of the decisions your team made about it. Both are sensitive. This page describes the controls that exist today — not intentions, and not certifications.
Controls
Eight things, all of them implemented
Password security
Session cookies
CSRF protection
Organisation isolation
Private document storage
Signed provider webhooks
Evidence-chain integrity
Backup restore verification
A deliberate refusal
Machine keys cannot make human decisions
API keys can automate ingest and reads. They are refused for the triage and reporting decisions the product attributes to a named person, and that refusal is enforced by the server rather than by omitting a button from an interface.
This is a security property and an evidential one. A record that says a person assessed a vulnerability should not be producible by a script holding a key.
What this page is not
These controls describe how CRA Sentinel is currently built. They are not a third-party certification or guarantee that security incidents are impossible.
CRA Sentinel does not hold SOC 2 attestation, ISO 27001 certification, a third-party penetration-test certificate, or any other external security audit, and this page does not claim any of them. If that changes, it will be stated here with the issuing body and date.