Trust
Security Statement
Last updated: 15 July 2026
SentraRisk Systems is designed to help organisations review transaction risk with clear access controls, auditability, and customer-controlled data handling.
Account and Access Controls
SentraRisk supports business account structures with administrative controls for managing users, roles, account access, protected routes, and API keys. Administrators are responsible for creating, reviewing, and revoking access for their organisation.
API Key Management
Organisation administrators can create and revoke API keys used to connect SentraRisk to business systems. Customers should protect API keys, rotate them when needed, and revoke keys that are no longer required.
Audit and Review History
The platform includes audit logs, alert review status, reviewer notes, control pack records, decision memos, transaction reports, and review history to support accountable decision-making and internal review.
Hosting, Encryption, and Backups
Where technically available and configured, SentraRisk may use HTTPS, secure hosting practices, provider-level encryption controls, restricted support access, logging, data minimisation controls, and database backup procedures. Customers remain responsible for downloaded reports, exports, local files, and records held outside the platform.
Local and Customer Environment Security
SentraRisk may run through a mix of cloud services and local or customer-controlled environments. Customers are responsible for securing their own infrastructure, local profiles, devices, credentials, backups, network access, and data-handling procedures.
Data Control
SentraRisk is designed so customer transaction data can remain within the customer's controlled environment where applicable. Account, security, billing, and access-control data may be processed as needed to operate the service.
Human-Led Decisions
Risk scores, fraud indicators, and alerts are decision-support tools. Customers remain responsible for human review, investigations, and final business decisions.
Security Reviews
Customers can request reasonable security information for procurement or due diligence. Deep technical review, penetration testing, audit access, or review of confidential platform methods must be agreed in writing and scoped so it does not compromise other customers, platform security, source code, risk logic, or trade secrets.