[ SECURITY DOSSIER ]
Zero data egress. Your VPC. Your logs.
Built for CISO review before purchase. Everything your security team needs to know, without the discovery call.
[ HOW IT SITS IN YOUR NETWORK ]
Proxy overhead: < 15ms p99 · No data leaves your VPC
Deploys in your VPC
SentnelOps runs inside your own infrastructure. The proxy lives in your network. MCP call parameters, tool responses, and logs never transit our servers.
Logs stored in your database
All call logs are written to your own database instance. We provide the schema and query tools. You own the data, full stop.
YAML policy enforcement
Policies are plain YAML files, version-controlled, GitOps-friendly, and testable in CI. Every tool call is evaluated against the policy before the MCP server sees it.
Zero trust by default
Every agent starts with no permissions. You explicitly grant what each agent can call, on which server, under which conditions. No implicit allowlisting.
SOC 2 audit export
The full call log — agent identity, tool name, parameters, timestamp, permit/block decision, policy matched — exports as CSV for your auditors. Structure built for SOC 2 Type II.
Human approval gates
Any policy rule can be set to require_approval instead of block. The call pauses, you get a Slack DM with full context, and the agent resumes only after your explicit approval.
⟨ RESPONSIBLE DISCLOSURE ⟩
Found a security issue? Email security@sentnelops.com with full details. We acknowledge within 24 hours and publish fixes within 30 days unless coordinated disclosure requires otherwise.