What we collect, what we never send anywhere, and how to exercise your rights.
Atlas and Ares clone your authorized repository into an isolated, run-to-completion task. Ares performs active, potentially mutative proof-by-exploitation testing only after DNS ownership verification. The task analyses it and destroys the workspace when the scan ends. Repository contents are never written to long-term storage and never used to train any Sentesting model.
When AI-assisted threat modelling is enabled, the model receives a structured summary only — language and framework names, counts, and the categories of issues found. It does not receive file contents, file paths, or code snippets.
Ares is different: it is a source-aware autonomous pentester. When you choose an Ares scan, authorized source context and live application interactions are processed by the configured AI model provider to plan and validate exploits.
Ares only tests hosts whose ownership you have verified, and Shield analyses APKs you upload. Scan results, findings, and generated reports are stored against your organisation so you can view history, and are deleted when you delete the scan or your account.
| Cookie / storage | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Supabase auth session | Keeps you signed in between page loads. | Strictly necessary — no consent required | Until sign-out or session expiry |
| sentesting.consent.v1 | Remembers your cookie choice so we stop asking. | Strictly necessary — records the choice itself | Until you clear site data |
| Vercel Analytics | Anonymous page-view counts to see which pages are used. | Consent — loaded only if you accept | Aggregated; no cross-site identifier |
Analytics does not load at all until you accept. Declining is not penalised and the product works identically either way.
Sentienta Technologies Private Limited is the data controller (Data Fiduciary under the DPDP Act, 2023). To exercise any right below, email privacy@sentesting.space. We respond within 30 days.