sentesting
FeaturesPricingAboutBlogFAQsContact
Log inStart free →
Security

How we protect your code

We ask customers to trust us with source code and live systems. Here is what that trust rests on.

Controls

What is actually in place

Your code is never executed

Atlas parses repositories to an AST. It does not install dependencies, run build scripts, or evaluate configuration. A hostile repository cannot execute code on our infrastructure.

Workspaces are destroyed after each scan

Repositories are cloned into an isolated, run-to-completion task and the workspace is discarded when it ends. Code is never written to long-term storage.

Aggressive testing is authorization-gated

Ares requires both an approved source repository and DNS-verified host before testing starts. Scope and address checks block private, loopback, link-local, and cloud-metadata ranges. Because testing is intentionally aggressive, the product directs customers to disposable staging environments, never production.

Tenant isolation in the database

Every organisation-owned table has row-level security, so a query can only ever return rows for organisations the caller belongs to. This is enforced by Postgres, not application code.

Least-privilege credentials

Each service holds only the secrets it needs, stored in AWS Secrets Manager and injected at task start. Engine tasks hold no AWS permissions at all.

Findings are redacted

Evidence captured with a finding passes through redaction before storage, so tokens and credentials observed during a scan are not persisted verbatim.

Disclosure

Reporting a vulnerability

If you believe you have found a security issue in Sentesting, email security@sentesting.space. Include enough detail to reproduce it.

  • • We acknowledge reports within 3 working days.
  • • We will tell you our assessment and expected timeline within 10 working days.
  • • We will not pursue legal action against good-faith research that follows this policy.
  • • Please do not access other customers’ data, degrade the service, or run automated scans against our production systems while testing.
  • • We will credit you when the issue is resolved, unless you prefer otherwise.

We do not currently run a paid bug bounty.

Honesty

What we have not done yet

We would rather be accurate than impressive. Sentesting is a young product and the following are not yet true:

  • • We do not hold SOC 2, ISO 27001, or any third-party security certification.
  • • We have not had an independent penetration test of the platform.
  • • We do not offer a contractual uptime SLA on self-serve plans.

Our reports are built to support your SOC 2 or ISO evidence gathering. That is different from us being certified, and we will not imply otherwise.

sentesting

Autonomous application-security testing — static, dynamic, mobile, and on-device runtime — in one platform. Find what attackers would, and prove it.

Product
FeaturesPricingAtlas · SASTAres · DASTShield · MobileAegis · Runtime
Company
About usBlogContact
Resources
FAQsDashboardSecuritySupport

© 2026 Sentienta Technologies Private Limited. Sentesting is a product of Sentienta Technologies.

Privacy · Terms · Security