1. Scope, Definitions & Processor Status
This Privacy Policy sets forth the technical and organizational commitments of Sentrium Infrastructure Technologies Inc. ("Sentrium", "we", "us", or "our") regarding the collection, transmission, evaluation, storage, and erasure of information processed via our AI agent governance platform, sidecar agents, and reverse proxy gateways (the "Platform").
Under Regulation (EU) 2016/679 (the General Data Protection Regulation or "GDPR") and the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"), Sentrium operates strictly as a Data Processor (or "Service Provider") with respect to all customer telemetry, tool parameters, prompt contexts, and audit records processed on behalf of our enterprise customers ("Customers"). The Customer remains the sole Data Controller (or "Business") and retains full, unencumbered ownership of all data.
2. Absolute Zero-Model-Training Guarantee
Sentrium’s business model is exclusively software licensing and enterprise infrastructure subscription fees. We do not sell data, monetize telemetry, or develop proprietary consumer foundation models.
- No Model Training: Neither Customer Content nor Intercepted Telemetry will ever be used, disclosed, or processed to train, retrain, calibrate, fine-tune, or validate any large language model, machine learning classifier, or heuristic neural network belonging to Sentrium or any third party.
- No Cross-Tenant Data Leakage: All policy evaluations are executed in isolated memory spaces segregated by cryptographic customer tenant IDs. Telemetry from Customer A cannot inform heuristics or state tables for Customer B.
- Zero Storage of Raw Payloads by Default: Unless the Customer explicitly activates the Cryptographic Audit Log retention subsystem in their tenant configuration, tool call payloads are evaluated ephemerally in RAM and wiped immediately upon socket transmission or termination.
3. Explicit Cryptographic & Encryption Standards
Sentrium enforces rigorous cryptographic safeguards across all data handling layers in accordance with NIST Special Publication 800-52 Rev. 2 and FIPS 140-3 compliance guidelines:
- Data in Transit: All communication between agent clusters, Sentrium sidecars, edge reverse proxies, and third-party APIs is encrypted using Transport Layer Security (TLS) 1.3. Earlier protocols (TLS 1.0, 1.1, and 1.2 with non-PFS ciphers) are strictly rejected. Supported cipher suites are restricted to
TLS_AES_256_GCM_SHA384andTLS_CHACHA20_POLY1305_SHA256utilizing elliptic curve Diffie-Hellman ephemeral key exchanges (ECDHE with X25519 or P-384 curves) ensuring Perfect Forward Secrecy. - Data at Rest: Any persistent audit logs, policy manifests, or cached session tokens are encrypted using AES-256-GCM (Advanced Encryption Standard in Galois/Counter Mode) with 256-bit symmetric keys. Customers on Scale and Enterprise tiers may supply customer-managed encryption keys (CMEK) via AWS KMS, GCP Cloud KMS, or HashiCorp Vault.
- Cryptographic Tamper-Evidence: Audit log chains utilize SHA-256 Merkle tree hashing, generating a deterministic, immutable proof-of-action chain where any retroactive tampering invalidates the mathematical signature of the entire ledger.
4. Data Ingestion & Types of Information Processed
The Sentrium Platform processes three categories of data:
- Account & Administrative Metadata: Name, corporate email address, billing address, IP address of console users, and Single Sign-On (SSO) identity tokens necessary to administer tenant clusters.
- Operational Telemetry: Anonymized timestamps, agent instance identifiers, tool name strings (e.g.
stripe.charges.create), latency measurements, and HTTP status codes necessary to generate operational dashboards and ensure SLA commitments. - Tool Execution Payloads (Ephemeral): The JSON-formatted arguments and responses exchanged between your autonomous agents and external APIs. This data is examined in-memory to execute DLP rules, regex masking, and AST parameter checks, and is purged immediately unless persistent logging is configured.
5. Statutory Rights Under GDPR (European Union / UK)
To the extent Sentrium processes personal data subject to the GDPR, individuals ("Data Subjects") are entitled to exercise the following statutory rights under Chapter III:
- Right of Access (Article 15): Obtain confirmation as to whether personal data is processed and request certified machine-readable copies.
- Right to Rectification (Article 16): Require correction of inaccurate personal data without undue delay.
- Right to Erasure / "Right to be Forgotten" (Article 17): Mandate the permanent cryptographic erasure of personal data where retention is no longer necessary.
- Right to Restriction of Processing (Article 18): Suspend the processing of personal data during ongoing dispute resolutions.
- Right to Data Portability (Article 20): Receive personal data in a structured, commonly used, and machine-readable format (JSON/CEF).
- Right to Object (Article 21): Object to processing based on legitimate interests.
Requests to exercise GDPR statutory rights should be directed to our dedicated Data Protection Officer at support@sentrium.tech. We respond to verified data subject requests within 30 calendar days without fee.
6. Statutory Rights Under CCPA / CPRA (California Residents)
Pursuant to the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.):
- No Sale or Sharing of Personal Information: Sentrium does not sell, rent, or lease personal information to third parties, nor do we share personal data for cross-context behavioral advertising.
- Right to Know and Delete: California residents have the right to request disclosure of categories of personal information collected, sources, business purposes, and specific pieces of data held, as well as the right to request verified deletion.
- Non-Discrimination: Sentrium will never discriminate against any customer or user for exercising their statutory rights under the CCPA/CPRA.
7. Data Retention Schedules & Automated WORM Purging
Sentrium adheres to strict data minimization schedules:
- Ephemeral In-Memory Payloads: Discarded within < 50ms upon completion of policy evaluation.
- Team Gateway Audit Logs: Cryptographically retained for exactly 14 calendar days, after which automated WORM (Write Once, Read Many) lifecycle rules purge keys and raw records.
- Scale Cluster Audit Logs: Retained for 90 calendar days by default, or streamed directly to customer-owned object storage (AWS S3, Google Cloud Storage, Azure Blob).
- Enterprise Audit Logs: Configurable from 30 days to 7 years in compliance with SEC Rule 17a-4, FINRA Rule 4511, and EU AI Act Article 12 mandates.
8. Approved Infrastructure Subprocessors
Sentrium utilizes high-assurance infrastructure subprocessors certified under SOC 2 Type II and ISO 27001:
- Amazon Web Services Inc. (AWS): Cloud compute, KMS encryption, and multi-region consensus infrastructure (US-East-1, EU-West-1).
- Google Cloud Platform (GCP): High-throughput regional edge proxy clusters and zero-trust IAM.
- Cloudflare Inc.: Anycast edge routing, DDoS mitigation, and TLS termination.
9. Data Protection Officer & Inquiries
For inquiries regarding our cryptographic architecture, compliance certifications, Data Processing Addenda (DPA), or to exercise statutory privacy rights, contact our Data Protection Office:
Email: support@sentrium.tech
Statutory Escalation Turnaround: Within 72 hours for privacy escalations.