Skip to content
Security

Security and data protection

This page lists what Centinel processes, the status of our security certifications and programs, and where to get the documents for a vendor review.

Trust Center
Certifications and programs

Certification and program status

  • ISO/IEC 27001

    Certified

    Our information security management system is certified to ISO/IEC 27001. The certification audit was carried out by TempoAudits, and the certificate is listed in the UKAS CertCheck register.

    Check the certificate (opens in a new tab)
  • SOC 2 Type 1

    Program active

    The Trust Center lists our SOC 2 Type 1 program. Request the current status and the report through the Trust Center.

    Open the Trust Center (opens in a new tab)
  • GDPR

    Program active

    Centinel Analytica GmbH is based in Berlin, Germany, and processes personal data under the GDPR. The data section below lists what detection processes.

    Open the Trust Center (opens in a new tab)
Data

What Centinel processes

Detection uses this data to separate automated traffic from visitors and to apply your access policy. The team also uses the stored requests to investigate detection results.

Request data
The IP address and the request headers of protected traffic, stored as received with the detection result. Headers can include cookies and authorization values. An IP address is personal data under the GDPR.
Browser and session signals
Where the integration collects them, browser and session signals add evidence about whether a visit is automated. Direct API clients do not send them.
Dashboard accounts
Names, email addresses, and sign-in details of the people on your team who use the dashboard.
Vendor review

Documents for your security review

  • Security policies

    The Trust Center lists our policies by title, among them incident response and breach notification, encryption, access control, vulnerability and patch management, and backup and disaster recovery. Approved reviewers can download the documents; approval may require an NDA.

  • Data processing agreement and subprocessors

    Ask for the data processing agreement and the subprocessor list during procurement. Processing and backup locations for your deployment are part of that review.

  • Vulnerability reports

    Send a report through the contact form and mention security. We route it to the team that handles it.

Service availability is published on the status page (opens in a new tab).