Security and data protection
This page lists what Centinel processes, the status of our security certifications and programs, and where to get the documents for a vendor review.
Trust CenterCertification and program status
ISO/IEC 27001
Certified
Our information security management system is certified to ISO/IEC 27001. The certification audit was carried out by TempoAudits, and the certificate is listed in the UKAS CertCheck register.
Check the certificate (opens in a new tab)SOC 2 Type 1
Program active
The Trust Center lists our SOC 2 Type 1 program. Request the current status and the report through the Trust Center.
Open the Trust Center (opens in a new tab)GDPR
Program active
Centinel Analytica GmbH is based in Berlin, Germany, and processes personal data under the GDPR. The data section below lists what detection processes.
Open the Trust Center (opens in a new tab)
What Centinel processes
Detection uses this data to separate automated traffic from visitors and to apply your access policy. The team also uses the stored requests to investigate detection results.
- Request data
- The IP address and the request headers of protected traffic, stored as received with the detection result. Headers can include cookies and authorization values. An IP address is personal data under the GDPR.
- Browser and session signals
- Where the integration collects them, browser and session signals add evidence about whether a visit is automated. Direct API clients do not send them.
- Dashboard accounts
- Names, email addresses, and sign-in details of the people on your team who use the dashboard.
Documents for your security review
Security policies
The Trust Center lists our policies by title, among them incident response and breach notification, encryption, access control, vulnerability and patch management, and backup and disaster recovery. Approved reviewers can download the documents; approval may require an NDA.
Data processing agreement and subprocessors
Ask for the data processing agreement and the subprocessor list during procurement. Processing and backup locations for your deployment are part of that review.
Vulnerability reports
Send a report through the contact form and mention security. We route it to the team that handles it.
Service availability is published on the status page (opens in a new tab).