Data processing agreement
Art. 28 GDPR · last updated 3 August 2026 · sub-processor list version 2026-08-05
Not yet reviewed by a lawyer. This states the obligations Art. 28(3) requires and describes what Sentris actually does, accurately. It has not been through legal review, and neither have the terms. If you need a countersigned agreement before you can buy, write to info@sentris.dev and you will get an honest answer about the timeline rather than a signature on something unreviewed.
To sign: print this page (your browser's print-to-PDF is enough — the layout is built for it), sign, and send it to the address above. There is no portal and no account manager.
You, the Sentris customer, are the controller. Sentris is the processor and acts only on your documented instructions — of which starting a scan is one.
1. Subject matter and duration
Sentris scans repositories and running applications the controller nominates, and reports the exposures it finds. Processing lasts for as long as the controller has an account or an active scan, and ends with clause 8.
2. Nature and purpose
Reading source code, configuration and SQL from a repository the controller connected; sending read-only requests to systems the controller proved they own; producing, storing and displaying findings. Nothing is processed for any purpose of the processor's own, and nothing is used to train a model.
3. Categories of data
Ordinarily processed: repository metadata (names, paths, commit references), file contents during a scan, findings, scan history, account email addresses, subscription status.
Incidentally:personal data the controller's own code or configuration happens to contain. Sentris does not look for it, and any secret it encounters is masked at the point of discovery — before it reaches the database, the interface, or a log line.
Never processed:the controller's end users' records. Findings state that a row was returned; they never contain the row.
Data subjects:the controller's personnel who hold Sentris accounts, and — only incidentally, as above — the controller's own end users.
4. Instructions
The processor acts only on the controller's documented instructions. Starting a scan, connecting a repository, storing credentials for an active check and switching on a feature that opens a pull request are each such an instruction, given through the interface. The processor will tell the controller if an instruction appears to infringe data protection law.
5. Confidentiality
Sentris is operated by one named individual, bound to confidentiality. There is no support team with database access, because there is no support team.
6. Technical and organisational measures (Art. 32)
- · TLS in transit throughout; HSTS on every response.
- · Passwords hashed with scrypt; API keys stored only as SHA-256 digests.
- · Repository access via short-lived, installation-scoped GitHub tokens the controller can revoke at any time without asking the processor.
- · Secrets found in a scan are masked at the point of discovery, so an unmasked value never exists in storage.
- · Row Level Security is enabled on every table of the processor's own database with no policies at all — deny-all to anon and authenticated roles.
- · Scan results are served behind unguessable URLs with
no-store, never framed, never indexed. - · Write access to a controller's repository is off by default and enabled per repository by the controller; it never targets a default branch and never merges.
- · Credentials the controller stores for active checks are encrypted at rest with AES-256-GCM under a key held outside the database.
7. Sub-processors
The controller gives general written authorisation for the sub-processors listed at /subprocessors, version 2026-08-05, currently Vercel Inc., Supabase Inc., GitHub, Anthropic PBC, Stripe, Resend, PostHog. The processor will notify account holders by email before a new sub-processor begins processing, and the controller may object. Each sub-processor is bound by equivalent obligations; transfers outside the EU/EEA and Switzerland rest on Standard Contractual Clauses, noted per row on that page.
8. Deletion and return
- · Repository file contents — held for the duration of a scan only. Never stored.
- · Findings and scan history — until the controller deletes the target or the account.
- · Stored test credentials — deleted on request, and automatically when the target is removed or the subscription ends.
- · Account data — removed within 30 days of account deletion.
- · Payment records — retained by Stripe for as long as accounting law requires.
9. Assistance
The processor assists the controller with data subject requests, with data protection impact assessments, and with notifying a personal data breach — the last without undue delay after becoming aware of one, and in any case in time for the controller to meet its own 72-hour obligation.
10. Audit
The processor makes available the information needed to demonstrate compliance with Art. 28 and permits audits by the controller or an auditor it mandates, on reasonable notice and at most once a year unless an incident warrants more. In practice most of what an audit would ask for is already public: the checks, the sub-processor list, the measured false-positive rate at /precision, and the corpus it was measured against.
11. Governing law
Swiss law, courts of Zurich, as stated in the terms. Nothing in this agreement limits the rights data subjects have under the GDPR or the revised Swiss FADP.
Sentris is evidence of technical measures taken. It is not evidence of GDPR compliance, and nobody selling a tool can issue that.