Skip to main content
SpaceTime IndustriesBack to Home
Security Overview

Security at SpaceTime Industries

Last updated: June 2026

Security is not an afterthought at SpaceTime Industries — it is foundational to everything we build. Sentinel OS processes sensitive threat intelligence data for critical infrastructure operators and government agencies. This page describes how we protect that data and the systems that handle it.

Zero Trust Architecture
Every request is authenticated and authorized. No implicit trust based on network location.
Encryption Everywhere
AES-256 at rest, TLS 1.3 in transit. All data encrypted before it touches disk.
Continuous Monitoring
24/7 threat detection, anomaly alerting, and incident response via PagerDuty and Slack.
Tenant Isolation
Strict multi-tenant boundaries. Your data is never accessible to other tenants.

1. Security Architecture

Multi-Tenant Isolation

Sentinel OS is designed with strict tenant isolation at every layer of the stack. Each customer organization operates in a logically isolated environment:

Role-Based Access Control (RBAC)

Access within an organization is controlled by RBAC:

JWT RS256 Token Authentication

All API and dashboard sessions are protected by JSON Web Tokens signed with RS256 (RSA + SHA-256):

2. Authentication

Password Security

Multi-Factor Authentication (MFA)

Single Sign-On (SSO)

Professional and Enterprise plans support SSO via:

SSO sessions respect your identity provider’s session policies. Account provisioning and de-provisioning can be automated via SCIM 2.0 for Enterprise customers.

API Keys

3. Data Protection

ZeroDB — Vector and Document Storage

Sentinel OS uses ZeroDB for vector embeddings, semantic search, and document storage. ZeroDB applies encryption at the storage layer using AES-256-GCM. Tenant data is partitioned by namespace with strict access controls enforced at the API level.

S3-Compatible Object Storage

Raw data, threat intelligence exports, and long-term archives are stored in S3-compatible object storage with:

Audit Logging

All security-relevant events are captured in immutable audit logs:

Audit logs are retained for a minimum of 12 months (24 months for Enterprise) and are available for export from your dashboard.

4. Network Security

5. Vulnerability Management

Dependency Scanning

All production dependencies are continuously scanned for known vulnerabilities using automated tools integrated into our CI/CD pipeline. Critical and high-severity vulnerabilities trigger immediate alerts and remediation workflows.

Security Patches

We maintain a security patch SLA:

Penetration Testing

SpaceTime Industries conducts annual third-party penetration testing of the Sentinel OS platform. Findings are remediated based on severity. Enterprise customers may request access to test summary reports under NDA.

Secure Development

6. Compliance

SOC 2 Type IIIn Progress
GDPRReady
CCPAReady
ISO 27001Planned
FedRAMPPlanned

SOC 2 Type II (In Progress)

SpaceTime Industries is actively pursuing SOC 2 Type II certification covering Security, Availability, and Confidentiality trust service criteria. Our audit period begins Q3 2026. Enterprise customers requiring compliance documentation should contact legal@usesentinel.io.

GDPR Readiness

Sentinel OS is designed with GDPR compliance in mind:

Data Residency

Enterprise customers with data residency requirements can request EU or US data residency. Data residency configurations ensure that your Customer Data remains within your specified region. Contact sales for availability and pricing.

7. Incident Response

SpaceTime Industries maintains a formal incident response program to detect, contain, and remediate security incidents:

Detection and Alerting

Response Process

8. Responsible Disclosure

We believe that working with security researchers improves the security of our platform for everyone. If you have discovered a security vulnerability in Sentinel OS or any SpaceTime Industries system, we encourage responsible disclosure.

Security Contact

Email: security@usesentinel.io

Please encrypt sensitive vulnerability reports using our PGP key, available upon request. We will acknowledge your report within 48 hours and provide updates as we investigate.

Disclosure Guidelines

When reporting a vulnerability, please:

Researchers who follow these guidelines will receive our cooperation and recognition. We do not pursue legal action against researchers acting in good faith.

9. Bug Bounty

Coming Soon
Formal Bug Bounty Program

We are launching a formal bug bounty program with monetary rewards for qualifying vulnerability reports. The program will cover the Sentinel OS API, dashboard, authentication systems, and infrastructure. Sign up at security@usesentinel.io to be notified when the program launches.

Questions About Security

For security questions, compliance documentation requests, or to report a vulnerability:

SpaceTime Industries, Inc.

Security: security@usesentinel.io

General: legal@usesentinel.io

Website: usesentinel.io