Everything your vendor-risk file needs
Sentrix is built to pass a bank, PSP or acquirer procurement review. Here is the security, legal and deployment picture in one place — with a clear line between what runs today and what is on the roadmap.
Security & due-diligence review
Security questionnaires
We complete standard vendor-security and due-diligence questionnaires. Send yours to compliance@sentrix.world and we'll return it with supporting evidence.
Architecture walkthrough
A working session for your security and risk teams covering data flow, controls, hosting and the attestation roadmap.
Documentation package
The security, compliance and legal documents above, provided as a set for your vendor-risk file.
Roadmap transparency
A straight answer on what is live versus planned — SSO/SAML, four-eyes approval, WORM/hash-chained audit and data residency are on the roadmap and we will not represent them as shipped.
Documentation package
The documents a procurement and security team asks for, ready to review before signature.
Information Security overview →
Technical & organisational measures: encryption, RBAC, tenant isolation, application security and vulnerability disclosure.
Regulatory & Compliance posture →
UAE PDPL & AML/CTF alignment, FATF, obligation mapping and the attestation roadmap.
Data Processing Addendum →
Controller/processor terms, security annex and sub-processing — ready to review before signature.
Sub-processors →
Infrastructure sub-processors by category, purpose and region, with change notification.
Terms of Service →
Master terms, governing law and the contracting entity's registered particulars.
Responsible Disclosure →
How vulnerabilities are reported and our safe-harbour commitment.
Deployment model
What the platform is today, and what is planned. Roadmap items are never represented as shipped.
| Capability | Detail | Status |
|---|---|---|
| Hosting | Multi-tenant SaaS on Vercel (edge/serverless) with Neon Postgres, in a single primary region today. | Live |
| Tenant isolation | Logical per-workspace separation, enforced on every request against the authenticated workspace. | Live |
| Access | Email + password with Argon2 hashing and server-enforced RBAC (owner / manager / analyst / viewer). | Live |
| SSO / SAML & SCIM | Federated sign-in and provisioning for Institution plans. | Roadmap |
| Data residency | Customer-selectable region, including UAE-region hosting. | Roadmap |
| Four-eyes approval | Dual control on high-impact overrides and dispositions. | Roadmap |
| Tamper-evident audit | Hash-chaining / WORM export over the append-only audit trail. | Roadmap |
Service levels & support
Operate and Institution plans are backed by a support SLA with defined response targets by severity; the specific availability and response commitments are set out in the Order Form and service schedule for your plan. Operational status is published at /status, backed by a programmatic health endpoint. Named technical contact is available on the Institution tier. We do not publish an availability figure we cannot stand behind — the committed number is contractual and plan-specific.
Onboarding
- 01
Briefing & scoping
A walkthrough mapped to your operation, and confirmation of scope, plan and any roadmap dependencies.
- 02
Security & legal review
Questionnaire, documentation package and DPA review; architecture session with your security team.
- 03
Sandbox & integration
A workspace to author rules, connect sandboxed providers and integrate the decisioning API against simulated traffic.
- 04
Go live
Under an executed Order Form, with production providers connected and RBAC configured for your team.
Start a procurement review
Send a questionnaire to compliance@sentrix.world or security@sentrix.world, or book a briefing to begin.