Security

Security-First. Australian-Hosted. Defensible by Design.

SentinelOps is built from the ground up to protect investigation data with the same rigour applied to the investigations themselves. Every architectural decision is made to protect the confidentiality of what you hold and the integrity of what you can later prove.

Security-First Architecture

Investigation data is among the most sensitive information any organisation holds. SentinelOps treats security as a foundational architectural requirement, not a feature added after the fact.

Encryption In Transit and At Rest

Case records, evidence files, attachments and audit logs are encrypted where they are stored and encrypted whenever they move. Encryption is applied across the whole data lifecycle, not selectively to some record types.

Australian Data Sovereignty

All data hosted exclusively within Australian data centres. No offshore replication, no foreign jurisdiction access. Your investigation data stays in Australia, governed by Australian law.

Immutable Audit Trails

Every action is written to a tamper-evident, append-only record, including who opened and viewed a file. Records are cryptographically chained, so any later alteration, deletion or reordering breaks the chain and is detectable.

Role-Based Access Controls

Granular, role-based permissions ensure users only access investigation data relevant to their function. Compartmentalised case access prevents unauthorised visibility across investigations.

Authentication & SSO

Multi-factor authentication is enforced for every user. It is not a setting an administrator can turn off. Sessions are time-limited and expire on inactivity.

Built for Australian Obligations

Designed around the security expectations Australian government, critical infrastructure and regulated organisations are assessed against, with a documented information security management system and a control summary available to your assurance team on request.

Data Sovereignty & Australian Hosting

For Australian organisations conducting investigations under Australian law, data sovereignty is not a preference. It is an operational and legal requirement. Investigation data frequently contains personal information governed by the Privacy Act 1988, sensitive employee records subject to the Fair Work Act 2009, and material that may be subject to legal professional privilege or statutory secrecy obligations.

SentinelOps hosts all customer data exclusively within Australian data centres. This is not a regional deployment option or a premium tier feature. It is the only deployment model. There is no offshore data replication, no foreign-jurisdiction backup storage, and no cross-border data transfer. Your investigation data remains subject to Australian law and Australian privacy protections at all times.

Data residency is a precondition of the obligations Australian government and regulated organisations carry, including those set out under the Protective Security Policy Framework (PSPF) and the Australian Government Information Security Manual (ISM). SentinelOps meets that precondition by default rather than by configuration, which removes a category of risk your team would otherwise have to manage and evidence. Organisations subject to the Security of Critical Infrastructure Act 2018 (SOCI Act) can deploy SentinelOps knowing data residency requirements are satisfied from day one.

Encryption Standards

Encryption at Rest

All data stored within SentinelOps is encrypted at rest using current strong-encryption standards. This covers case records, evidence files, attachments, notes, communications, and audit logs - there is no category of stored investigation data that sits unencrypted. Encryption keys are held separately from the data they protect, and access to key material is restricted to the platform itself rather than to any individual operator. The specific algorithms, key lengths and key-handling arrangements are documented in our security questionnaire response, provided to prospective customers on request.

Encryption in Transit

All data moving to, from and within SentinelOps travels over an encrypted, authenticated channel using current transport security standards. This applies to browser sessions, programmatic access, integrations, and communication between internal services - there is no internal network segment over which investigation data moves in the clear. Deprecated protocol versions are not accepted. Exact protocol versions and cipher configuration are supplied in our security questionnaire response.

Evidence and Attachment Security

Evidence files and attachments receive additional treatment beyond storage encryption. Every file is fingerprinted with a cryptographic hash at the moment of upload, and that fingerprint can be re-verified at any later point. If a single byte of an evidence file changed, the fingerprint would no longer match and the discrepancy would be visible. This gives you a chain of custody you can demonstrate to a tribunal or court - not an assertion that evidence is unaltered, but a mechanism that lets you prove it.

Role-Based Access Controls

Investigation data requires access controls that go beyond standard role-based permissions. SentinelOps enforces separation between customer organisations at the data boundary itself. Every request is constrained at the point data is retrieved, so a request can only return records belonging to the organisation that made it. This matters because cross-tenant exposure in multi-customer platforms usually traces back to a single missed check in application logic - a class of failure this approach is designed to remove rather than mitigate.

Within an organisation, roles define what each user can do, and case-level permissions allow investigation leads to further restrict access on a per-case basis. Sensitive matters - executive misconduct, whistleblower disclosures, covert work - can be compartmentalised so they are not visible to the general investigation team.

All access control changes are logged in the immutable audit trail, creating a complete record of who had access to what data and when. This is critical for demonstrating compliance with privacy obligations and for responding to discovery requests or regulatory inquiries about data handling practices.

Immutable Audit Trail Security

The audit trail is the evidentiary backbone of any defensible investigation. SentinelOps implements tamper-evident, append-only audit logging that records every action performed within the platform: case creation, evidence uploads, note additions, status changes, permission modifications, and report generation. It also records read access. When someone opens a piece of evidence, that viewing is recorded and attributed to a named individual. Most systems can tell you who changed something. In a whistleblower matter, a privilege dispute or an internal leak, the question that actually gets asked is who looked - and that is a question this platform can answer.

Audit records are cryptographically chained, meaning any attempt to modify, delete, or reorder historical records would break the cryptographic chain and be immediately detectable. This approach mirrors the integrity techniques used in digital forensic evidence handling, so an audit trail presented to a regulator, tribunal or court can be independently checked for signs of alteration rather than simply taken on trust.

Audit records are retained for the life of your engagement with the platform, and are not pruned or summarised as a matter of routine operation. Because every entry is attributed to a named individual and carries its position in the cryptographic chain, the record you produce years later is the same record that was written at the time. Retention arrangements for organisations with specific regulatory obligations are agreed as part of onboarding.

Authentication & Single Sign-On

Multi-factor authentication is enforced by default for every SentinelOps user. It is not an optional setting and cannot be disabled at the tenant level. Second factors are time-based one-time codes from a standard authenticator application.

Enterprise organisations can integrate SentinelOps with their existing identity provider using standards-based single sign-on, so platform access inherits the authentication policy and joiner-mover-leaver process you already operate.

Sessions are time-limited and expire on inactivity. Every authentication event - successful or not - is written to the audit trail alongside the individual it belongs to, so account activity is reviewable in the same evidentiary record as case activity.

Compliance & Framework Alignment

Australian Cyber Security Centre Essential Eight

The Essential Eight Maturity Model published by the Australian Cyber Security Centre is a control set for organisations hardening their own environments, and several of its mitigations - application control, macro settings, user application hardening - apply to your endpoint fleet rather than to a hosted platform. Where the Essential Eight does bear on a platform like ours, SentinelOps supports it directly: administrative privileges are tightly restricted, application dependencies are checked for known vulnerabilities before every release, and backups are taken and have been restore-tested. SentinelOps has not been assessed against a specific Essential Eight maturity level and does not claim one.

Australian Government Information Security Manual (ISM)

The Australian Government ISM sets the information security expectations for government entities and their service providers. SentinelOps is built with those expectations in view - Australian-only data residency, restricted administrative access, encryption of data at rest and in transit, and a complete attributable audit record. We provide a written control summary to government and critical infrastructure buyers on request so your assessors can evaluate the platform against the specific controls in scope for your environment.

ISO 27001

SentinelOps operates a documented information security management system built to ISO/IEC 27001, the international standard for information security management. It governs how we identify, assess and treat information security risk across the platform lifecycle, and it is the source of truth for every security statement we make publicly, including this page. To be unambiguous: SentinelOps is not currently ISO 27001 certified. Certification is in progress and we will say so here on the day it is achieved, and not before.

Infrastructure

SentinelOps runs on enterprise-grade Australian cloud infrastructure. The underlying data centre facilities are operated by a major infrastructure provider that holds its own independent security certifications - those certifications belong to the facility operator, not to SentinelOps, and we do not present them as ours. All processing and all storage occur within Australia. No part of the platform, and no copy of your data, sits outside Australian jurisdiction.

The platform is segmented with enforced boundaries between components, so systems handling live investigation data are isolated from those that do not. Administrative access is restricted to a small number of named individuals and requires strong non-password authentication. Repeated unauthorised access attempts are automatically blocked. Every code change is automatically checked for known-vulnerable dependencies and for common classes of security defect before it is able to reach production.

Backups are encrypted and held in Australia, with two independent backup mechanisms rather than one: a daily backup of the case database, and separate versioned copies of stored evidence captured multiple times each day. Restoration has been tested against a real backup, not assumed. Defined recovery objectives are documented and are provided to customers, with the arrangements that apply to your organisation set out in your agreement.

Security FAQ

Where is SentinelOps data hosted?

All SentinelOps data is hosted exclusively within Australian data centres. There is no offshore replication or cross-border data transfer. This is not a configurable option; it is the only deployment model. Your investigation data remains subject to Australian law at all times.

Can SentinelOps be deployed in our own environment?

SentinelOps is delivered as a managed Australian-hosted service, with customer data separated at the data boundary rather than by shared application logic. For organisations with specific data handling requirements or their own hosting mandates, contact our team - we will work through what your security policy and regulatory obligations require before proposing an arrangement.

Does SentinelOps comply with Australian Government security requirements?

SentinelOps is built with Australian Government ISM expectations in view, including Australian-only data residency, restricted administrative access, encryption at rest and in transit, and a complete attributable audit record. We provide a written control summary on request so your assessors can evaluate the platform against the controls in scope for your environment. SentinelOps has not been assessed against a specific Essential Eight maturity level and does not claim one.

How are audit trails protected from tampering?

Audit trails are implemented as tamper-evident, append-only logs with cryptographic chaining. Each record is linked to the one before it, so any attempt to modify, delete or reorder history breaks the chain and becomes detectable rather than passing unnoticed. Read access is captured as well as changes, so the record shows who viewed a piece of evidence and when. This is what allows an audit trail to be relied on in regulatory proceedings and legal matters: not a promise that nobody tampered with it, but a mechanism that would reveal it if they had.

Your Next Investigation Deserves Better

See how SentinelOps transforms investigation management in a 30-minute investigator-led walkthrough. No sales pitch. Just the platform, your questions, and straight answers.

Currently serving Australian enterprise, government, and regulated industry organisations.