Subprocessors & Security
Every third party that touches data on our behalf, what it sees and where it is, plus what we actually do to keep things secure. Referenced from the Privacy Policy so the list stays current.
Table of Contents
1. Purpose
This page lists every third party that processes data on SentinelGrid's behalf, and describes the security practices we actually follow. It is referenced from the Privacy Policy and Terms of Service and is maintained separately so that the policies do not go stale every time infrastructure changes. Managed IT clients are notified by email when a subprocessor is added.
2. Subprocessors
Infrastructure and hosting:
- Cloudflare, Inc.: Hosting for every SentinelGrid service: Workers (application code), D1 (databases for the Portal, Helpdesk, Monitor and Fleet), Workers KV (inbound email store, sessions), R2 (object storage and backups), Email Routing (inbound mail for sentinelgrid.us), DNS, TLS, Tunnel (private access to self-hosted services), edge cache for the CDN, and Workers AI (internal planning and review text only).
Handles: all application data, inbound email, request logs · Location: United States; global edge network - GitHub (Microsoft): Source-code hosting for every service. No customer data is stored in repositories.
Handles: code, deployment configuration · Location: United States
Communications:
- Brevo (Sendinblue SAS). Transactional email: sign-in links, ticket notifications, form acknowledgements, outage alerts, HR mailbox replies.
Handles: recipient address, subject, message body · Location: European Union - Pushover (Superblock, LLC): Push notifications to SentinelGrid on-call staff when a monitor goes down.
Handles: monitor name and status; no client personal data · Location: United States - Google LLC: Google Analytics 4 on the website; Google Fonts on all pages.
Handles: pseudonymous usage data, IP address, browser details · Location: United States
Payments:
- Stripe, Inc.: Payment processing and billing for managed IT plans and one-off invoices. Card details are entered on Stripe-hosted pages and never reach a SentinelGrid system; we hold only a reference to your Stripe customer record. Stripe issues invoices, stores payment methods, and holds the authoritative record of what has been paid.
Handles: billing contact name and email, business address, plan and quantities, invoice amounts and status, card brand and last four digits, payment history · Location: United States
Managed IT tooling:
- Tailscale Inc.: Private network coordination for access to the fleet server, SentinelVision dashboards and client internal systems. Tailscale coordinates connections; traffic itself is end-to-end encrypted between devices.
Handles: device identities, public keys, IP addresses · Location: Canada / United States - MeshCentral (self-hosted): Remote access and device management server. Open source, run by us on our own infrastructure, not a third-party service. Listed for transparency.
Handles: device inventory, remote-session logs · Location: SentinelGrid-operated
Development tooling (no client data):
- Anthropic, PBC: Claude, used as an AI development tool to help write, review and document our software, websites and documents. Used under terms that do not train on our inputs. Client data is not put into it without the client's written agreement for a specific engagement, so it is not a processor of client data; it is listed here so the statement can be checked.
Handles: our own source code, copy and drafts · Location: United States
SentinelVision runs on customer hardware and uses no subprocessors of ours. Alerts are delivered through whichever notification service the customer configures.
Transfers. Cloudflare, GitHub, Google, Pushover and Tailscale are U.S.-based; Brevo is in the EU. For data leaving the EEA, Switzerland or the UK we rely on the EU–U.S. Data Privacy Framework where a provider is certified, and otherwise on the Standard Contractual Clauses and UK Addendum in each provider's data-processing terms. Each provider is bound by a data-processing agreement that restricts it to processing on our instructions.
3. Security Practices
Identity & access
- Client-facing services use passwordless, single-use emailed sign-in links (about 15 minutes, one use). Tokens are stored as SHA-256 hashes.
- Sessions are HMAC-signed cookies; the signing secret exists only in the Worker environment. Disabling a person or organisation revokes their sessions immediately.
- No public sign-up on any service. Accounts are created by an administrator or through a client-specific enrolment link; enrolment by domain can only ever create a customer, never staff.
- Internal tools use passwords stored as PBKDF2-SHA256 (100,000 iterations) with constant-time comparison, plus per-user accounts so access can be removed individually.
Network
- Every public endpoint sits behind Cloudflare with TLS enforced. The website ships security headers (content-security-policy, frame denial, referrer policy, permissions policy).
- Administrative surfaces, the fleet server and SentinelVision dashboards are not reachable from the public internet, only over Tailscale or an authenticated Cloudflare Tunnel.
- Sign-in and form endpoints are designed so that they cannot be used to enumerate accounts or clients: unknown addresses get the same response as known ones.
Payments
- No SentinelGrid system receives, stores, processes or transmits a full card number. Every payment method entry, plan change and invoice payment happens on a page hosted by Stripe, which keeps our card-data environment empty rather than merely well guarded.
- The billing service holds only a mapping from an organisation to its Stripe customer id, plus a signed-event audit log. Balances, invoices and subscription state are read from Stripe on each request and are never copied into our database, so our records cannot silently disagree with what was actually charged.
- Payment webhooks are accepted only with a valid signature over the exact bytes Stripe sent, with a timestamp tolerance, and each event is processed once.
- Who inside a client organisation can see billing is explicit: organisation managers, plus individuals granted billing access. An ordinary member account is refused.
Code & deployment
- Every service is in version control and deployed from it. Two production email bugs once lived only in a dashboard-edited script; that is why.
- Secrets are held in Cloudflare's secret store and are never committed. Services are dependency-light, single-file Workers with no build step where possible, which keeps the supply-chain surface small.
- Database schema changes are additive and re-runnable; they never drop rows.
Monitoring & response
- Our own services are monitored by the same Monitor we offer clients; the public status page is at status.sentinelgrid.us.
- Alert delivery is tested end to end before it is relied upon.
- Audit logs of sign-ins and administrative actions are kept for 12 months.
People
- Access is granted per engagement and removed when it ends. Contractors never receive client-environment access before signing confidentiality terms, and minors never receive it at all.
- Remote sessions on managed devices are initiated by named staff and logged.
4. Incident Notification
If we become aware of a security incident affecting your data we will notify affected clients and users without undue delay, and our target is within 72 hours of confirmation, with what happened, what data was involved, what we have done, and what you should do. We will update you as we learn more and publish a post-incident summary on the status page where appropriate.
Statutory outer limits we work inside: 30 days to affected Florida residents and, for 500 or more of them, to the Florida Department of Legal Affairs (Florida Information Protection Act, § 501.171); 72 hours to a supervisory authority under the GDPR and UK GDPR; and, for Managed IT clients under a regulated-data addendum, the timelines in HIPAA, PCI DSS or the CJIS Security Policy, which we help the client meet. Our own practices are aligned to the NIST Cybersecurity Framework 2.0 functions (govern, identify, protect, detect, respond, recover) at a scale appropriate to a very small provider.
5. Vulnerability Disclosure
If you find a security problem in any SentinelGrid service, email support@sentinelgrid.us with "Security" in the subject. We will acknowledge within 2 business days, keep you informed, and credit you if you want. We will not pursue legal action against good-faith research that avoids denial of service, data destruction, and access to other people's data, and that gives us reasonable time to fix the issue before publication. We do not currently run a paid bounty programme.
6. Changes
This page changes whenever our infrastructure does. The "Last Updated" date at the top reflects the most recent change. Managed IT clients receive email notice when a subprocessor that handles their data is added.
7. Contact
SentinelGrid, operated by Mason Collier, sole proprietor, Florida
Security and privacy: support@sentinelgrid.us