Enterprise & procurement

Everything your vendor-risk file needs

Sentrix is built to pass a bank, PSP or acquirer procurement review. Here is the security, legal and deployment picture in one place — with a clear line between what runs today and what is on the roadmap.

Security & due-diligence review

Security questionnaires

We complete standard vendor-security and due-diligence questionnaires. Send yours to compliance@sentrix.world and we'll return it with supporting evidence.

Architecture walkthrough

A working session for your security and risk teams covering data flow, controls, hosting and the attestation roadmap.

Documentation package

The security, compliance and legal documents above, provided as a set for your vendor-risk file.

Roadmap transparency

A straight answer on what is live versus planned — SSO/SAML, four-eyes approval, WORM/hash-chained audit and data residency are on the roadmap and we will not represent them as shipped.

Documentation package

The documents a procurement and security team asks for, ready to review before signature.

Deployment model

What the platform is today, and what is planned. Roadmap items are never represented as shipped.

CapabilityDetailStatus
HostingMulti-tenant SaaS on Vercel (edge/serverless) with Neon Postgres, in a single primary region today.Live
Tenant isolationLogical per-workspace separation, enforced on every request against the authenticated workspace.Live
AccessEmail + password with Argon2 hashing and server-enforced RBAC (owner / manager / analyst / viewer).Live
SSO / SAML & SCIMFederated sign-in and provisioning for Institution plans.Roadmap
Data residencyCustomer-selectable region, including UAE-region hosting.Roadmap
Four-eyes approvalDual control on high-impact overrides and dispositions.Roadmap
Tamper-evident auditHash-chaining / WORM export over the append-only audit trail.Roadmap

Service levels & support

Operate and Institution plans are backed by a support SLA with defined response targets by severity; the specific availability and response commitments are set out in the Order Form and service schedule for your plan. Operational status is published at /status, backed by a programmatic health endpoint. Named technical contact is available on the Institution tier. We do not publish an availability figure we cannot stand behind — the committed number is contractual and plan-specific.

Onboarding

  1. 01

    Briefing & scoping

    A walkthrough mapped to your operation, and confirmation of scope, plan and any roadmap dependencies.

  2. 02

    Security & legal review

    Questionnaire, documentation package and DPA review; architecture session with your security team.

  3. 03

    Sandbox & integration

    A workspace to author rules, connect sandboxed providers and integrate the decisioning API against simulated traffic.

  4. 04

    Go live

    Under an executed Order Form, with production providers connected and RBAC configured for your team.

Start a procurement review

Send a questionnaire to compliance@sentrix.world or security@sentrix.world, or book a briefing to begin.

Book a briefing