πŸ›‘οΈSENTINEL
FR Β· EN

Security & trust

Last updated: June 2026

Sentinel protects some of the most sensitive information there is: your final messages and documents for your loved ones. Here is, in full transparency, how we protect your data β€” and what we do not do (we'd rather be honest than promise the impossible).

πŸ” Encryption

Encryption at rest (AES-256-GCM)

Your messages and files are encrypted on our servers with AES-256-GCM, a recognized standard. The master key is an infrastructure secret, never stored in the database. Key derivation uses HKDF-SHA256.

Encryption in transit (HTTPS/TLS)

All communications between the app, our servers and your recipients use encrypted connections (HTTPS/TLS).

Hashed passwords (PBKDF2)

Your password is never stored in plain text: it is hashed with PBKDF2-HMAC-SHA256 (100,000 iterations, random per-user salt). Even we cannot read it.

Transparency: not "end-to-end"

We say it plainly: Sentinel is not end-to-end encrypted. To be able to send your messages in your absence, the service must be able to decrypt them at send time. In return, we never read your content and use it for no other purpose.

πŸ“œ Integrity & transparency

Tamper-proof audit log

Every security action (login, check-in, dispatch, deletion, admin access…) is timestamped and sealed with cryptographic hash-chaining: each entry's hash depends on the previous one. Any attempt to modify or erase the history breaks the chain and becomes immediately detectable. This log contains none of your message content, only technical identifiers.

πŸ›‘οΈ Access protection

Email address verification

At sign-up, a 6-digit code confirms you actually own the address. Such a sensitive tool must not be created with a wrong email.

Anti-bot protection (CAPTCHA)

Authentication pages are protected by a CAPTCHA (Cloudflare Turnstile) against bots and mass creation of fake accounts.

Brute-force protection

Repeated login attempts are rate-limited (per account and per IP address) and temporarily blocked, to counter trial-and-error attacks.

Local lock (biometrics / PIN)

On your device, you can require Face ID / fingerprint or a PIN to open the app, with automatic re-lock after inactivity.

Double-confirmation deletion

Deleting your account requires typing the word "DELETE" AND your password β€” to prevent accidental or malicious deletion. Deletion is immediate and permanent.

⏱️ Against accidental triggers

Escalating reminders & grace period

Before any dispatch, you receive a first reminder then a last reminder. Nothing is sent until the grace period you configured has elapsed.

Two-person rule (optional)

At the deadline, Sentinel can first ask a trusted contact to confirm your absence. Without their confirmation within the set delay, the dispatch happens automatically.

Holiday mode

Suspend monitoring during planned absences, with automatic resume on the date you choose. No dispatch can occur during the pause.

Anti-replay protection

Right before a dispatch, the service re-checks your last check-in: if you confirmed your presence at the last minute, the dispatch is cancelled.

πŸ“¨ Delivery reliability

Dual email provider

Sentinel uses a primary sending provider and automatically switches to an independent second provider on failure β€” so a final message is never lost because of a single provider.

Automatic retry queue

On a delivery failure, the attempt is automatically retried several times (with progressive delay). You're notified if a recipient could not be reached.

Secure email-verified links

By default, the email only contains a neutral notification + a protected link: the recipient must confirm their email address to access the content. The confidential text therefore never travels through email.

Optional Telegram channel

You can receive your reminders on Telegram and, optionally, have your recipients receive a secure notification via Telegram β€” in addition to email, for extra reliability.

Proof it works

As long as your account is active, you receive a weekly health email and an automatic monthly backup of your data. A simulation (Dry Run) button lets you test without sending anything to your recipients.

βœ… Your best practices

πŸ”Ž What we don't do

We never sell your data, do not use it for advertising, and do not read your content. Sentinel does not replace any official legal, medical or safety arrangement.

A question about security? Email us: getssentinel@gmail.com.

Contact : getssentinel@gmail.com