Security & trust
Last updated: June 2026
Sentinel protects some of the most sensitive information there is: your final messages and documents for your loved ones. Here is, in full transparency, how we protect your data β and what we do not do (we'd rather be honest than promise the impossible).
π Encryption
Encryption at rest (AES-256-GCM)
Your messages and files are encrypted on our servers with AES-256-GCM, a recognized standard. The master key is an infrastructure secret, never stored in the database. Key derivation uses HKDF-SHA256.
Encryption in transit (HTTPS/TLS)
All communications between the app, our servers and your recipients use encrypted connections (HTTPS/TLS).
Hashed passwords (PBKDF2)
Your password is never stored in plain text: it is hashed with PBKDF2-HMAC-SHA256 (100,000 iterations, random per-user salt). Even we cannot read it.
Transparency: not "end-to-end"
We say it plainly: Sentinel is not end-to-end encrypted. To be able to send your messages in your absence, the service must be able to decrypt them at send time. In return, we never read your content and use it for no other purpose.
π Integrity & transparency
Tamper-proof audit log
Every security action (login, check-in, dispatch, deletion, admin accessβ¦) is timestamped and sealed with cryptographic hash-chaining: each entry's hash depends on the previous one. Any attempt to modify or erase the history breaks the chain and becomes immediately detectable. This log contains none of your message content, only technical identifiers.
π‘οΈ Access protection
Email address verification
At sign-up, a 6-digit code confirms you actually own the address. Such a sensitive tool must not be created with a wrong email.
Anti-bot protection (CAPTCHA)
Authentication pages are protected by a CAPTCHA (Cloudflare Turnstile) against bots and mass creation of fake accounts.
Brute-force protection
Repeated login attempts are rate-limited (per account and per IP address) and temporarily blocked, to counter trial-and-error attacks.
Local lock (biometrics / PIN)
On your device, you can require Face ID / fingerprint or a PIN to open the app, with automatic re-lock after inactivity.
Double-confirmation deletion
Deleting your account requires typing the word "DELETE" AND your password β to prevent accidental or malicious deletion. Deletion is immediate and permanent.
β±οΈ Against accidental triggers
Escalating reminders & grace period
Before any dispatch, you receive a first reminder then a last reminder. Nothing is sent until the grace period you configured has elapsed.
Two-person rule (optional)
At the deadline, Sentinel can first ask a trusted contact to confirm your absence. Without their confirmation within the set delay, the dispatch happens automatically.
Holiday mode
Suspend monitoring during planned absences, with automatic resume on the date you choose. No dispatch can occur during the pause.
Anti-replay protection
Right before a dispatch, the service re-checks your last check-in: if you confirmed your presence at the last minute, the dispatch is cancelled.
π¨ Delivery reliability
Dual email provider
Sentinel uses a primary sending provider and automatically switches to an independent second provider on failure β so a final message is never lost because of a single provider.
Automatic retry queue
On a delivery failure, the attempt is automatically retried several times (with progressive delay). You're notified if a recipient could not be reached.
Secure email-verified links
By default, the email only contains a neutral notification + a protected link: the recipient must confirm their email address to access the content. The confidential text therefore never travels through email.
Optional Telegram channel
You can receive your reminders on Telegram and, optionally, have your recipients receive a secure notification via Telegram β in addition to email, for extra reliability.
Proof it works
As long as your account is active, you receive a weekly health email and an automatic monthly backup of your data. A simulation (Dry Run) button lets you test without sending anything to your recipients.
β
Your best practices
- Choose a strong, unique password (at least 8 characters, ideally more).
- Enable the local lock (biometrics / PIN) on your phone.
- Test regularly with the simulation (Dry Run) and check that you receive the health email.
- Keep your recipients' addresses up to date and let your trusted contacts know their role.
- Set a realistic grace period and use holiday mode before a planned absence.
π What we don't do
We never sell your data, do not use it for advertising, and do not read your content. Sentinel does not replace any official legal, medical or safety arrangement.
A question about security? Email us: getssentinel@gmail.com.
Contact : getssentinel@gmail.com