Trust & Security

Verify every boundary.

How Senti limits permissions, separates execution, protects credentials, records activity, and lets you stop or revoke access. Funds stay at your broker.

Non-custodial MetaTrader 5 API & Whitelabel
Broker accountYour broker holds the funds
Senti APIAccess only, no withdrawal
MT5 executionRuns the supported workflow
ReportingActivity back to you

Funds never leave the broker. Senti cannot withdraw or transfer them.

$600M+Cumulative volume
63,000+Closed deals
$38MSingle-day peak
99.9%Live-beta uptime

These figures show platform activity and measured availability, not investment performance, returns, or a contractual service level.

[01]Permission boundary / 01 : 10

What the access model can and cannot do

The supported access model is scoped to execution. It does not extend to moving money.

Non-custodial by design

Security starts with a smaller permission boundary

The first control is architectural. Funds remain in the user's own broker account, and deposits and withdrawals happen through the broker, outside Senti.

  • Funds remain in the user's broker account at all times.
  • Senti executes the supported automation workflow through the agreed access model.
  • Senti cannot initiate a withdrawal, transfer funds, or take custody of capital.
  • The customer owns strategy selection, risk parameters, account authorization, and applicable regulatory obligations.

Senti is trading automation infrastructure. It is not a broker, fund manager, copy-trading marketplace, signal seller, or promise of returns.

Senti can
Senti cannot
Open, modify, and close positions through the supported execution workflow
Initiate withdrawals or transfer funds
Read the account information required to execute and report the workflow
Move capital between accounts
Show supported account and execution activity
Access the broker's withdrawal process
Stop placing new orders when the workflow is paused or stopped
Remove market risk or guarantee a trading result
[02]Responsibility boundary / 02 : 10

A clear line between what you own and what Senti operates

The user or authorized customer stays responsible for the trading decisions. Senti provides infrastructure, not custody, investment advice, or discretionary fund management.

You own
Senti operates
Strategy selection and trading rules
The agreed technical service boundary
Risk parameters and position decisions
Trading automation runtime and execution
Account authorization and user access
Broker connectivity and operational monitoring
Applicable regulatory obligations
Execution and reporting of the supported workflow
[03]Isolation boundary / 03 : 10

Where isolation is defined

“Isolation” is not used as a generic security slogan. The boundary depends on the deployment:

  • Trade Account execution: each connected Trade Account keeps its own execution context, configuration, orders, and runtime state.
  • Whitelabel workspace: the security review verifies how customer and account data is logically separated from other Whitelabel customer workspaces within the supported multi-tenant model before launch.
  • API workspace: an integration accesses its own provisioned users and accounts, not another customer's workspace data.
  • On-premise deployment: infrastructure, network, access, and data boundaries are defined for the customer's contracted environment.

The security review confirms which boundary applies, how it is enforced, and which evidence can be shared for that deployment.

[04]Access model / 04 : 10

Access remains under customer control

The authorized user can pause, revoke, and review at any time. Control does not depend on Senti.

[01] Pause or stop execution

The authorized user can pause or stop the supported automation workflow from Senti. When it is stopped, no new orders are placed.

[02] Revoke access

Disconnecting the broker account or changing its credentials removes Senti's ability to continue the trading workflow.

[03] Keep withdrawals separate

Senti does not request withdrawal or transfer rights. The deposit and withdrawal flow stays entirely with the broker.

[04] Review activity

Supported order and account activity can be reviewed through Senti's operating and verification surfaces.

For B2B deployments, the exact account roles, administrative permissions, support access, and offboarding process are confirmed during technical discovery and documented in the applicable agreement.

[05]Credential handling / 05 : 10

How broker credentials are handled

Senti's documented credential path uses AES-256-GCM encryption on submission. Credentials are stored encrypted at rest and are decrypted only inside the isolated execution environment, not in the web layer.

  • Use the narrowest broker permission supported by your setup.
  • Protect your own administrator credentials.
  • Revoke or rotate access when an account is no longer active.

The detailed credential flow and any deployment-specific controls should be validated during the security review.

[06]Evidence, read honestly / 06 : 10

What the operating record proves, and what it does not

Evidence available today
Correct interpretation
$600M+ cumulative trading volume
The infrastructure has handled material live-beta trading activity
63,000+ closed deals
The execution workflow has operated repeatedly under real account activity
$38M single-day peak
The platform has handled a measured peak day
99.9% measured live-beta uptime
Historical operational availability, not a public contractual SLA
No reported security incidents since launch, as of 2026-07-30
Current incident history, not a promise that an incident can never occur

We do not turn an operational metric into a certification, warranty, or guaranteed future result.

[07]Assurance status / 07 : 10

Where formal assurance stands today

Senti does not currently claim SOC 2 certification or a published independent penetration-test report. Formal external assurance remains a roadmap item, with no public completion date stated on this page.

The standard public posture is therefore evidence-led:

  • Non-custodial account architecture.
  • Documented execution and withdrawal boundaries.
  • Credential-protection controls.
  • Measured live-beta uptime and activity.
  • Solution-specific ownership and support boundaries.

Any certification, audit result, penetration-test report, data-residency commitment, or security schedule will appear here only after completion and approval for external disclosure.

[08]Security review / 08 : 10

What a security review can cover

A technical or procurement review works through the deployment on real terms, not a generic checklist.

01
Deployment model and data flow

How your chosen model is deployed and how data moves through it.

02
Account permissions and credential handling

The access scope and the credential path behind it.

03
Workspace, administrator, and support-access boundaries

Who can do what, and where those boundaries sit.

04
Monitoring, incident escalation, and offboarding

How issues are detected, escalated, and how access ends.

05
API or on-premise requirements specific to the buyer

The technical requirements particular to your deployment.

06
Measured uptime versus a contractual service level

The difference between operating history and a signed commitment.

Non-public evidence is shared only after scope and confidentiality terms are agreed. Current B2B agreement templates include mutual confidentiality provisions subject to legal review, and a separate mutual NDA can be scoped for deeper diligence. Availability and final terms are confirmed by Senti and legal before non-public materials are shared. It is not a self-serve or pre-approved public document.

[09]Availability boundary / 09 : 10

Measured uptime is not a contractual SLA

The public operating metric is 99.9% measured live-beta uptime. Standard API support currently targets a response to email within 24 hours. Enterprise or on-premise buyers can scope a dedicated channel, incident-response targets, maintenance responsibilities, and a contractual SLA in their agreement.

Senti does not publish a default enterprise availability commitment. Any contractual availability figure, service credit, response time, or remediation term is valid only when included in a signed agreement.

[10]Common questions / 10 : 10

Trust FAQ

Does Senti ever hold customer funds? +
No. Funds stay in the user's broker account. Senti is not in the deposit or withdrawal flow.
Can Senti withdraw from a connected account? +
No. The supported access model allows the execution workflow to place and manage trades, not to initiate withdrawals or fund transfers.
Can access be revoked? +
Yes. The authorized user can pause or stop the workflow and disconnect the broker account. Changing the broker credentials also revokes the existing connection.
Is 99.9% a contractual SLA? +
No. It is a measured live-beta operating figure. Contractual service levels are scoped separately for the applicable B2B deployment.
Is Senti SOC 2 certified or independently penetration-tested? +
Senti does not currently make either public claim. Formal external assurance is on the roadmap, without a public completion date.
Can our security team review more detail? +
Yes. Request a security review with your deployment model and priority questions. Senti will confirm what can be shared publicly, what requires confidentiality terms, and which items need solution-specific technical or legal review.

Verify the boundary before the deployment.

Tell us which deployment you are evaluating. We will route the review to the relevant technical and commercial context. Contact: Email partners@koni.studio with your company, deployment model, reviewer role, and priority security questions.

Read the security docs Senti confirms what can be shared publicly and what needs confidentiality terms.