Trust & Security
Verify every boundary.
How Senti limits permissions, separates execution, protects credentials, records activity, and lets you stop or revoke access. Funds stay at your broker.
Funds never leave the broker. Senti cannot withdraw or transfer them.
These figures show platform activity and measured availability, not investment performance, returns, or a contractual service level.
What the access model can and cannot do
The supported access model is scoped to execution. It does not extend to moving money.
Security starts with a smaller permission boundary
The first control is architectural. Funds remain in the user's own broker account, and deposits and withdrawals happen through the broker, outside Senti.
- Funds remain in the user's broker account at all times.
- Senti executes the supported automation workflow through the agreed access model.
- Senti cannot initiate a withdrawal, transfer funds, or take custody of capital.
- The customer owns strategy selection, risk parameters, account authorization, and applicable regulatory obligations.
Senti is trading automation infrastructure. It is not a broker, fund manager, copy-trading marketplace, signal seller, or promise of returns.
A clear line between what you own and what Senti operates
The user or authorized customer stays responsible for the trading decisions. Senti provides infrastructure, not custody, investment advice, or discretionary fund management.
Where isolation is defined
“Isolation” is not used as a generic security slogan. The boundary depends on the deployment:
- Trade Account execution: each connected Trade Account keeps its own execution context, configuration, orders, and runtime state.
- Whitelabel workspace: the security review verifies how customer and account data is logically separated from other Whitelabel customer workspaces within the supported multi-tenant model before launch.
- API workspace: an integration accesses its own provisioned users and accounts, not another customer's workspace data.
- On-premise deployment: infrastructure, network, access, and data boundaries are defined for the customer's contracted environment.
The security review confirms which boundary applies, how it is enforced, and which evidence can be shared for that deployment.
Access remains under customer control
The authorized user can pause, revoke, and review at any time. Control does not depend on Senti.
The authorized user can pause or stop the supported automation workflow from Senti. When it is stopped, no new orders are placed.
Disconnecting the broker account or changing its credentials removes Senti's ability to continue the trading workflow.
Senti does not request withdrawal or transfer rights. The deposit and withdrawal flow stays entirely with the broker.
Supported order and account activity can be reviewed through Senti's operating and verification surfaces.
For B2B deployments, the exact account roles, administrative permissions, support access, and offboarding process are confirmed during technical discovery and documented in the applicable agreement.
How broker credentials are handled
Senti's documented credential path uses AES-256-GCM encryption on submission. Credentials are stored encrypted at rest and are decrypted only inside the isolated execution environment, not in the web layer.
- Use the narrowest broker permission supported by your setup.
- Protect your own administrator credentials.
- Revoke or rotate access when an account is no longer active.
The detailed credential flow and any deployment-specific controls should be validated during the security review.
What the operating record proves, and what it does not
We do not turn an operational metric into a certification, warranty, or guaranteed future result.
Where formal assurance stands today
Senti does not currently claim SOC 2 certification or a published independent penetration-test report. Formal external assurance remains a roadmap item, with no public completion date stated on this page.
The standard public posture is therefore evidence-led:
- Non-custodial account architecture.
- Documented execution and withdrawal boundaries.
- Credential-protection controls.
- Measured live-beta uptime and activity.
- Solution-specific ownership and support boundaries.
Any certification, audit result, penetration-test report, data-residency commitment, or security schedule will appear here only after completion and approval for external disclosure.
What a security review can cover
A technical or procurement review works through the deployment on real terms, not a generic checklist.
How your chosen model is deployed and how data moves through it.
The access scope and the credential path behind it.
Who can do what, and where those boundaries sit.
How issues are detected, escalated, and how access ends.
The technical requirements particular to your deployment.
The difference between operating history and a signed commitment.
Non-public evidence is shared only after scope and confidentiality terms are agreed. Current B2B agreement templates include mutual confidentiality provisions subject to legal review, and a separate mutual NDA can be scoped for deeper diligence. Availability and final terms are confirmed by Senti and legal before non-public materials are shared. It is not a self-serve or pre-approved public document.
Measured uptime is not a contractual SLA
The public operating metric is 99.9% measured live-beta uptime. Standard API support currently targets a response to email within 24 hours. Enterprise or on-premise buyers can scope a dedicated channel, incident-response targets, maintenance responsibilities, and a contractual SLA in their agreement.
Senti does not publish a default enterprise availability commitment. Any contractual availability figure, service credit, response time, or remediation term is valid only when included in a signed agreement.
Trust FAQ
Does Senti ever hold customer funds? +
Can Senti withdraw from a connected account? +
Can access be revoked? +
Is 99.9% a contractual SLA? +
Is Senti SOC 2 certified or independently penetration-tested? +
Can our security team review more detail? +
Verify the boundary before the deployment.
Tell us which deployment you are evaluating. We will route the review to the relevant technical and commercial context. Contact: Email partners@koni.studio with your company, deployment model, reviewer role, and priority security questions.