Terms of Service
Last updated 29 July 2026
1. What Sentris is
Point-in-time, findings-based results. Sentris is not a penetration test, not a certification, and carries no warranty. We report reproducible exposures with evidence and a fix — we prove them, we do not exploit them.
Sentris inspects what a target exposes and reports reproducible findings with evidence and a suggested fix. It does not fix anything for you, does not guarantee that it finds every issue, and a clean result is not a statement that your application is secure.
2. You must be entitled to test the target
By submitting a URL or connecting a repository you warrant that you own it, or that you are authorised by its owner to have it tested. Submitting anyone else's asset is prohibited and is a breach of these terms.
Unverified targets receive passive checks only: we look at what the server hands to every visitor. Active checks are unlocked only after you prove control of the asset, through the GitHub App installation or a DNS TXT record, verification file or meta tag. Verification is re-checked periodically; if the proof disappears, active checks stop automatically.
3. How we behave against your systems
Requests are rate-limited. We demonstrate findings, we do not exploit them: at most one masked example record as evidence, never a full table, never a write operation, and no request flooding. These limits also keep scans inside the acceptable use policies of Supabase, Vercel and Cloudflare.
4. Your data
Repository access is read-only and short-lived. We read files during a scan and do not keep copies afterwards. Secrets we find are stored and displayed masked, and are never written to logs in clear text. You can revoke our access at any time in your GitHub settings.
Optional analytics uses PostHog's European service to measure visits, product actions and application errors, and Vercel Web Analytics and Speed Insights to measure traffic and page load performance. All of it starts only after you choose “Accept analytics” and may include a pseudonymous analytics identifier, browser data, page views, page timings, product events and, for signed-in users, an account identifier and email address. You can withdraw that choice at any time through Privacy settings; declining does not affect the core service. We retain the choice in a first-party cookie for six months.
5. Out of scope
Sentris does not look at any of the following, and never claims to:
- · Server infrastructure & DDoS
- · Dependency CVEs
- · TLS / cryptography depth
- · Social engineering
- · Business logic beyond access control
- · Mobile apps
- · Load / performance
6. Indemnity
You will indemnify and hold Sentris harmless against any claim, loss or expense arising from a target you submitted that you were not entitled to test.
7. Suspension
We may suspend or terminate access at any time, without notice, if we believe a target was submitted without entitlement, if the service is being used to scan third parties, or if usage threatens the stability of the service or of a third-party platform.
8. Liability
The service is provided as-is. To the extent permitted by law, Sentris is not liable for indirect or consequential damages, for issues it did not find, or for the consequences of applying a suggested fix. Nothing here excludes liability that cannot lawfully be excluded.
9. Governing law
These terms are governed by Swiss law. The place of jurisdiction is Switzerland, to the extent permitted by mandatory law.
10. Contact
Questions about these terms: the operator's name, postal address and email are on the privacy page.