Sensat is ISO27001:2022 certified. Our implementation of security controls is audited annually, validating our commitment to the critical security standards required to protect client data.
Sensat is Cyber Essentials certified and maintains compliance annually. Cyber Essentials is a UK Government-backed certification scheme that helps keep company and customer data safe from cyber attacks.
Sensat complies with the General Data Protection Regulation (GDPR). We act as both a data processor and controller, depending on the context, and have designed our product and processes to support GDPR compliance for our customers.
The Sensat platform is cloud hosted, with storage and data processing performed in facilities across the globe.Customers can choose which region to host their project data, ensuring that data sovereignty requirements will be enforced.
Single Sign-On (SAML, Azure, OIDC) allows you to authenticate users using your own identity providers.This reduces friction, enables smoother joiner-mover-leaver (JML) processes, and allows for robust monitoring via your SIEM system.
Cyberattacks and phishing attempts are becoming more frequent and sophisticated. Passwords alone can be stolen or guessed.For those not using SSO, Sensat adds MFA as a second layer of security so even if your password is compromised, your account stays safe.
Sensat provides robust Role-Based Access Control (RBAC) across your account, project, and workspaces.Fine-grained data access controls are available to allow or restrict the flow of information across specific users and groups.
Automate onboarding, offboarding, and updates to data access using our comprehensive User Management and Content Management APIs.
Sensat is built with high availability in mind. All infrastructure and data is spread across multiple cloud Availability Zones in each region. Should one zone fail, service will continue to operate as normal.All compute servers are redundant and set up to auto-scale based on demand.
Our platform has accidental deletion-prevention mechanisms and maintains multiple backups of data. These measures enable recovery with minimal downtime in the event that data is corrupted or deleted by a malicious actor.In the event the Sensat Platform becomes unresponsive (due to deployment or code change issues for example) there is a rollback mechanism to restore the previous working configuration.
Customer data is logically separated in our multi-tenant VPCs.Network access control lists (ACLs) provide a secure perimeter preventing unauthorised requests to the network.Customers can optionally choose to have a dedicated environment for their project data (at extra cost).Every request to any asset for a project is signed against the authenticated user session. The request signature is only valid for a few seconds, so it cannot be replayed.
The Sensat Platform audits system and user events, logging actions taken across the application and network.Automated controls are in place to alert our engineers of any increase in errors or suspicious load on our systems.We use continuous automated checking for known vulnerabilities in software dependencies, which is reinforced via manual code reviews, and automated scans of all software images and servers.
Data is encrypted in transit and at rest, across our platform and the connection to end-user devices.We use industry-standard enterprise-grade technology – HTTPS/TLS (TLS 1.2 or higher) and strong ciphers such as AES256.
All data management and information security policies and processes are implemented and handled in full compliance with ISO 27001.This includes mandatory Security and Awareness training and confidentiality agreements with all employees. Where applicable by law, Sensat also performs background screenings on personnel prior to joining the organisation.