Security
Last updated: March 6, 2026
Disclaimer: This page describes our security practices for informational purposes only. It does not constitute a warranty or guarantee of security. The Service is provided “as is” and “as available.” See our Terms of Use for disclaimers and limitation of liability.
Our Commitment
BaselineSentinel takes the security of your data seriously. We use encryption in transit (TLS) and at rest (AES-256 for stored secrets), strong password hashing, and access controls. We do not guarantee that the Service or your data will be secure; you use the Service at your own risk.
Data Protection
We use TLS for all traffic between you and our systems. Sensitive data (e.g., integration credentials, API keys) is encrypted at rest. Passwords are stored using strong one-way hashing. Stored credentials are decrypted only when needed for operations you authorize.
Access Control
Access to the Service is controlled by authentication (email/password and optional MFA). We support role-based access within organizations. We restrict administrative access to the Service and do not access your data except as necessary to operate the Service, comply with law, or with your consent.
Your Responsibilities
You are responsible for keeping your password and MFA credentials secure, not sharing account access, and configuring AWS and third-party integrations securely. You are responsible for the security of your own systems and data. We are not responsible for misuse of your account, unauthorized access due to your failure to secure credentials, or outcomes resulting from your use of the Service.
Reporting Security Issues
If you discover a security vulnerability in the Service, please report it responsibly to us at [email protected]. Do not exploit the vulnerability or disclose it publicly before we have had a reasonable opportunity to address it. We will acknowledge receipt and work with you as appropriate.
Contact
For security-related questions or reports: [email protected].