← Sentinel

Privacy & data handling

Last updated 11 September 2026

Who operates this service

Sentinel is operated by Fisshbone and Lestr on behalf of CashToken Rewards and partner engineering organisations. It is an internal governance tool: access is restricted to an allowlist of named engineering staff. Contact: developers@fisshboneandlestr.com.

Signing in

Sign-in is delegated to GitHub (and optionally Microsoft Entra ID) via OAuth. Sentinel never sees or stores your password. From the identity provider we receive only your verified email address and display name, which must already be on the operator's allowlist for sign-in to succeed.

What we store

  • Your email address and display name (to identify you within your organisation).
  • Organisation membership and role.
  • Governance configuration you author (rulesets, repository settings, issued keys).
  • Review outcomes for governed repositories: verdicts, timestamps, pull-request references.

Platform credentials that connect Sentinel to GitHub, Azure DevOps, or AWS are held by the Sentinel service and are never returned to the browser or displayed after entry.

What we never do

  • Ask for passwords, card numbers, or other financial details — Sentinel has no such fields.
  • Sell, share, or use your data for advertising.
  • Store source code from reviewed repositories; reviews operate on the pull request and only review outcomes are retained.

Security

All traffic is encrypted in transit (TLS). Sessions use signed, HttpOnly cookies with a 24-hour sliding lifetime. Every governance action is written to an append-only audit log visible to your organisation's administrators.