Skip to main content
Last updated 09/09/2026
Sentinel

Security Assurance Plan

ALTCHA Sentinel — Enterprise Self-Hosted Deployments

  • Version: 1.0
  • Effective date: September 9, 2026
  • Owner: ALTCHA
  • Review frequency: At least annually and following material changes to the security architecture, product, or applicable requirements

1. Purpose

This Security Assurance Plan ("Plan") describes how ALTCHA maintains, verifies, and communicates the security of ALTCHA Sentinel for enterprise self-hosted deployments.

The Plan complements the ALTCHA Security Compliance Framework, which defines the security controls and shared responsibilities applicable to Sentinel deployments.

The purpose of this Plan is to provide customers and their security, compliance, and procurement teams with a clear description of:

  • ALTCHA's security assurance activities;
  • security testing and vulnerability management;
  • security monitoring and response practices;
  • security-related documentation and evidence;
  • the respective responsibilities of ALTCHA and the customer; and
  • the process for maintaining and improving security over time.

This Plan does not replace the Security Compliance Framework, product documentation, contractual commitments, or applicable customer security requirements.


2. Scope

This Plan applies to ALTCHA Sentinel when deployed in an enterprise customer's environment.

Sentinel is designed to be self-hosted. Accordingly, security is based on a shared-responsibility model:

ALTCHA is responsible for the security of the software it develops, tests, and releases.

The customer is responsible for securely deploying, configuring, operating, monitoring, and maintaining Sentinel and the infrastructure in which it runs.

The detailed division of responsibilities is defined in the Security Compliance Framework.

This Plan does not by itself establish security commitments for ALTCHA Cloud or other ALTCHA services.


3. Security Governance

Security is treated as a core product and engineering responsibility at ALTCHA.

ALTCHA maintains security practices covering:

  • secure software development;
  • security testing;
  • vulnerability identification and remediation;
  • secure release processes;
  • security documentation;
  • responsible vulnerability disclosure; and
  • continuous improvement of security controls.

Security requirements are incorporated into product development and release activities as appropriate to the nature and risk of the change.

The Security Compliance Framework and this Plan are reviewed periodically and updated when material changes occur.


4. Secure Software Development

ALTCHA applies security practices throughout the software development lifecycle.

Security activities include, as applicable:

  • security-focused design and implementation;
  • testing of security-relevant functionality;
  • code and dependency review;
  • vulnerability identification;
  • security testing before release;
  • remediation of identified vulnerabilities; and
  • controlled publication of software releases.

ALTCHA's objective is to ensure that security is considered throughout the lifecycle rather than solely after software has been released.


5. Security Testing and Assurance

ALTCHA performs security assessments of Sentinel as part of its security assurance activities.

Security assurance activities include:

5.1 Vulnerability assessment

ALTCHA conducts vulnerability assessments and maintains processes for identifying and addressing vulnerabilities affecting Sentinel and its software dependencies.

5.2 Penetration assessment

ALTCHA conducts penetration assessments of Sentinel.

Penetration testing is used to identify security weaknesses that may not be detected through automated vulnerability scanning alone.

Where appropriate, identified findings are assessed and addressed through ALTCHA's vulnerability management and release processes.

5.3 Container security

ALTCHA publishes vulnerability scanning information for Sentinel releases.

Sentinel Docker images are subject to Trivy scanning, and the results are published alongside the relevant release information.

5.4 Software Bill of Materials

ALTCHA provides a Software Bill of Materials (SBOM) to support software supply-chain transparency and enable customers to identify software components and dependencies.

5.5 Customer assurance evidence

Where appropriate and available, ALTCHA may provide security-related evidence to customers, subject to confidentiality, security, and responsible-disclosure considerations.

Potential evidence includes:

  • penetration assessment reports or appropriate summaries;
  • vulnerability scan results;
  • SBOMs;
  • security documentation;
  • security advisories; and
  • other relevant security information.

Sensitive information that could materially increase security risk may be redacted or withheld.


6. Vulnerability Management

ALTCHA maintains a process for identifying, evaluating, prioritizing, and remediating security vulnerabilities affecting Sentinel.

Vulnerabilities may be identified through:

  • internal security testing;
  • penetration assessments;
  • automated vulnerability scanning;
  • dependency analysis;
  • security research;
  • responsible vulnerability disclosures; and
  • information from relevant security advisories.

Identified vulnerabilities are assessed according to their nature, severity, exploitability, affected components, and potential impact.

Remediation may include:

  • applying a security patch;
  • updating a dependency;
  • modifying application behavior;
  • changing configuration;
  • implementing compensating controls; or
  • publishing a security advisory.

Security updates are released as appropriate to the severity and nature of the vulnerability.

Customers are responsible for monitoring relevant ALTCHA security advisories and applying available updates to their deployments in a timely manner.


7. Security Release Assurance

ALTCHA maintains security controls around Sentinel releases.

Security-related release activities may include:

  1. assessment of relevant source-code and dependency changes;
  2. security testing;
  3. vulnerability scanning;
  4. container image scanning;
  5. generation or provision of an SBOM;
  6. remediation or assessment of identified security findings; and
  7. publication of relevant security information.

Sentinel release information may include vulnerability scan results and other security evidence to support customer assessment.


8. Access Control and Authentication

Sentinel provides security capabilities including:

  • Role-Based Access Control (RBAC);
  • least-privilege access capabilities;
  • Multi-Factor Authentication (MFA) support;
  • session management;
  • rate limiting; and
  • audit logging of authentication and access events.

Customers are responsible for configuring these capabilities appropriately for their environment, including:

  • assigning appropriate roles;
  • managing user accounts and credentials;
  • enforcing MFA policies;
  • restricting administrative access; and
  • reviewing relevant audit events.

9. Data Protection

Sentinel provides capabilities supporting encryption of data in transit and at rest.

Customers are responsible for securely configuring these capabilities, including:

  • TLS for data in transit;
  • encryption-at-rest settings;
  • encryption-key management;
  • secure backup configuration; and
  • appropriate data retention and lifecycle controls.

For customer-managed deployments, the customer remains responsible for the security of the underlying infrastructure and the data stored within it.


10. Logging and Monitoring

Sentinel provides audit logging capabilities covering system and API activity and supports exporting logs to external systems.

Customers are responsible for implementing the operational monitoring layer appropriate to their environment, including:

  • centralized log collection;
  • SIEM integration where appropriate;
  • alerting;
  • regular review of security-relevant events;
  • investigation of anomalies; and
  • retention of logs in accordance with their requirements.

The customer should configure monitoring and alerting according to the risk profile and sensitivity of its deployment.


11. Availability and Resilience

Sentinel is designed to support high availability and fault-tolerant deployments.

Customers are responsible for implementing the infrastructure-level resilience appropriate to their requirements, which may include:

  • redundant application instances;
  • load balancing;
  • infrastructure redundancy;
  • backups;
  • disaster recovery procedures;
  • monitoring;
  • automated or documented failover; and
  • periodic recovery testing.

The customer's recovery objectives depend on its deployment architecture and infrastructure configuration.


12. Infrastructure Security

For self-hosted deployments, the customer is responsible for securing the environment in which Sentinel operates.

Security measures should include, as appropriate:

  • hardened operating systems and container images;
  • network segmentation;
  • firewall controls;
  • restricted administrative access;
  • secure secrets management;
  • container security policies;
  • secure cloud configuration;
  • vulnerability scanning;
  • security monitoring; and
  • timely application of operating-system and infrastructure patches.

ALTCHA provides software designed to support secure deployment on modern cloud and container platforms, including Azure App Services, Amazon ECS, and Kubernetes.


13. Security Incident and Vulnerability Reporting

ALTCHA maintains a process for receiving and investigating reports of security vulnerabilities affecting its software.

Customers and security researchers should report suspected vulnerabilities through ALTCHA's designated security reporting channels and follow the Security Vulnerability Disclosure Policy.

ALTCHA prioritizes prompt investigation and remediation of legitimate security concerns.

Customers are responsible for incident detection and response within their own infrastructure, including incidents involving:

  • customer-managed networks;
  • operating systems;
  • cloud accounts;
  • container infrastructure;
  • credentials;
  • customer applications; or
  • other infrastructure outside ALTCHA's direct control.

Where an incident involves ALTCHA software, ALTCHA will provide appropriate investigation and remediation support within the scope of its responsibilities.


14. Security Documentation and Transparency

ALTCHA maintains security documentation to enable customers to evaluate and operate Sentinel securely.

Security documentation may include:

  • Security Compliance Framework;
  • Security Assurance Plan;
  • Security Vulnerability Disclosure Policy;
  • security advisories;
  • release security information;
  • vulnerability scan results;
  • SBOMs; and
  • relevant product security documentation.

Documentation is updated as appropriate to reflect material changes in the product, architecture, security practices, or applicable requirements.


15. Customer Security Responsibilities

Because Sentinel is self-hosted, customers have significant responsibility for the security of their deployment.

Customers are responsible for:

  • secure deployment and configuration;
  • identity and access management;
  • MFA enforcement;
  • infrastructure security;
  • network security;
  • encryption configuration and key management;
  • operating-system and infrastructure patching;
  • Sentinel updates;
  • vulnerability scanning;
  • backup and disaster recovery;
  • log collection and monitoring;
  • security incident response within their environment; and
  • compliance with applicable legal and regulatory requirements.

The complete shared-responsibility model is defined in the Security Compliance Framework.


16. Security Assurance Lifecycle

ALTCHA's security assurance activities follow a continuous lifecycle:

Design → Develop → Test → Assess → Release → Monitor → Remediate → Improve

Security findings identified through testing, vulnerability research, customer reports, or operational experience may result in:

  • software changes;
  • security patches;
  • configuration recommendations;
  • security advisories;
  • documentation updates; or
  • additional security testing.

This lifecycle is intended to maintain security assurance as Sentinel evolves.


17. Review of This Plan

ALTCHA reviews this Security Assurance Plan at least annually and following material changes to:

  • Sentinel's security architecture;
  • security controls;
  • vulnerability management processes;
  • deployment model;
  • applicable security requirements; or
  • the shared-responsibility model.

Changes are incorporated where necessary to maintain an accurate representation of ALTCHA's security assurance practices.


This Plan should be read together with the following ALTCHA documentation:

  1. Security Compliance Framework — security controls and shared responsibilities.
  2. Security Vulnerability Disclosure Policy — vulnerability reporting and disclosure.
  3. Security Advisories — information concerning identified security vulnerabilities and relevant remediation.
  4. Sentinel Release Documentation — release-specific technical and security information.
  5. Privacy Policy and Data Processing Agreement (DPA) — applicable privacy and data protection information.

19. Statement of Assurance

ALTCHA is committed to maintaining security as a fundamental property of Sentinel and to providing customers with appropriate information to evaluate and securely operate the product.

ALTCHA's security assurance model combines secure software development, security testing, vulnerability management, security transparency, and a clearly defined shared-responsibility model.

For enterprise self-hosted deployments, effective security is a joint responsibility between ALTCHA and the customer. ALTCHA provides security capabilities and secure software; customers are responsible for securely deploying, configuring, operating, and maintaining Sentinel within their environments.

Start typing to search...

Navigate Select