DEMO — SENTRYFOX — REGULATED COMMERCE CONTROLRepresentative data. Nothing here is a real merchant or a real transaction.ALL DEMOS →
SENTRYFOX
SYSTEM
Security Readiness
What a vendor diligence review asks for, stated plainly including where the answer is not yet yes.
AREAPOSITIONSTATE
PCI DSS scope
No cardholder data reaches this application; entry is hosted fields served by the acquirer
ASSESSMENT PENDING
SOC 2
Readiness programme not yet started
NOT STARTED
Penetration test
Not yet commissioned
NOT STARTED
Authentication
Multi-factor required for institutional and channel roles
IN PROGRESS
Encryption
In transit and at rest
IN PLACE
Logging
Append-only audit record, no update or delete path
IN PLACE
Incident management
Process drafted, not exercised
IN PROGRESS
Backup and recovery
Point-in-time recovery not yet enabled
IN PROGRESS
Third-party risk
Vendor inventory maintained
IN PROGRESS
Data separation
Row-level access on institution, organization and role
UNVERIFIED
This screen is for the diligence reviewer, and it says no where the answer is no
A security page reporting every row green is the one a reviewer stops believing. The rows above are the current position including the three that have not started, because an institution discovers those in week two regardless and it is better they read them here.
DEMO — FIXTURES ONLY, NO DATABASE
