Security
How your money is held, what protects your account, what our own staff can and cannot do, and what none of it protects you from.
Who holds your money
Sentinel does. This is a custodial service. When you deposit, the funds go to wallets we control, and the keys to those wallets, and to the positions we delegate, are held by Sentinel, not by you. Your balance is an entry in our ledger.
That means your ability to withdraw depends on Sentinel continuing to operate, staying solvent and acting honestly. If our systems or keys were compromised, funds could be lost. Nothing we hold is insured, and our platform has not been reviewed by an outside security firm.
The protections below make it much harder for someone else to take money out of your account. They do not change who holds it.
Protecting your account
Each of these is in your security settings once you have an account. The times shown are the ones the platform is using now.
Fund password
A second password, separate from the one you sign in with, that money leaving your account has to present. Your sign-in password is what a phishing page or a reused-password leak already has; the fund password is typed only when money moves, so a stolen session on its own cannot empty the account. Repeated wrong attempts lock it for a while.
- Asked for on every withdrawal
- Yes
- Withdrawals pause after you change it
- 24 hours
Withdrawal address book
Save the addresses you withdraw to. We email you the moment one is added, and a new address has to wait before it can receive anything. The usual takeover runs: get in, add your own address, pay out. The wait and the email give you time to notice and tell us before anything leaves.
- Wait on a new address
- Off
A pause after a security change
When your password, email address changes, withdrawals stay locked for a while. If the change was not you, the money is still there while you get the account back.
- Withdrawals locked for
- 24 hours
Anti-phishing code
Choose a word or phrase in your security settings and it appears at the top of every email we send you. An email that claims to be from Sentinel without your code is not from us. We add it when each email is sent rather than storing it with the message, so it is not sitting where staff can read it.
Sessions and sign-in history
See every device signed in to your account and recent sign-ins, successful or not. Sign out any device you do not recognise, or all of them at once.
What our staff can do, and the record they leave
An audit trail. Staff actions on accounts, withdrawals, settings and the ledger are written to an audit log: who did it, when, what changed, and for sensitive actions the reason they gave. Each entry carries a fingerprint of the one before it, so an entry removed or altered afterwards breaks the chain and shows.
Two people for large withdrawals. Above a set amount, the person who approves a withdrawal cannot also be the one who releases it.
A ledger that checks itself. Every movement is recorded as balanced entries, and your balance is worked out from those entries and checked against the stored figure. Staff with the highest level of access can correct entries; every correction goes on the audit trail.
Read-only help. To help with a problem, support staff can open a read-only view of your account. They cannot move funds or change anything while doing so, each view needs a written reason, and each one is recorded.
The audit trail is internal: you cannot browse it. What you can check yourself is below.
Check what we hold
Our proof of reserves sets what Sentinel owes its customers against what it holds on-chain, with a fingerprint that commits to every balance. Signed in, you can check your own balance was counted.
It shows what we held at the moment it was taken. It does not show what we owe elsewhere, and it is not an audit.
What this protects against, and what it cannot
Helps protect against
- A stolen session, such as a laptop left signed in, being used to send money out without your fund password.
- Someone adding their own address and paying out before you notice.
- Emails pretending to be from us, if you check for your anti-phishing code.
- A single member of staff releasing a large withdrawal alone, or changing records without trace.
Cannot protect against
- Sentinel failing, becoming insolvent or acting dishonestly. That is the cost of a custodial service.
- A breach of our own systems or keys. There is no insurance behind the funds we hold.
- Malware on your own device that can see your passwords and codes as you type them.
- Being talked into sending money to someone. A withdrawal to an address you chose is final once it is on-chain.
- Sending a deposit on the wrong network or to the wrong address.
- Slashing, network failures and changes in the price of what you hold.
Sentinel will never ask for your password or your fund password, by email or otherwise. If you think someone else has been in your account, change your password, sign out every device from your security settings, and contact support. The full list of risks is on the risk page.
Read how the rest works
How the ledger records every movement, and exactly what we charge.