Trust Center

The answers to your CIP-013 vendor review, before you ask.

You must assess every vendor whose products touch your BES Cyber Systems. Here is how CIP Sentry addresses each vendor process in CIP-013-2 R1.2, and what we can provide for your review.

On-premises onlyYour data stays on your hardware.
No outbound callsNo telemetry, no call-home, no cloud AI.
No vendor accessWe cannot reach your system.
Verifiable releasesSHA-256 hashes for every release.

CIP-013-2 R1.2

Our commitments for each vendor process

R1.2.1

Notification of vendor-identified incidents

If we identify a cyber security incident that affects CIP Sentry software, a release, or our build and release systems, we notify affected customers' designated security contacts without undue delay and no later than 72 hours after we confirm it, with what we know, what to do, and when we will update you.

R1.2.2

Coordination of incident response

A named security contact (security@cipsentry.com) coordinates with your incident response team, shares indicators and remediation steps, and supports your CIP-008 process. We follow your lead on communications inside your organization.

R1.2.3

Notification when vendor access should end

CIP Sentry runs on your servers and we have no standing remote or onsite access to your systems. If you grant temporary access for support, you control it, and we tell you as soon as a named representative no longer needs it (for example, on role change or departure).

R1.2.4

Disclosure of known vulnerabilities

We publish a vulnerability disclosure policy, accept reports through security.txt, and notify customers of confirmed vulnerabilities in CIP Sentry with severity, affected versions, fixes and workarounds.

R1.2.5

Software integrity and authenticity

Every release is published with SHA-256 hashes, on this site and by email to your designated contact, so you can verify identity and integrity under CIP-010 R1.6. Code-signed installers and signed update packages are on our roadmap.

R1.2.6

Coordination of remote access

There is no vendor-initiated remote access. Support sessions are customer-initiated screen shares that you start, supervise and end, under your own remote access controls.

Documents

What we provide for your assessment

Ask for the package by email and tell us your utility's name and your role. We usually respond within two business days.

  • Security overview (architecture, data flows, controls)On request
  • NATF Energy Sector Supply Chain Risk Questionnaire (v7.0), completedOn request
  • Software bill of materials (CycloneDX JSON) per releaseOn request
  • Release notes and security advisories (your CIP-007 R2.1 patch source)Published with each release
  • SHA-256 hashes for every releasePublished with each release
  • Vulnerability disclosure policyPublic
  • Certificate of insurance, W-9On request
  • Hardening and deployment guideIncluded with the product

Product security

Security built into CIP Sentry

Isolation by default

The database and internal services can only be reached from the server itself. People reach CIP Sentry through a single encrypted connection, secured with certificates you control.

Accounts and permissions

Strong one-way password hashing, role-based permissions per module, and a one-time server-side setup code for the first administrator.

Auditability

Changes to compliance records and administrative settings are written to the audit trail.

Secrets per install

Every installation generates its own random secrets on first start. Nothing is shared between customers.

Resilience

Nightly database backups with 30-day retention and an automatic backup before every update.

Roadmap

Multi-factor authentication for local accounts, directory (SSO) integration, code-signed installers, signed update packages and an independent penetration test are on our roadmap.

Trust FAQ

Questions security teams ask

Does CIP Sentry send any data to you or to a cloud service?

No. CIP Sentry makes no outbound connections to us: no telemetry, no license call-home and no cloud AI. If you add the optional AI Assistant module, it connects only to a model server on your own network.

Is the AI Assistant required?

No. The AI Assistant is an optional add-on module. If you add it, the model runs on your hardware, never decides a compliance fact, and nothing it drafts is used until a person reviews it.

Is CIP Sentry SOC 2 certified?

Not yet. As a focused vendor we prioritize the controls utilities assess under CIP-013: signed software, published hashes, vulnerability disclosure, incident notification and no vendor access. We complete the NATF questionnaire and share our security overview on request. Independent assessments are on our roadmap, and we will publish them here when complete.

How are passwords and access handled in the product?

Passwords are stored with strong one-way hashing, permissions are role-based per module, the first administrator is created with a one-time code only readable on the server, and changes are recorded in the audit trail. Multi-factor authentication for local accounts is on the product roadmap.

Will you accept our contract language?

Yes, in most cases. We are familiar with the EEI Model Procurement Contract Language (v4.0) for cybersecurity supply chain risk and can align to your CIP-013 terms.

What if CIP Sentry, the company, goes away?

Because CIP Sentry runs entirely on your servers, it keeps working. Your data is in a standard database you control. Source code escrow can be arranged for customers who require it.

Request a quote

See CIP Sentry on your own terms.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.