← Back to Senshin
Security & Trust

Your projects are sensitive. We treat them that way.

Senshin holds the plans, budgets, risks and politics of real programmes — often for people who work across several client organisations at once. So isolation and restraint aren't features here. They're the foundation.

Last reviewed: 21 September 2026 · Questions: security@senshin.io

The four things we promise about your data

One person, many clients — kept apart

The hardest case is the honest one: an independent consultant or a delivery lead running several clients inside the same account. Their clients must never bleed into each other.

Every project lives inside a workspace, and every single data operation — reading a risk, loading a budget line, running an AI analysis — is scoped to that workspace before it returns a thing. There is no shared pool a query can accidentally reach across. This isn't a promise on a page: we run multi-tenant isolation tests on every code change, and a release that could let one workspace see another's data does not ship.

What we do — and don't do — with your data

Kept safe

Encrypted at rest and in transit, with access limited to your workspace.

Not on your device

Senshin runs in the browser. Your client's data is shown to you; the browser app does not save a copy to the machine beyond what your browser holds in its normal cache and the files you choose to export. (The optional mobile app keeps an encrypted offline copy — see the Privacy Policy.)

Not sold as personal data

We never sell personal data and never share it for advertising. Our privacy notice describes the kinds of service provider we use. Aggregated industry statistics, if published later, contain no one identifiable.

Not training on your words

The AI reads your project to help you. We don't use it to train foundation models, and our main AI route is set to providers that don't keep it. The anonymous numeric picture is optional, and asked for.

Why the "device" point matters for contractors. Some organisations are wary of a contractor touching their data on unmanaged hardware. With Senshin, the data is held in our cloud and the contractor works through the browser, so the browser app does not put a working copy on that hardware. We do not currently offer controls that restrict which devices or networks may connect.
Based outside the UK? You're not shut out — Senshin serves customers wherever they are. If your organisation has particular requirements about where data is kept, ask us before you sign up — we will tell you plainly what we can and cannot do.

How the AI handles your data

This is where most tools get vague. Here's the specific mechanism.

Senshin reasons in two stages. First, a deterministic engine on our own servers extracts the signals — schedule slippage, budget variance, RAID velocity, and so on — with nothing leaving our infrastructure. Then, to write that up in plain English, your project context is passed to a language model through our AI gateway. Our main route is configured to use only providers that do not keep or train on the request, and we ask for that on each call rather than leaving it to a provider's default setting. Our privacy notice describes the kinds of provider we use.

When you drop files to start a project, Senshin reads the workbook or plan itself first. A language model is used only for running prose that still needs one.

You stay in control

Compliance & posture

UK GDPR In place

Data controller: Alex Sakpoba, trading as Senshin (senshin.io), United Kingdom. Full data-subject rights, honoured within 30 days.

DPA In place

A Data Processing Agreement is available for every customer. Sub-processor information available on request.

Audit trail In place

Data changes, AI runs and sign-ins are recorded in an audit trail.

Encryption In place

Encrypted at rest and in transit.

Certifications None yet

We do not hold SOC 2, ISO 27001 or Cyber Essentials certification, and we do not claim to. If your organisation needs one, tell us before you buy.

Security isn't a one-off box we ticked. We track the standards as they move — UK GDPR guidance, OWASP, cloud best practice — and update continuously. When something changes, this page changes with it.

Found something? Tell us.

If you believe you've found a security issue, email security@senshin.io. We read every report and respond quickly. Responsible disclosure is always welcomed, never penalised.