Skip to main content
SentryOT
  • Solutions
  • Product
  • Platform
  • Our Mission
  • About Us
  • Latest News

Features

  • Asset InventoryA live map of every asset, down to firmware
  • Real Time MonitoringContinuous detection across every OT asset
  • Incident InvestigationFull context on every event, from alert to physical impact
  • Operational ImpactCyber events understood in operational terms
  • Case ManagementFrom alerts to one defensible case

Services

  • Data Sources EnablementEvery OS, ICS, and network source, switched on.
  • Data Retention & ContinuityRedundancy and retention for uninterrupted collection.
  • Infrastructure CalibrationPlatform mapped to your process and infrastructure.
Request a Demo

Cookie Policy

The www.sentryot.com website sets no cookies at all on its public pages, and no analytics or advertising identifiers of any kind unless you accept analytics on the banner shown on your first visit. Two things happen whatever you answer, and this policy is precise about both: the record of your own answer is kept in your browser, so that a refusal does not have to be asked about again; and the contact form is protected by a spam check that runs from Cloudflare’s domain, which stores nothing on your device but does let Cloudflare see your IP address. Sections 5.1 to 5.3 set out each case. Below that you will find how to change or withdraw your answer, and how to control cookies in your browser.

1. What a cookie is

A cookie is a small text file that a website asks your browser to keep, and that your browser sends back the next time you visit. It can be written by the web server or by JavaScript running in the page, and it usually holds a short identifier rather than anything readable.

Related technologies do the same job without being cookies — local storage and session storage, for instance, which hold data in your browser until they are cleared. For the device-storage rules this policy is about, they are treated the same way as cookies: what matters is whether information is stored on or read from your device, not what the technology is called.

An identifier does not have to contain your name to count as personal data. Where it allows a device or a person to be recognised again, data protection law applies to it.

2. How long they last

Session — kept only until you close the browser or leave the site.

Persistent — kept for a stated lifetime, which can be days or months, so the site can recognise the browser on a later visit.

3. What they are used for

Strictly necessary — without them a function you asked for cannot work: keeping you signed in, remembering a choice you made, protecting a form from automated abuse.

Functional — remembering preferences such as a language or a layout.

Performance and analytics — counting visits and recording how pages are used, so that the site can be improved.

Advertising — building a profile of what you look at in order to target advertising. This site uses none.

4. Who sets them: first party and third party

A first-party cookie is set by the site whose address is in your browser’s bar. A third-party cookie is set by a different domain whose content the page has loaded — an embedded video, a font service, a tracking script.

That distinction is about who sets the cookie and has nothing to do with how long it lasts or what it is for: a third-party cookie can be a session cookie or a persistent one, necessary or analytical. It matters because a third party may be able to recognise the same browser across different sites that embed it — though how far that still works depends on the browser’s own protections, several of which now partition or block third-party storage.

5. What types of cookies and device identifiers do we use?

5.1 No analytics storage unless you agree — and one entry that records your answer. Browsing www.sentryot.com sets no cookies at all: not functional, not performance, not analytics, not advertising. Nothing is stored while the banner is still on screen. If you accept analytics, section 5.2 lists exactly what is then set; if you decline, nothing from that list is ever created.

5.1.1 One thing is stored whichever way you answer, and it would be wrong to tell you otherwise: the answer itself. It is a single entry in your browser’s local storage — not a cookie — under the name sentryot.consent.v2, holding the word “granted” or “denied” and the date you answered, and nothing else. It contains no identifier, is never sent anywhere, and exists so that a refusal is respected instead of being asked about on every page. Storing it is strictly necessary for that purpose. It expires about six months after you answer, and we then ask again, because an answer given once should not stand indefinitely. You can change or withdraw your answer at any time under Analytics at the foot of every page, which also deletes what was set under it.

5.2 Analytics you have agreed to: PostHog. If, and only if, you accept, we load PostHog and it sets cookies named ph_…_posthog and ph_…_posthog_cpm, valid for up to twelve months, together with matching entries in your browser’s local storage. We use it for six things: counting which pages are read, recording where on a page visitors click, measuring how far down a page they scroll, following the path visitors take from one page to the next, recording the visit itself so that we can replay it afterwards and see where the site was unclear, and establishing the approximate part of the world a visit came from. That last one works from your IP address: the request our server forwards to PostHog carries it, PostHog looks up a country and region from it, and both the address and the location it produced are kept with the event for as long as the events are kept. We use it at the level of countries and regions to understand where our readers are, not to identify anyone. That recording covers the pages you moved through, your mouse movement, your clicks and your scrolling. It does not cover what you type: every input field is masked before the recording leaves your browser, so nothing you enter into the contact form — your name, your e-mail address, your telephone number — is in it. PostHog is provided by PostHog Inc. and the data is held on its European infrastructure in Frankfurt. It acts on our instructions and for no purpose of its own, and we neither sell this data nor share it with advertising networks. The lawful basis is your consent, Art. 6(1)(a) GDPR. We keep the events for up to twelve months and the session recordings for up to thirty days, and the arrangements for this data leaving the European Economic Area are the European Commission’s Standard Contractual Clauses, incorporated in our data processing agreement with PostHog Inc., a copy of which is available on request. When you withdraw your consent, the cookies and local storage entries listed above are deleted from your device, and they are deleted in the same way if your answer expires before you return.

5.3 The spam check on the contact form, which does not ask you first. The contact page carries a check that distinguishes people from automated scripts, so that the form cannot be used to send us bulk mail. It is Cloudflare Turnstile, provided by Cloudflare, Inc., and it loads only on /contact — no other page requests anything from Cloudflare. Most visitors see nothing at all: it looks for signs of automation in the background and only shows a box to tick when it is unsure. It sets no cookie and stores nothing on this website’s own domain, and we do not use its pre-clearance feature, which is the one part of the product that would issue a clearance cookie. What it does do is send a small set of technical signals to Cloudflare: your IP address, a fingerprint of the way your browser negotiates an encrypted connection, the identifier your browser sends to describe itself, and the key identifying our widget together with the address of the page it ran on. It does not read what you type. Your name, your e-mail address, your telephone number and the text of your inquiry are never sent to Cloudflare — the check runs beside the form, not on it. Two separate points, which are easy to run together: the check places no cookie and no other storage on your device, so there is nothing here that consent law requires us to ask about; and separately, for the personal data involved in running it, we rely on our legitimate interest in protecting the contact form against automated abuse, Art. 6(1)(f) GDPR. You can object to it, as section 5 of the Privacy Policy explains, and write to us directly at office@sentryot.com instead. Cloudflare handles these signals on our instructions for the purpose of the check itself; it also uses them, on its own account, to improve how its bot detection works generally. Cloudflare does not pass those signals back to us: its response tells us whether the check succeeded, along with routine verification details such as the time and the hostname, and never the fingerprint or the other signals behind that verdict. We do not use its optional ephemeral device identifiers. Cloudflare does not publish a retention period for what it holds. Our own servers record your IP address in their ordinary request logs, as any web server does; that is separate from Turnstile and is described in section 2.4 of the Privacy Policy. Its own account of this processing is the Turnstile Privacy Addendum; the transfer arrangements are in section 4.3 of the Privacy Policy.

5.4 Third-party content requests. Fonts, images and scripts are served from our own domain rather than from external content networks, so simply loading a page does not disclose your IP address to a content network. PostHog is addressed through our own domain as well, which means your browser opens no connection to the supplier: our server forwards the request on your behalf, and the data reaches PostHog by that route. The one exception is the spam check described in section 5.3: on the contact page, and only there, your browser fetches it from Cloudflare’s domain and Cloudflare therefore sees your IP address.

5.5 The editorial area. The /admin area, used by SentryOT staff to publish content, sets strictly necessary first-party cookies once a member of staff signs in — one to keep that person signed in, one to remember the language of the editing interface. Neither is set for visitors to the public site.

5.6 If a further cookie or similar technology is introduced, this policy will be updated and, where the law requires your consent, that consent will be requested before the technology is used. Where the change is a material one — a new supplier, or a new purpose — everyone is asked again rather than being held to an answer given about something else.

6. Social plug-ins

The site does not embed third-party social networking plug-ins and uses no social media buttons. The links to our LinkedIn and YouTube pages are ordinary links: they transmit nothing to those networks until you choose to follow them, at which point the policies of the destination apply.

7. How can I stop cookies?

Disabling and refusing to receive cookies may make certain sites impractical or difficult to visit and use. It is possible to set your browser so that cookies are no longer accepted, or to accept cookies only from a specific site.

Your browser will usually provide information on how to refuse, delete or block cookies. The following references take you to that information for the most common browsers:

• Chrome

• Safari

• Firefox

• Edge

• Opera

For a general explanation of what cookies are and what they are used for, see allaboutcookies.org.

8. Changes to this policy

This policy will be updated periodically, depending on the functional, lawful, or internal changes that may occur. In the event of material changes, the updated policy will be published on the site before the changes take effect. We encourage users to check this page periodically for updates on our use of cookies.

SentryOT

Real-time OT defense for critical energy infrastructure.

Product

  • Solutions
  • Product
  • Platform

Company

  • Our Mission
  • About Us
  • Latest News

Contact

  • +40 371 017 242
  • office@sentryot.com

Social

LinkedIn (opens in a new tab)YouTube (opens in a new tab)
Website Terms of UsePrivacy PolicyCookie Policy

© 2026 SentryOT. All rights reserved.