Legal
Last reviewed: 26 July 2026Cookie Policy
This policy explains the cookies and browser storage used by Sentinel42 Ltd on sentinel42.com and inside the ISMS27001 platform. We keep the list short on purpose: Sentinel42 does not run advertising pixels, retargeting, or third-party analytics. Everything below is first-party.
You can change your choice at any time by clicking here or in the site footer.
1. What is a cookie?
A cookie is a small text file a website stores in your browser. “Browser storage” (localStorage and sessionStorage) works the same way but is only readable by JavaScript on our own domain. For the purposes of the UK Privacy and Electronic Communications Regulations (PECR) we treat all three the same.
2. The categories we use
Strictly necessary — required for the site to work (auth, session, security). No consent is required under PECR reg. 6(4)(b).
Functional — remembers preferences you have actively chosen (sidebar, voice mode, saved views). Turning these off means the app will forget your UI choices.
Analytics — not currently used. If we ever add analytics we will ask again before loading them.
Marketing — not currently used. Sentinel42 runs no advertising pixels.
3. Strictly necessary cookies and storage
| Name | Type | Purpose | Duration |
|---|---|---|---|
| sb-<project>-auth-token | Cookie + localStorage | Keeps you signed in and refreshes your session. | Session + 1 hour refresh window |
| s42.legalAccepted | sessionStorage | Records that you accepted our Terms during this session. | Until you close the tab |
4. Functional cookies and storage
| Name | Type | Purpose | Duration |
|---|---|---|---|
| sidebar:state | Cookie | Remembers whether the app sidebar is expanded or collapsed. | 7 days |
| s42.voiceLoopOn | localStorage | Remembers whether hands-free voice mode is switched on for the AI assistant. | Until cleared |
| s42.sidebar.groups | localStorage | Remembers which sidebar groups you have expanded. | Until cleared |
| s42.dashboard.tab | localStorage | Remembers which dashboard tab you last viewed. | Until cleared |
| s42.risks.savedViews / s42.reports.draft | localStorage | Stores saved risk-register views and any unsaved report draft you were working on. | Until cleared |
| s42.onboarding.dismissed.<org> | localStorage | Remembers that you dismissed the onboarding checklist for a given organisation. | Until cleared |
Some readiness dashboards (NIS2, ISO 27701, EU AI Act, DORA, CAF) also cache their completed control counts in your browser so the dashboard tiles render instantly on your next visit. These caches are wiped when you sign out or clear site data.
5. Third parties
Sentinel42 loads Google Fonts on marketing pages using the CSS-only API, which does not set cookies. The AI assistant sends your question text to Google’s Gemini API through our server — no cookies are set by that call. Payment pages, when used, are hosted by Stripe/Paddle and are subject to their own cookie policies.
6. Managing your choice
Use the button to review or change your preferences. You can also clear cookies and storage in your browser settings — doing so will sign you out and reset your preferences. We record your choice in an audit log (categories, timestamp, policy version) so we can demonstrate compliance to the ICO if required.
7. Contact
Questions about this policy or your data: privacy@sentinel42.com. You may also complain to the UK Information Commissioner’s Office at ico.org.uk.