Docs
API v1
Session cookie or CI token depending on the route. No public stack trace. Reference ID on worker errors.
Reviewed 2026-09-14 · Automated technical assessment. Not a legal certification.
Auth
HMAC session cookie. CI token on /ci routes. Viewer: read-only (requireWriter).
Examples
GET /api/v1/sites ; GET /api/v1/sites/:id/status ; POST /api/v1/sites/:id/scans ; GET /api/v1/incidents ; GET /api/v1/evidence/:id
Errors
{ error, message, reference? }. SCAN_FAILED and JOB_FAILED carry a Reference ID. No public stack.
Test this behaviour on a live website
Limited public scan. No free history. SentriRail is a drafting aid. It is not legal advice. You are solely responsible for whether generated documents fit your situation. When in doubt, consult a privacy lawyer.