The calculators can be used without creating an account, entering personal data, or completing a form. The optional review request builder runs locally.
Privacy
Privacy policy for calculator users
SaaS Sentinel is currently an informational calculator site. It does not require user accounts or mandatory forms to use the tools.
Summary
What matters most
The site links to external provider pages when a user decides to view official pricing or a partner destination.
Once a visitor leaves the site and opens a provider page, that provider handles its own privacy and tracking policies.
Operational data
What may be processed
Server and hosting logs
Hosting infrastructure can process basic technical logs such as URL, IP address, user agent, and timestamps for delivery, security, and the limited first-party product measurement described below.
Calculator, Decision Room, Provider Response Room, Review Scope Room, Review Delivery Room, Assurance Room, and Decision Monitor inputs
Calculator values, Decision Room constraints, imported decision and assurance dossiers, provider evidence requests and responses, review-scope routing values, review-delivery acceptance references, findings and conclusions, monitor thresholds, commercial assumptions, evidence references, risk gates, and sign-off states are handled in the browser. A shared Decision Room scenario is encoded after the # in the URL, which browsers do not send in the HTTP request. The Provider Response Room, Review Scope Room, Review Delivery Room, Assurance Room, provider evidence reviewer, and Decision Monitor do not put imported files or edits in the URL. Provider Response Room, Review Scope Room and Review Delivery Room do not call a provider API or send imported values to product analytics. The Decision Monitor requests only the public current catalog. JSON and Markdown dossiers, provider responses, provider evidence reviews, review-scope packs and review-delivery records are created locally. Acceptance references and findings may still be commercially sensitive, so redact them before sharing or committing an export. The site does not require these inputs to be submitted through an account.
Analytics status
The site can send a limited set of first-party product events through its own canonical /api/events/ endpoint: page category, selected public catalog dimensions, coarse usage-hour bucket, result count, calculator or assurance-engine use, dossier/export actions, preparation of a review brief, opening of a review-email draft, and clicks to official or affiliate destinations. These events do not prove that an email was sent or that a request was accepted. Decision Room workload constraints, imported decision or assurance dossier contents, provider request or response contents, provider review results, review-form values, review-scope or review-delivery values, acceptance references, findings, conclusions, monitor thresholds or outcomes, cost assumptions, evidence references, risk gates, sign-off states and artifact fingerprints are not included.
Privacy-first measurement
Measurement does not store an analytics identifier in cookies or local storage. A random page-session identifier is created in memory and expires when the page is closed or reloaded. The endpoint uses the hosting platform's normalized client IP only as a transient key for a one-minute abuse-prevention limit; the application does not copy the IP or user agent into the product event. When Runtime Logs provide the measurement fallback, the hosting platform can correlate its standard request metadata with the event at the invocation level. This is treated as pseudonymous operational data, not anonymous data; access is limited to project operators and retention follows the hosting plan's limits. Raw calculator costs, assurance evidence, email addresses, names, and form contents are not included in product events.
Analytics processor
If the optional Google Analytics destination is configured, the server forwards sanitized, non-personalized events without intentionally forwarding the visitor IP address or user agent. Hosting infrastructure may still process standard delivery and security logs.
Contact messages
The independent-review request builder validates and formats information in the browser. It sends nothing to the site. If you choose to open and send the generated email, your email provider and the recipient process the message and reply history to assess and handle the request. Imported dossier files are not attached or uploaded automatically. The Review Scope Room validates that downloaded request locally and exports a draft routing pack; it does not send, accept, sign, invoice, collect payment, or verify either party's identity. After a separate written acceptance, the Review Delivery Room can validate four locally selected artifacts and prepare a review record. Its acceptance attestation and fingerprint are operator-supplied controls, not proof of contract, identity, payment, delivery or purchasing authority.