Family Sentinel
The standard we hold ourselves to

How we decide —
and who we answer to.

Most of what a security company does is invisible, which means most of what it claims is unfalsifiable. This page is the opposite: how a verdict is actually reached, the exact moment a person steps in, how we decide what our public Scam Library says we can and cannot catch, and the things we have committed not to do. Written so you can hold us to it.

Reviewed by the founder · last updated 1 August 2026. If something on this page stops being true, it is a bug, and security@familysentinel.org reaches a person.

Where we stand

We are on the family’s side of the table.

Every other product in this market sells to a technician: an IT manager, an MSP, a security team. Their buyer is the person who runs the mail system. Ours is the son or daughter quietly worried about a parent, and that changes every decision we make.

We sell one thing

Monitoring. We are not a reseller, we take no commission from any vendor, and we do not earn a referral fee for pointing you anywhere. When we say Google and Microsoft already do something well, nothing about our revenue changes.

Our reference library is free and ungated

Forty-nine scams, a comparison of every kind of email protection including ours, and a free posture check. No email address, no account. A family that reads all of it and never buys anything is still a family that got helped.

We publish what we miss

The Scam Library says, per scam, whether we detect it, partly detect it, or do not yet. A vendor with nothing to hide can afford an unflattering table; one selling completeness cannot.

How a verdict is reached

Three layers, and a person at the end of them.

Every message takes the same path. Nothing about it changes because of who you are or what you pay.

1 · Deterministic forensics

Facts, not opinions: does the sender authentication actually pass, is the visible link the real link, is the attachment what it claims to be, is the domain days old, does the link appear on a live threat feed. These produce evidence rather than a guess, and evidence is never talked back down by anything below.

2 · Reading for intent

An AI analysis reads the message the way a fraud examiner would — what is it asking for, how does it want to be paid, why the urgency. This is where AI-written attacks are caught, because they are fluent and polite and fail on none of the old tells.

3 · Patterns over time

Some signals exist only across days: a burst of password resets, a sudden surge of scam attempts, the first reply to a sender we previously flagged. A single message cannot show these.

The rules that stop false alarms

Published, and deliberately boring. Phishing requires a payload — you cannot phish someone with prose alone, so a message with no link, no attachment, no phone number and no request is capped no matter how odd it sounds. Mentioning a brand is not impersonating it. First contact only matters from a domain that did not exist last year.

When a person steps in

Before your family is alarmed, never after. A serious verdict is reviewed by a working Security Architect, and the alert is held until it is. An automated system that wakes a household at 2am on its own confidence is a system we would not want pointed at our own parents.

What we do when we are unsure

Hold it and look. The uncertain middle is where every product either cries wolf or goes quiet, and it is the only part of this job that is genuinely hard. Those go to a person rather than to a threshold.

The coverage labels

How we decide what to claim.

Detected

We have a specific detection for this scam and a test that proves it fires on a real example of one. Not "our AI would probably notice" — a named check with a fixture behind it.

Partly detected

We catch the common shape and would likely miss a careful variant, or we catch it only when it arrives with a link or an attachment. Said plainly, because "partly" is the honest answer more often than anyone in this industry admits.

Not yet

We would probably miss it. It stays in the library anyway, with how to spot it yourself, because you are more likely to be hurt by a scam nobody warned you about than by one we labelled honestly.

A label may only be raised by evidence — a real message it fired on, or a test that proves it. It is lowered the moment we find a miss, including one we found ourselves. We also now watch for the case where Google or Microsoft re-files as spam a message we called clean: that is a mistake by us, labelled for free by a better classifier, and we would rather know.

What we keep

The retention schedule, in numbers.

These are not intentions. Each one is an instruction that runs automatically on a timer and writes to an audit log — not a task somebody has to remember.

Ordinary, safe mail → nothing

The only trace is the provider’s message ID, so we do not scan the same message twice. No sender, no subject, no body. That record is itself deleted.

A message we warned you about → 14 days

Encrypted. Your proof if you need it for a bank or a police report, then destroyed.

The verdict record → 13 months

Who it was from, what it was, and why we judged it. Your audit trail — not the message.

The alert we sent → wording erased at 90 days

The record that a decision was made survives; the quoted content does not.

Who you write to → addresses only, 730 days

Knowing your real correspondents is how we tell a stranger from your own family.

On cancellation → purged within 30 days

Confirmed in writing. And you can revoke our access yourself at Google or Microsoft in under a minute, without telling us.

The full permissions story, including the one claim we deliberately refuse to make, is on the Trust page.

Social proof

There are no testimonials on this site. Here is why.

We are new, and we have very few customers. We could fill this page with plausible quotes from plausible-sounding people and almost nobody would check. That is apparently normal in this industry. It is also the single easiest thing to fake, which is exactly why it should mean nothing to you when you see it elsewhere.

When we do publish them, here is the standard. Every quote will be from a real customer who gave written permission. None will carry a full name — our customers are people who were targeted by criminals, and publishing “Margaret in Denton nearly lost $40,000” would put a target on them. They will be attributed the way an auditor would accept: a role and an organization size, or a relationship and a state. “Family member, Texas.” “Office manager, 40-person congregation.”

Until then, judge us on the things you can verify without trusting us: the coverage table that says what we miss, the free check that asks for nothing, the permissions we publish before you grant them, and this page.

Stated as refusals, not promises

What this standard commits us to

Hold us to it.

If anything on this page does not match what we actually do, that is worth knowing and we want to hear it. security@familysentinel.org reaches a person, and so does (940) 281-6672.