FAQ
Quick answers to the questions customers ask most. Each answer links to the page with the full detail - start here, then follow the link if you need more.
Getting started & accounts
Section titled “Getting started & accounts”Do I need to install anything to use Sencai?
Section titled “Do I need to install anything to use Sencai?”No - the platform application at app.sencai.space runs entirely in your browser; you sign up, sign in, and manage everything from there. The one thing you might install separately is the fleet agent, a small binary for servers you want Sencai to monitor and manage directly. See Create your account and Fleet agent.
How do I create an account?
Section titled “How do I create an account?”Sign up at app.sencai.space/auth/register with your name, email address,
and a password, then verify your email before your first sign-in. You can
also sign up using your existing Google or Microsoft account instead. See
Create your account.
Can my organization use enterprise SSO instead of passwords?
Section titled “Can my organization use enterprise SSO instead of passwords?”Yes - an organization Owner or Admin can configure Microsoft Entra ID or Google Workspace single sign-on so members sign in with their corporate identity instead of a Sencai-specific password. This is set up per organization by an administrator, not by individual members. See SSO.
Should I turn on two-factor authentication?
Section titled “Should I turn on two-factor authentication?”We recommend it, especially if your organization manages production infrastructure. Once you enable it from your profile’s security settings, every future sign-in asks for a 6-digit code from your authenticator app in addition to your password. See Account security.
What happens if I lose access to my authenticator app?
Section titled “What happens if I lose access to my authenticator app?”Turning two-factor authentication off yourself requires a valid code from the same device, so there’s no self-service reset if you’ve genuinely lost it. Contact support to regain access to your account.
Organizations & access
Section titled “Organizations & access”What’s the difference between an organization and my personal account?
Section titled “What’s the difference between an organization and my personal account?”Instances, fleet agents, billing, and most settings belong to an organization - your team’s shared workspace - not to you as an individual. Separately, your own personal account has its own plan governing how many organizations you can own, how many members you can invite into each of them, and your AI-assisted features. See Organizations & teams and Personal plans.
What roles can members have, and what can each one do?
Section titled “What roles can members have, and what can each one do?”Organizations have five roles, from most to least privileged: Owner, Admin, Member, Auditor, Viewer. Owner and Admin can manage members and most settings, Member has standard working access, Auditor is read-only access scoped to audit and compliance data, and Viewer is general read-only access. See Roles & permissions.
How do I invite someone to my organization?
Section titled “How do I invite someone to my organization?”An Owner or Admin invites a new member by email from the organization’s member settings. The invitation has to be accepted before that person counts as a member - a pending, unaccepted invitation grants no access on its own. See Organizations & teams.
Can I manage infrastructure for more than one customer organization?
Section titled “Can I manage infrastructure for more than one customer organization?”Yes, through a cross-tenant relationship between organizations - each with its own scoped access and audit trail, rather than one shared set of credentials passed around between customers. This is typically arranged with your account team. See Agency.
Cloud accounts & providers
Section titled “Cloud accounts & providers”Which cloud providers does Sencai support today?
Section titled “Which cloud providers does Sencai support today?”Sencai natively integrates with a broad set of providers, including AWS, Microsoft Azure, Google Cloud, Hetzner, DigitalOcean, Scaleway, OVHcloud, UpCloud, Oracle Cloud (OCI), Vultr, and Linode (Akamai), with IBM Cloud support in progress. Not every provider necessarily appears in the credential form on every screen that manages cloud accounts - check the provider picker in the app. See Connect a cloud provider.
Can Sencai provision infrastructure without my own cloud account?
Section titled “Can Sencai provision infrastructure without my own cloud account?”Not as a self-service option today. Provisioning and managing cloud instances requires you to connect your own provider account (bring your own cloud) - instances then run on infrastructure you control and are billed by that provider in addition to Sencai’s platform fee. Sencai can also provision and bill capacity on your organization’s behalf as an alternative, but that’s arranged through your account team rather than an in-app toggle. Separately, the fleet agent doesn’t need any cloud account - it works on servers you already have, cloud or not. See Connect a cloud provider.
What permissions does Sencai need on my cloud account?
Section titled “What permissions does Sencai need on my cloud account?”It depends on what you want Sencai to do: read-only access is enough for discovery and monitoring, while provisioning and managing resources needs write access too. Wherever your provider supports scoped or read-only tokens, start with one of those rather than an account-wide admin credential. See Credential permissions.
Is my cloud credential stored securely?
Section titled “Is my cloud credential stored securely?”Credentials are encrypted at rest and are never displayed in full again once saved - including to Sencai staff. A credential belongs to exactly one organization and is never shared across organizations, even if you’re a member of more than one. See Connect a cloud provider.
Can Sencai import infrastructure I already have running?
Section titled “Can Sencai import infrastructure I already have running?”Yes - a discovery scan against a connected cloud account finds existing resources so you can bring them under Sencai’s management instead of recreating them from scratch. See Import existing infrastructure.
Fleet agent
Section titled “Fleet agent”Does the fleet agent work on servers that aren’t in the cloud?
Section titled “Does the fleet agent work on servers that aren’t in the cloud?”Yes - the fleet agent runs on bare metal, on-premise machines, and cloud VMs alike, including ones Sencai didn’t provision. It doesn’t require a connected cloud account at all. See Fleet agent.
What operating systems and architectures does the agent support?
Section titled “What operating systems and architectures does the agent support?”Linux, on amd64 or arm64. See Install & enroll an agent.
What does the fleet agent actually do once installed?
Section titled “What does the fleet agent actually do once installed?”Depending on which capabilities your organization grants it: software inventory, patch status, CIS-style security scanning, and running pre-approved runbooks. A newly enrolled agent starts with monitoring only - an admin grants any further capability you want. See Fleet agent.
Can I isolate a server if I think it’s compromised?
Section titled “Can I isolate a server if I think it’s compromised?”Yes, where fleet command dispatch is enabled for your environment - quarantine drops a server’s outbound network traffic at the OS level from within the app, without you needing to touch the server directly. Where dispatch is not enabled, both isolating and releasing fail outright rather than queueing. Releasing also requires the appropriate organization role. See Quarantine.
Security & compliance
Section titled “Security & compliance”Is every action in Sencai logged?
Section titled “Is every action in Sencai logged?”Yes - cloud provisioning, fleet agent actions (including runbook runs), browser terminal sessions, and organization membership changes are all recorded in an append-only audit trail, including which user performed the action. See Audit log.
Does Sencai help with NIS2 or similar compliance requirements?
Section titled “Does Sencai help with NIS2 or similar compliance requirements?”Yes - Sencai tracks compliance controls and CIS hardening scores, and can compile evidence relevant to frameworks like NIS2 from data it already collects about your environment. See NIS2.
Does Sencai scan for leaked secrets and known vulnerabilities?
Section titled “Does Sencai scan for leaked secrets and known vulnerabilities?”Yes, though scanning has to be turned on for your environment before anything appears here - don’t read an empty screen as confirmation that nothing has leaked. Leaked credentials detected in the Git repositories you manage through Sencai are surfaced as secret findings, and known CVEs in the container images your cloud instances run are tracked separately with their own resolution workflow. See Vulnerabilities and Secret findings.
Data & privacy
Section titled “Data & privacy”Where is Sencai built and hosted?
Section titled “Where is Sencai built and hosted?”Sencai is built in the EU. For where your specific platform data is hosted, see the data residency page on the main site; for infrastructure running on your own connected cloud account, that’s the region(s) you chose when provisioning it. See Regions & data residency.
What data does Sencai collect about my infrastructure?
Section titled “What data does Sencai collect about my infrastructure?”Whatever a feature you’re using is explicitly designed to read - for example, inventory metadata, monitoring metrics, and audit records - not the contents of your servers or databases beyond what that feature needs. See Privacy & agreements for the specifics that apply to your organization.
Can I get a copy of my data, or have it deleted?
Section titled “Can I get a copy of my data, or have it deleted?”Yes - see Privacy for how to request an export of your data or the deletion of your account and associated data.
Billing & plans
Section titled “Billing & plans”What happens when my trial ends?
Section titled “What happens when my trial ends?”Nothing is deleted. Every organization starts on a 14-day trial with no credit card required (fair-use limits apply during the trial), and when it ends an Owner picks a tier to continue on - your configuration and data are kept exactly as they were either way. See Billing & plans.
What’s the difference between an organization tier and a personal plan?
Section titled “What’s the difference between an organization tier and a personal plan?”They’re independent billing axes. Your organization’s tier covers shared infrastructure, seats, and limits; your own personal plan (Free, Plus, AI, Unlimited) covers things scoped to you individually: how many organizations you can own, how many members each of those may have, and your AI-assisted features. See Billing & plans and Personal plans.
What happens if a payment fails?
Section titled “What happens if a payment fails?”Your organization doesn’t lose access immediately - it enters a grace period first, then becomes read-only if the issue isn’t resolved, and only as a last resort are non-terminal cloud instances terminated. Resolving payment at any point before the final step restores everything to normal right away. See Billing & plans.
Can someone else pay for my personal plan?
Section titled “Can someone else pay for my personal plan?”Yes - one user can sponsor another user’s personal plan. See Personal plans.
API & integrations
Section titled “API & integrations”Can I use Sencai’s API instead of the web app?
Section titled “Can I use Sencai’s API instead of the web app?”Yes - create a personal access token from your organization’s API settings and use it with the official SDKs, or call the API directly. See API tokens.
Can an AI agent act on my organization’s behalf?
Section titled “Can an AI agent act on my organization’s behalf?”Read access is the most mature path today. Write access is possible but is off by default at two independent levels - the token itself needs read/write scope, and an organization Owner has to separately turn on AI-agent write access - so a leaked or over-broadly-scoped token alone can’t do anything on its own. See AI agents and API tokens.
Does Sencai support webhooks?
Section titled “Does Sencai support webhooks?”Yes - you can register a webhook endpoint to be notified when events happen in your organization, such as provisioning completing or an incident being raised. See Webhooks.
Troubleshooting
Section titled “Troubleshooting”I can’t sign in - what should I check first?
Section titled “I can’t sign in - what should I check first?”Confirm you’re using the right email and password (or the SSO option your organization set up), that you’ve verified your email address, and that your two-factor code hasn’t expired. See Troubleshooting for a fuller breakdown by symptom.
My invitation link isn’t working.
Section titled “My invitation link isn’t working.”An invitation only grants access once it’s accepted, and it can be resent or revoked by an Owner or Admin - ask them to check its current status. See Troubleshooting.
How do I get help?
Section titled “How do I get help?”Use the support option in your organization’s settings, or see Support - response times depend on your organization’s tier.
Where can I find the technical/architecture side of Sencai?
Section titled “Where can I find the technical/architecture side of Sencai?”This site covers how to use the platform. Sencai’s internal engineering documentation is a separate, non-public site.
Why is this documentation only in English right now?
Section titled “Why is this documentation only in English right now?”The main sencai.space marketing site supports multiple languages; this documentation site will follow once there’s reviewed content to publish in another language.
What’s next
Section titled “What’s next”- Getting started - accounts, sign-in, and the first things to do
- Troubleshooting - symptom-by-symptom fixes
- Glossary - every term used across this site
- Support - how to reach a human