Skip to content
Bentry

Security & trust

What Bentry does with attendance and biometric data — for organisations evaluating the product in India. This is not a certification claim.

Plane separation

User, admin, kiosk (device), and super-admin traffic use separate hosts and tokens. An admin session cannot call device routes; a kiosk token cannot administer an organisation.

No selfie retention

When someone enrols a face, the photograph is converted to a mathematical template and discarded. Bentry does not keep face images for attendance.

Erase your face without deleting your account

People can erase face data in the user app (E3) and keep marking with My-QR or assisted mark. Attendance history stays append-only for the organisation’s legal record.

India region

Production runs in Amazon Web Services Mumbai (ap-south-1). Databases are not on the public internet.

Wall terminals (ADMS)

eSSL / ZKTeco-style machines match on the device and push punches only. Bentry stores the punch and the terminal mapping — not fingerprint or face templates from those machines.

Mark without face

My-QR on the kiosk and assisted mark are equal attendance paths — not secondary fallbacks. Organisations choose channels; refusing face enrolment does not mean slower or lesser marking.

Service readiness

Live dependency probe: https://api.bentry.app/readyz. A 200 means the API can serve traffic; it is not a full public status board.

Privacy notice: bentry.app/privacy. Terms: bentry.app/terms.

Questions: admin.bentry@gmail.com