Security

Security and data handling.

Straterai builds and runs AI systems on client data under a security program designed for regulated, mid-market companies. Your data remains in your systems and your accounts, access is controlled by your team, and the AI provider retains nothing. The detail below is written for your IT lead and your counsel.

01

Your data stays in your systems.

We connect to the systems you already run under access your team controls. The data foundation we build is provisioned in an account your company owns.

02

Zero data retention at the AI provider.

Zero data retention is contracted with our AI provider, and training on your data is prohibited under its commercial terms. Nothing you send the model is stored.

03

Role-based access for your team.

Sign-in runs through your identity provider and permissions follow the roles you already use. Each user sees only what their role allows.

04

Least-privilege access for ours.

Our access is granted per system by a named person at your company, is read-only by default, and can be withdrawn at any time.

05

Your company owns the system.

The data, the code and the infrastructure are your company's property from the first day of the engagement.

06

Encrypted in transit and at rest.

Every vendor that can touch your data is listed on our sub-processors page with its region and attestation. Nothing is added to that list without notice to you.

In detail

How the system is built and controlled.

Each commitment above is stated the same way in your statement of work and data processing addendum.

Architecture

One system per company. Nothing you run is shared with another client or built on a multi-tenant platform.

Instance
Provisioned in your company's name, in an account you own. We administer it for the length of the engagement and can be removed at any time.
Integrations
Read-only connections to the systems you run, granted by your team.
Writes
Only where you ask for them, only into the systems you name, and every write is logged with the person or workflow that caused it.

Data residency

Residency follows your existing systems. Infrastructure we provision is placed in the region you nominate.

Region
United States by default for US companies, or your existing cloud region.
Copies
We keep no second copy of your data. Working files and logs on our side are returned or destroyed on request and confirmed in writing.
Backups
Production databases are backed up with tested recovery procedures.

Access and permissions

The same people see the same things as in the systems they already use.

Sign-in
Through your identity provider. Accounts are removed when a person leaves.
Permissions
Role-based access enforced at the database. Requests above a user's clearance are declined and logged.
Personal data
Employee and customer information is handled as personal data and processed one record at a time.

AI models

The model reads what a workflow needs, returns an answer, and retains nothing.

Retention
Zero data retention, contracted with the provider and verified at the organization level.
Training
Prohibited under the provider's commercial terms.
Scope
Each system accesses only the data its workflow requires, under credentials you approve.

Controls

Controls are enforced in code and infrastructure, with evidence maintained for audit.

Encryption
TLS 1.2 or higher in transit. AES-256 at rest. Full-disk encryption on every device with production access.
Our access
Single sign-on with multi-factor authentication on production infrastructure. Quarterly access reviews.
Incidents
A documented incident response process. You are notified within 72 hours of a confirmed incident affecting your data, or sooner where your contract requires.

Due diligence

Your security and IT teams can review the system before it touches production data.

Inspection
Full visibility into how the system works, where data flows, and what the model is permitted to do.
Evidence
Policies, access registers, the data inventory and disaster-recovery test records are available to your counsel under NDA.
Vendors
Listed on our sub-processors page and in your data processing addendum, with 30 days' notice before any addition.
Compliance program

Built for audit.

The controls above sit inside a security program maintained by our engineering team. The evidence behind every line is available to your counsel under NDA.

Security policies

In place and version controlled: access control, data classification, acceptable use, backup and disaster recovery, vendor management.

Continuous monitoring

Live through Vanta, across cloud accounts, source control and hosting.

SOC 2

Type I audit in progress. The report is shared with you when it is issued.

Network assessment

Completed May 2026, repeated annually.

Penetration test

Independent black-box test scheduled for 2026, then annually.

Evidence registers

Access, devices, data inventory and disaster-recovery tests, held in version control.

Questions, or the full policy set under NDA: security@straterai.com

Empowering Enterprises,
Engineering the Future.

Start the conversation
Or writeinquire@straterai.com
Hear from a founder within a business day