Straterai/Security/Sub-processors
Trust · Sub-processors · Live

Who touches your data.

Straterai uses the third parties below to deliver our products and services. Every entry on this list has a Data Processing Addendum on file. We update this page when sub-processors change.

Last updated 2026-05-12 · Eastern Time

Amazon Web Services

aws.amazon.com/compliance

Primary hosting, storage, and compute for the Sentinel control plane and enterprise client systems.

Data categories
Application data, system logs, encrypted backups
Processing region
us-east-1 (N. Virginia)

Vercel

vercel.com/legal/privacy-policy

Application hosting and global edge delivery for the Straterai marketing site and client product surfaces.

Data categories
Application data, request logs, build artifacts
Processing region
Global edge, primary US

Anthropic

anthropic.com/legal/privacy

Large-language-model inference for every AI feature we ship. Commercial API tier with zero data retention and no training on inputs.

Data categories
Prompts, retrieved context, model outputs
Processing region
United States

Neon

neon.tech/privacy-policy

Managed Postgres for client products that run on Neon (Occasio, Sleep Geekz).

Data categories
Application database records, point-in-time backups
Processing region
United States

Sentry

sentry.io/security

Runtime error and performance telemetry for the marketing site and client products.

Data categories
Stack traces, request metadata, user identifiers when present
Processing region
United States

Bitwarden

bitwarden.com/privacy

Internal secrets vault for credentials issued to Straterai personnel and AI agents.

Data categories
Internal secrets only. No client data.
Processing region
United States

Google Workspace

workspace.google.com/security

Email, calendar, and document collaboration for Straterai personnel.

Data categories
Correspondence, meeting metadata, internal documents
Processing region
United States

GitHub

docs.github.com/site-policy

Source-code hosting and version control for the gbholdings organization.

Data categories
Source code, issue and pull-request history
Processing region
United States

Vanta

vanta.com/privacy

Compliance program automation. Continuous control monitoring across the sub-processors above. Scale tier engaged 2026-05-12.

Data categories
Configuration metadata from connected systems, evidence artifacts
Processing region
United States
Compliance posture

SOC 2 Type 1 audit in progress with a target of Q3 2026. ISO 27001 in parallel with a target of Q4 2026. Compliance program managed via Vanta. Email security@straterai.com for our current evidence package or to request a Data Processing Addendum.