Trust center
What we do, and what we have not done yet
Security pages usually imply more than the company can substantiate. This one is written to survive a diligence conversation.
StratEdge is not SOC 2 certified. We have not completed an external penetration test. Both are on the roadmap and neither is done.
If your procurement process requires either one today, tell us on the first call. We will either point you elsewhere or agree a timeline in writing — we will not tell you it is “in progress” and hope the question does not come back.
Controls in place
- Authentication
- MFA required for all StratEdge staff accounts. Session rotation. OAuth and magic link supported for clients.
- Authorization
- Role-based access enforced at three independent layers, with row-level security in the database as the final backstop. A permission bug in application code does not expose data.
- Tenant isolation
- Every record carries an organization identifier and is filtered by database policy, not by an application-level query clause. Cross-organization access fails closed.
- Encryption
- AES-256 at rest, TLS 1.3 in transit. Card data goes directly to Stripe and never reaches our infrastructure.
- Audit logging
- Append-only. Every state change, permission change, payment, and data export is recorded with actor, timestamp, and before/after values. Retained seven years.
- File handling
- Private storage buckets, signed URLs with short expiry, MIME validation by content rather than extension, and malware scanning before a file becomes readable.
- Backups
- Continuous point-in-time recovery plus daily logical dumps to separate infrastructure. Restores are drilled, not assumed.
- Monitoring
- Error tracking, uptime monitoring, and alerting on authentication anomalies and authorization policy errors.
How we use AI
We use AI to draft and to surface signal. We do not use it to decide anything.
- No automated decision affects payment, assignment, project status, or account standing.
- Client-identifying data is stripped before any request made in an engineering or staffing context.
- Client-facing text derived from AI is always reviewed and edited by a human before it is sent.
- Retrieval features run under the requesting user’s own database permissions — the boundary is the database, not a prompt instruction.
- Every AI feature has a manual fallback. Nothing in our delivery process stops if a model provider has an outage.
If this stops being accurate, this page changes before the behavior does.
Data handling
- Residency
- Client data is stored and processed in U.S. regions. EU-region processing is available on request for EU entities.
- Retention
- Contracts, invoices, and audit records for seven years as legally required. Project files and messages for the project lifetime plus three years. Everything else deleted on request.
- Deletion
- Honored except where legal retention applies, in which case we strip personal data and keep the financial record — and tell you exactly what was kept and why.
- Engineer access
- Subcontracted engineers work under signed NDA and IP assignment. By default they do not receive your organization identity, contacts, or contract value.
Reporting a vulnerability
Email security@stratedge.global with steps to reproduce. We acknowledge within two business days and will keep you updated through remediation.
We will not pursue legal action against researchers acting in good faith who avoid privacy violations, service degradation, and data destruction, and who give us reasonable time to fix an issue before disclosing it.
Documents
- Privacy Policyv0.1 — draft · effective 2026-07-25
- Terms of Servicev0.1 — draft · effective 2026-07-25
- Cookie Policyv0.1 — draft · effective 2026-07-25
- Subprocessorsv0.1 — draft · effective 2026-07-25