Skip to content
StratEdge

Trust center

What we do, and what we have not done yet

Security pages usually imply more than the company can substantiate. This one is written to survive a diligence conversation.

Compliance status

StratEdge is not SOC 2 certified. We have not completed an external penetration test. Both are on the roadmap and neither is done.

If your procurement process requires either one today, tell us on the first call. We will either point you elsewhere or agree a timeline in writing — we will not tell you it is “in progress” and hope the question does not come back.

Controls in place

Authentication
MFA required for all StratEdge staff accounts. Session rotation. OAuth and magic link supported for clients.
Authorization
Role-based access enforced at three independent layers, with row-level security in the database as the final backstop. A permission bug in application code does not expose data.
Tenant isolation
Every record carries an organization identifier and is filtered by database policy, not by an application-level query clause. Cross-organization access fails closed.
Encryption
AES-256 at rest, TLS 1.3 in transit. Card data goes directly to Stripe and never reaches our infrastructure.
Audit logging
Append-only. Every state change, permission change, payment, and data export is recorded with actor, timestamp, and before/after values. Retained seven years.
File handling
Private storage buckets, signed URLs with short expiry, MIME validation by content rather than extension, and malware scanning before a file becomes readable.
Backups
Continuous point-in-time recovery plus daily logical dumps to separate infrastructure. Restores are drilled, not assumed.
Monitoring
Error tracking, uptime monitoring, and alerting on authentication anomalies and authorization policy errors.

How we use AI

We use AI to draft and to surface signal. We do not use it to decide anything.

  • No automated decision affects payment, assignment, project status, or account standing.
  • Client-identifying data is stripped before any request made in an engineering or staffing context.
  • Client-facing text derived from AI is always reviewed and edited by a human before it is sent.
  • Retrieval features run under the requesting user’s own database permissions — the boundary is the database, not a prompt instruction.
  • Every AI feature has a manual fallback. Nothing in our delivery process stops if a model provider has an outage.

If this stops being accurate, this page changes before the behavior does.

Data handling

Residency
Client data is stored and processed in U.S. regions. EU-region processing is available on request for EU entities.
Retention
Contracts, invoices, and audit records for seven years as legally required. Project files and messages for the project lifetime plus three years. Everything else deleted on request.
Deletion
Honored except where legal retention applies, in which case we strip personal data and keep the financial record — and tell you exactly what was kept and why.
Engineer access
Subcontracted engineers work under signed NDA and IP assignment. By default they do not receive your organization identity, contacts, or contract value.

Reporting a vulnerability

Email security@stratedge.global with steps to reproduce. We acknowledge within two business days and will keep you updated through remediation.

We will not pursue legal action against researchers acting in good faith who avoid privacy violations, service degradation, and data destruction, and who give us reasonable time to fix an issue before disclosing it.

Documents