Security
Enterprise-grade security built into every layer. Your data is protected by industry-leading encryption and SOC 2 compliant infrastructure.
256-bit AES Encryption
SOC 2 Compliant Infrastructure
GDPR Ready
US Data Centers
Data Encryption
- ✓In Transit: All data encrypted via TLS 1.3 (bank-level security)
- ✓At Rest: AES-256 encryption for all stored data
- ✓API Keys: Encrypted and never logged in plaintext
- ✓Passwords: Bcrypt hashed with unique salts
Infrastructure Security
- ✓Hosting: Fly.io (SOC 2 Type II certified)
- ✓AI Provider: Anthropic Claude (SOC 2 Type II certified)
- ✓Database: PostgreSQL with automated backups
- ✓Location: US-based data centers (configurable for enterprise)
- ✓Uptime: 99.9% SLA with automatic failover
Access Controls
- ✓Authentication: Secure OAuth 2.0 with Google/GitHub SSO
- ✓Sessions: JWT tokens with automatic expiration
- ✓Permissions: Role-based access control (RBAC)
- ✓Audit Logs: All access and changes logged
AI & Data Privacy
- ✓No Training: Your data is never used to train AI models
- ✓Data Isolation: Each account's data is logically separated
- ✓Retention: You control your data retention policies
- ✓Deletion: Full data deletion available on request
Compliance & Certifications
- ✓GDPR: Compliant with EU data protection regulations
- ✓CCPA: Compliant with California privacy requirements
- ✓Infrastructure: Built on SOC 2 Type II certified providers
- ◐SOC 2: Formal certification on 2026 roadmap
Enterprise customers can request our vendor security questionnaire and Data Processing Agreement (DPA).
Security Reporting
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.
Report vulnerabilities to:
security@stricklandai.com
We commit to acknowledging reports within 48 hours and providing updates on remediation progress.
Subprocessors
We use the following third-party services to provide our platform:
| Provider | Purpose | Location | Compliance |
|---|---|---|---|
| Anthropic | AI Processing | USA | SOC 2 Type II |
| OpenAI | AI Processing | USA | SOC 2 Type II |
| Fly.io | Hosting | USA | SOC 2 Type II |
| Supabase | Database | USA | SOC 2 Type II |
| Resend | USA | SOC 2 Type II | |
| Stripe | Payments | USA | PCI DSS Level 1 |
Enterprise Security Requirements?
Need a vendor questionnaire, DPA, or custom security review? We're here to help.
Contact Enterprise Sales