Trust & Security

You’re Sending Us Your Payments Data. Here’s How We Protect It.

Straata works from your transaction exports, residual reports, merchant statements, and processor contracts. That data is confidential, and it is handled like it. Below is exactly what we do today, what we are certified against, and what is on the roadmap. We will only ever tell you where we actually are.

ComplianceSOC 2 in progressType I audit underway; Type II to follow
Cardholder dataNone handledOutside PCI DSS scope by design
Your data & AINever used to train modelsAI runs through Anthropic’s API
Every engagementUnder NDADPA available on request

Certification

SOC 2, in progress and honestly staged.

SOC 2 is an independent audit of a service organization’s controls, and it applies to a services firm like ours just as it does to software. We are pursuing it on a phased plan.

Type IAudit underway

An independent auditor’s attestation that our controls are designed correctly, at a point in time.

Type IITo follow

The report that proves those controls operate effectively over a monitored window. Its observation period begins when Type I closes.

ScopeSecurity, Confidentiality, Availability

Processing Integrity is added at Type II. Privacy is out of scope, because we handle no personal information.

Ahead of the formal report, we share a Trust Pack: our controls mapped to the Trust Services Criteria, our subprocessor list, and a signable data processing agreement. Enterprise security teams use it to clear us in review. Ask your Straata contact for it.

How your data is handled

The controls behind the posture.

Encryption everywhere

Your data is encrypted in transit (TLS 1.3) and at rest (AES-256). Keys are managed and rotated under our infrastructure providers’ own audited controls.

Access & isolation

Every client’s data is isolated at the row level. Access is role-based and least-privilege, multi-factor authentication is enforced on every system, and access is reviewed on a set cadence.

No cardholder data

We work from aggregated and tokenized data, fees, volumes, residuals, statements, and contracts. We never receive, store, or transmit full card numbers or sensitive authentication data, so we sit outside the cardholder data environment. During migrations we orchestrate the movement of tokens without raw card data ever entering our systems.

Your data is not AI training data

We do not train models on your identifiable data. Our AI runs through Anthropic’s commercial API, which is not used to train models, and it only ever sees the transaction summaries a task requires, never personal information.

A human owns every finding

The AI surfaces and reconciles the data. A named payments operator reviews it and stands behind every number before it reaches you. No unreviewed model output is ever sent to a client.

Reproducible from your source

Every finding traces back to the exact line in your own statements. Any number we give you can be regenerated and checked against the record it came from, never a black box.

No personal information

By design, we process payment economics, not people. No cardholder names, addresses, emails, or other personal data enters our platform, which is why the Privacy criterion sits outside our audit scope entirely.

Monitoring & response

Application, infrastructure, and access events are logged centrally and retained. We run a documented incident-response plan with tiered response times, and we notify affected clients of any confirmed incident.

Backups & resilience

Data is backed up continuously with point-in-time recovery across a multi-zone footprint, with documented recovery targets and restore runbooks.

Confidentiality

Every engagement runs under a mutual NDA. Your data is classified confidential, and a Data Processing Addendum is available on request.

Retention & deletion

Your data is yours. What we learn from the market is ours.

These are two different things, and we keep them separate on purpose.

Your data

Deleted at engagement end, or on request.

The files you send us and the analysis specific to your business are yours. We hold them only as long as the work requires, and we delete them when the engagement ends or whenever you ask.

Market benchmarks

Aggregated, de-identified, never traceable to you.

The benchmarks that make our work valuable are built from patterns across many clients, aggregated and stripped of anything that could identify you. Those statistics remain; your identifiable data is never part of them. That is standard for any benchmarking service, and the right to it is spelled out in our agreement.

Subprocessors

Who else touches the data, and what they answer to.

We keep the list short and the bar high. Every provider that processes client data carries its own independent attestation.

ProviderFunctionAttestation
SupabaseDatabase, authentication, storageSOC 2 Type II
VercelApplication hostingSOC 2 Type II
DigitalOceanCompute infrastructureSOC 2 Type II, ISO 27001
AnthropicAI inference, via APISOC 2 Type II

We give 30 days’ notice before any material change to this list.

Need the full Trust Pack for your security review?

The controls matrix, subprocessor list, DPA, and compliance roadmap in one document, ready for your procurement team.

Last updated July 2026. We keep this page current with our real posture, not our aspirations.