Encryption everywhere
Your data is encrypted in transit (TLS 1.3) and at rest (AES-256). Keys are managed and rotated under our infrastructure providers’ own audited controls.
Trust & Security
Straata works from your transaction exports, residual reports, merchant statements, and processor contracts. That data is confidential, and it is handled like it. Below is exactly what we do today, what we are certified against, and what is on the roadmap. We will only ever tell you where we actually are.
Certification
SOC 2 is an independent audit of a service organization’s controls, and it applies to a services firm like ours just as it does to software. We are pursuing it on a phased plan.
An independent auditor’s attestation that our controls are designed correctly, at a point in time.
The report that proves those controls operate effectively over a monitored window. Its observation period begins when Type I closes.
Processing Integrity is added at Type II. Privacy is out of scope, because we handle no personal information.
Ahead of the formal report, we share a Trust Pack: our controls mapped to the Trust Services Criteria, our subprocessor list, and a signable data processing agreement. Enterprise security teams use it to clear us in review. Ask your Straata contact for it.
How your data is handled
Your data is encrypted in transit (TLS 1.3) and at rest (AES-256). Keys are managed and rotated under our infrastructure providers’ own audited controls.
Every client’s data is isolated at the row level. Access is role-based and least-privilege, multi-factor authentication is enforced on every system, and access is reviewed on a set cadence.
We work from aggregated and tokenized data, fees, volumes, residuals, statements, and contracts. We never receive, store, or transmit full card numbers or sensitive authentication data, so we sit outside the cardholder data environment. During migrations we orchestrate the movement of tokens without raw card data ever entering our systems.
We do not train models on your identifiable data. Our AI runs through Anthropic’s commercial API, which is not used to train models, and it only ever sees the transaction summaries a task requires, never personal information.
The AI surfaces and reconciles the data. A named payments operator reviews it and stands behind every number before it reaches you. No unreviewed model output is ever sent to a client.
Every finding traces back to the exact line in your own statements. Any number we give you can be regenerated and checked against the record it came from, never a black box.
By design, we process payment economics, not people. No cardholder names, addresses, emails, or other personal data enters our platform, which is why the Privacy criterion sits outside our audit scope entirely.
Application, infrastructure, and access events are logged centrally and retained. We run a documented incident-response plan with tiered response times, and we notify affected clients of any confirmed incident.
Data is backed up continuously with point-in-time recovery across a multi-zone footprint, with documented recovery targets and restore runbooks.
Every engagement runs under a mutual NDA. Your data is classified confidential, and a Data Processing Addendum is available on request.
Retention & deletion
These are two different things, and we keep them separate on purpose.
The files you send us and the analysis specific to your business are yours. We hold them only as long as the work requires, and we delete them when the engagement ends or whenever you ask.
The benchmarks that make our work valuable are built from patterns across many clients, aggregated and stripped of anything that could identify you. Those statistics remain; your identifiable data is never part of them. That is standard for any benchmarking service, and the right to it is spelled out in our agreement.
Subprocessors
We keep the list short and the bar high. Every provider that processes client data carries its own independent attestation.
| Provider | Function | Attestation |
|---|---|---|
| Supabase | Database, authentication, storage | SOC 2 Type II |
| Vercel | Application hosting | SOC 2 Type II |
| DigitalOcean | Compute infrastructure | SOC 2 Type II, ISO 27001 |
| Anthropic | AI inference, via API | SOC 2 Type II |
We give 30 days’ notice before any material change to this list.
The controls matrix, subprocessor list, DPA, and compliance roadmap in one document, ready for your procurement team.
Last updated July 2026. We keep this page current with our real posture, not our aspirations.