Legal

Privacy Policy

This policy describes what Strivio collects, why, and who else processes it. It reflects how the product works today rather than how we intend it to work. Where a process is still manual or incomplete, we say so.

Last updated: 5 August 2026

Who we are

Strivio is an AI security and governance platform operated by Ecclesia Strivio Technologies. This policy covers www.strivioai.ai and the Strivio platform.

For any question about this policy or your information, contact security@strivioai.ai.

Information we collect

Account information
Your name, email address, organization name, and a hashed password. Passwords are stored as bcrypt hashes and are never recoverable in plain text.
Demo and contact requests
Name, email, company, job title, company size, and anything you write in the message field.
Agent activity
When your AI agents send events to Strivio, we store the prompt or tool-call content submitted for evaluation, along with the agent identifier, session identifier, event type, timestamp, and the resulting decision.
Request metadata
IP address, user agent, SDK version, and environment, recorded alongside events.
Website chatbot conversations
If you use the assistant on this website, we store the messages exchanged, the page you were on, your IP address, and your user agent.
Payment information
Handled by Stripe. We store a Stripe customer identifier, a subscription identifier, and your plan. We never receive or store card numbers.

We do not use analytics or advertising trackers. There is no Google Analytics, no advertising pixel, and no third-party behavioral tracking on this website.

How we use information

We do not sell your information, and we do not use customer content to train any model.

AI and chatbot interactions

Strivio's detection engine is pattern and heuristic based. It does not send your agent traffic to any external model in order to evaluate it. Two features do involve third-party AI providers, and both are described here.

Website chatbot

Messages you send to the assistant on this website are transmitted to Anthropic's API to generate a response. The conversation, the page you were on, your IP address, and your user agent are stored in our database. These records are currently retained indefinitely and are visible to platform administrators. Do not enter confidential information into the website chatbot.

Model proxy (optional)

If you route agent traffic through Strivio's proxy endpoints, requests are inspected and then forwarded to OpenAI or Anthropic. Prompt content is scanned in memory and is not stored by the proxy; only metadata about the decision is recorded. You supply your own provider API key with each request, and we recommend always doing so, so that your traffic is governed by your own agreement with that provider.

Payments

Payments are processed by Stripe. Card details are entered on Stripe's infrastructure and are never transmitted to or stored by Strivio. We receive and store a customer identifier, a subscription identifier, your plan, and payment status. Stripe's handling of your payment information is governed by their own privacy policy.

Cookies and similar technologies

We use cookies only to keep you signed in. We do not use cookies for analytics, advertising, or cross-site tracking.

strivio_token
Your authentication session. Set when you sign in or create an account, and expires after 8 hours.
strivio_plan
Your organization's plan, used to route you to the correct part of the application after sign-in. Expires after 8 hours.

Both are strictly necessary for the service to function. Blocking them will prevent you from signing in. We also store your session token in browser local storage for the same purpose.

Service providers

These providers process data on our behalf:

MongoDB Atlas
Primary database. Stores all customer data. United States.
Railway
Application hosting and cache. United States.
Vercel
Website hosting. United States.
Anthropic
Generates website chatbot responses. Receives visitor conversation content.
OpenAI and Anthropic
Receive prompt content only if you use the optional model proxy.
Stripe
Payment processing. Receives billing information.
Resend
Transactional email. Receives recipient addresses and message content.
Sentry
Server-side error monitoring. Receives diagnostic data and stack traces. Sentry is not enabled in the browser, so it does not observe your browsing on this website.

We will notify customers before adding a provider that processes customer content.

How long we keep information

Plan tiers specify decision log retention periods of 90 days, 365 days, or unlimited. Automated retention enforcement is implemented but not yet enabled in production. In practice, records persist until they are removed manually.

Website chatbot conversations, including IP addresses, are currently retained indefinitely. We intend to expire them automatically and will update this page when that is in place.

Account records are retained while your organization is active. Cancelling a subscription suspends an organization; it does not delete stored data. See our security page for the technical detail.

How we protect information

In transit
TLS 1.3 and TLS 1.2 with forward secrecy.
At rest
Provider-managed encryption on our database host. Customer-managed encryption keys are not available on our current tier.
Passwords and API keys
Stored as bcrypt hashes. Never recoverable in plain text.
Access control
Role-based, with every query scoped to your organization. Administrative access that crosses an organization boundary is logged.
Audit records
Append-only and hash-chained, so modification is detectable.

Our full security posture, including what we have not yet done, is documented on our security page. We hold no security certifications and do not claim any.

Where information is stored

All Strivio infrastructure is located in the United States, in the US East region. Customer-selectable regions are not available. Information sent to the AI providers, payment processor, email provider, and error monitoring service described above is processed on their infrastructure under their own terms.

Your choices

Contact us at security@strivioai.ai to ask what information we hold about you, to correct it, or to request deletion. We handle these requests directly.

We are being straightforward about the current state: we do not yet have a self-service deletion process or an automated export. Requests are handled manually, and we are formalizing the process as the platform matures. If you have specific regulatory requirements, raise them with us before you buy so we can tell you honestly whether we can meet them today.

Children

Strivio is a business product intended for organizations. It is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a child has provided us with information, contact us and we will remove it.

Changes to this policy

We will update this page when our practices change and revise the date at the top. For changes that materially affect how we handle customer data, we will notify affected customers directly rather than relying on you to notice an edit.

Contact

Privacy and security questions: security@strivioai.ai
Everything else: sales@strivioai.ai
Ecclesia Strivio Technologies