We sell security software, so you should hold us to the standard we ask you to meet. This page documents how Strivio is built, where your data lives, what leaves our infrastructure, and what we have not done yet.
We would rather you learn these things here than discover them during procurement.
What this means for you. If your process requires a completed SOC 2 report, we cannot meet that today. If it allows compensating evidence — architecture review, questionnaire responses, contractual commitments — we can support that thoroughly.
No customer data is processed or stored outside the United States, with the exception of the third-party AI provider calls documented below.
When your agents send events to Strivio, we store the prompt or tool-call content in an audit record. This is deliberate: a decision log that does not contain what was evaluated cannot explain why a decision was made.
If storing raw content is not acceptable for your data, tell us during evaluation. We would rather scope a deployment that meets your requirements than have you discover a mismatch after signing.
Strivio retains customer records according to the retention period configured for the organization. Plan tiers set a default of 90 days, 365 days, or unlimited, and a negotiated contractual period overrides that default.
When records pass their retention period, Strivio removes the customer content they contain. That means prompt text, tool arguments, detected sensitive values, IP addresses, and free-text notes. The record of what happened survives: which agent acted, when, what was decided, and under which policy. The record survives. Its content does not.
This is deliberate. Deleting audit records outright would break the cryptographic chain that makes the remaining history verifiable. Redacting content leaves that chain intact, so integrity can still be proven for every record we retain.
What is not yet automated. Records themselves are never deleted by this mechanism, only their content. There is no self-service organization deletion, and deletion requests are handled manually. Legal holds are enforced by the system but are imposed and released manually rather than through an interface.
Legal holds override automated retention. An active hold blocks removal for an organization, or for named collections within it, until the hold is released. A hold in an inconsistent state blocks retention rather than permitting it.
The retention mechanism is implemented and tested but is not yet enabled in production. It runs in preview mode first, producing a report of what would be removed, which we review before enabling removal.
Last reviewed 18 August 2026. Next review 31 October 2026. If this notice is still here after that date, ask us why.
Audit records are append-only. Update operations are blocked at the data model layer, not merely by convention.
Each record carries a SHA-256 hash computed over its immutable fields plus the hash of the preceding record for that tenant, forming a per-tenant hash chain. Modifying or removing a record breaks the chain and is detectable on verification.
Where a hash cannot be computed at write time, the record is marked with a sentinel value rather than written silently unhashed, so gaps remain visible during verification.
Strivio's detection engine is pattern and heuristic based. It does not send customer data to any external model. Two features do involve third-party AI providers, and both are described here.
Conversations with the assistant on this website are sent to Anthropic's API to generate responses. Conversation content, the page visited, IP address, and user agent are stored in our database. These records are currently retained indefinitely and are visible to platform administrators. This is a marketing feature and is unrelated to the security platform.
If you route agent traffic through Strivio's proxy endpoints, requests are inspected and then forwarded to OpenAI or Anthropic. Prompt content is scanned in memory and is not persisted by the proxy; only metadata is recorded.
You supply your own provider API key with each request. If no key is supplied, the request is forwarded using Strivio's provider credentials. We recommend always supplying your own key so your traffic is governed by your own provider agreement.
If the firewall scan fails for any reason, the request is blocked rather than forwarded. The proxy fails closed.
Neither provider is used to train models on your data under their standard business terms. Review their published terms for the account under which requests are made.
We will notify customers before adding a subprocessor that processes customer content.
Strivio is currently operated by its founder, who is the only person with access to production systems. No contractors, offshore teams, or third-party support vendors have access to customer data.
What we do not have yet. We cannot provide customer-visible support-access reports, and we have no separation of duties, because there is one operator. These change as the team grows, and we will update this page when they do.
For enterprise requirements. If you need restricted vendor access, access notification, or specific contractual controls, raise it during evaluation. We can commit to these contractually rather than discover a mismatch later.
Our production database runs on a shared MongoDB Atlas tier that does not include automated backups. We take manual snapshots and store them separately from production.
Migrating to a dedicated cluster with continuous backups and point-in-time recovery is our next planned infrastructure investment. We will update this page when it is complete.
If your requirements include a specific recovery time or recovery point objective, tell us before you buy. We would rather have that conversation upfront.
We maintain an incident response process for investigating suspected security events. If a confirmed incident materially affects customer data, affected customers will be notified without unreasonable delay after verification and assessment.
We have not adopted a specific regulatory notification window. If your agreement requires one, raise it during evaluation and we will address it contractually.
If you have found a security issue in Strivio, we want to hear about it. Email security@strivioai.ai with reproduction steps, affected endpoints, and supporting evidence.
We acknowledge receipt and investigate reported issues. We will not pursue legal action against researchers who report in good faith, avoid privacy violations and service disruption, and give us reasonable time to remediate.
We do not currently operate a paid bug bounty. We credit researchers publicly with their permission.
Send questionnaires to security@strivioai.ai. We respond to vendor security reviews and will tell you plainly when we cannot meet a requirement.
For commercial questions, contact sales@strivioai.ai or book a demo.