We sell security software, so you should hold us to the standard we ask you to meet. This page documents how Strivio is built, where your data lives, what leaves our infrastructure, and what we have not done yet.
We would rather you learn these things here than discover them during procurement.
What this means for you. If your process requires a completed SOC 2 report, we cannot meet that today. If it allows compensating evidence — architecture review, questionnaire responses, contractual commitments — we can support that thoroughly.
No customer data is processed or stored outside the United States, with the exception of the third-party AI provider calls documented below.
When your agents send events to Strivio, we store the prompt or tool-call content in an audit record. This is deliberate: a decision log that does not contain what was evaluated cannot explain why a decision was made.
If storing raw content is not acceptable for your data, tell us during evaluation. We would rather scope a deployment that meets your requirements than have you discover a mismatch after signing.
Plan tiers list audit retention periods of 90 days, 365 days, or unlimited. Automated retention enforcement is not yet implemented. Records persist until removed manually. We are building scheduled purge and will update this page when it is in place.
We support customer requests to delete account data and handle them directly. Our documented deletion process, including timelines and verification, is being formalized as the platform matures. Contact us to discuss deletion requirements before you buy.
Audit records are append-only. Update operations are blocked at the data model layer, not merely by convention.
Each record carries a SHA-256 hash computed over its immutable fields plus the hash of the preceding record for that tenant, forming a per-tenant hash chain. Modifying or removing a record breaks the chain and is detectable on verification.
Where a hash cannot be computed at write time, the record is marked with a sentinel value rather than written silently unhashed, so gaps remain visible during verification.
Strivio's detection engine is pattern and heuristic based. It does not send customer data to any external model. Two features do involve third-party AI providers, and both are described here.
Conversations with the assistant on this website are sent to Anthropic's API to generate responses. Conversation content, the page visited, IP address, and user agent are stored in our database. These records are currently retained indefinitely and are visible to platform administrators. This is a marketing feature and is unrelated to the security platform.
If you route agent traffic through Strivio's proxy endpoints, requests are inspected and then forwarded to OpenAI or Anthropic. Prompt content is scanned in memory and is not persisted by the proxy; only metadata is recorded.
You supply your own provider API key with each request. If no key is supplied, the request is forwarded using Strivio's provider credentials. We recommend always supplying your own key so your traffic is governed by your own provider agreement.
If the firewall scan fails for any reason, the request is blocked rather than forwarded. The proxy fails closed.
Neither provider is used to train models on your data under their standard business terms. Review their published terms for the account under which requests are made.
We will notify customers before adding a subprocessor that processes customer content.
Strivio is currently operated by its founder, who is the only person with access to production systems. No contractors, offshore teams, or third-party support vendors have access to customer data.
What we do not have yet. We cannot provide customer-visible support-access reports, and we have no separation of duties, because there is one operator. These change as the team grows, and we will update this page when they do.
For enterprise requirements. If you need restricted vendor access, access notification, or specific contractual controls, raise it during evaluation. We can commit to these contractually rather than discover a mismatch later.
Our production database runs on a shared MongoDB Atlas tier that does not include automated backups. We take manual snapshots and store them separately from production.
Migrating to a dedicated cluster with continuous backups and point-in-time recovery is our next planned infrastructure investment. We will update this page when it is complete.
If your requirements include a specific recovery time or recovery point objective, tell us before you buy. We would rather have that conversation upfront.
We maintain an incident response process for investigating suspected security events. If a confirmed incident materially affects customer data, affected customers will be notified without unreasonable delay after verification and assessment.
We have not adopted a specific regulatory notification window. If your agreement requires one, raise it during evaluation and we will address it contractually.
If you have found a security issue in Strivio, we want to hear about it. Email security@strivioai.ai with reproduction steps, affected endpoints, and supporting evidence.
We acknowledge receipt and investigate reported issues. We will not pursue legal action against researchers who report in good faith, avoid privacy violations and service disruption, and give us reasonable time to remediate.
We do not currently operate a paid bug bounty. We credit researchers publicly with their permission.
Send questionnaires to security@strivioai.ai. We respond to vendor security reviews and will tell you plainly when we cannot meet a requirement.
For commercial questions, contact sales@strivioai.ai or book a demo.