Skip to content
STRAI8Security & Trust

Security and trust at Strai8

Strai8 scores how enterprises govern AI — so the platform is run to the standard it scores. Where your data lives, who can touch it, and what happens when something breaks are written commitments, and the documents behind them are available on request.

AES-256
encryption at rest
TLS 1.2+
encryption in transit
MFA
mandatory on every account
99.9%
monthly uptime target
India
primary data residency
DPDPA + GDPR
data protection alignment
01Data sovereignty

Where your data lives, and the law it answers to

Data sovereignty is a location and a legal regime, not a slogan. Customer data is stored on secure cloud infrastructure located primarily in India, held to DPDPA 2023 and the GDPR — and it crosses that boundary only with safeguards attached.

Stays in India
Primary storage on secure cloud infrastructure located in India
Backup facilities complying with applicable data-localization requirements
Assessment data, Trust Scores and reports encrypted at rest under AES-256
Leaves only with safeguards
Cross-border transfers only under Standard Contractual Clauses or adequacy decisions
Sub-processors bound by data processing agreements
Enterprise customers notified at least 30 days before any sub-processor change
Never
  • Your personal data is never sold to any third party.
  • Assessment data is never used to train our AI models without your explicit consent.

You retain ownership of everything you upload. Strai8 takes only the limited licence needed to process it for the service — and on termination, personal data is deleted or returned under the Data Processing Agreement.

Sub-processors
CategoryProvidersPurpose
Cloud infrastructureAWS, AzureHosting and compute
PaymentsRazorpay, StripePayment processing — payment data only
CommunicationsSendGridTransactional emails
AnalyticsGoogle AnalyticsAnonymized usage data
AI model providersOpenAI, AnthropicAI-assisted assessments, subject to data processing agreements

Sub-processor changes are notified at least 30 days in advance. How each category handles personal data is set out in the Privacy Policy.

02Platform security

Defense in layers, from the edge to the audit log

The Information Security Policy behind the platform is aligned to ISO/IEC 27001:2022 and available on request. These are its load-bearing controls.

01Encryption

  • AES-256 for all data at rest; TLS 1.2 or higher for all data in transit
  • Trust Score reports protected with end-to-end encryption
  • Database backups encrypted before transfer to backup storage
  • Keys managed in a dedicated Key Management Service

02Access control

  • Role-based access control across all platform components
  • Least privilege enforced; access rights reviewed quarterly and revoked immediately on exit
  • MFA mandatory for every account — TOTP apps or hardware security keys
  • Dual authorization required for critical privileged operations

03Network

  • Web Application Firewall in front of all public endpoints
  • DDoS protection at the network edge
  • Internal systems segmented in a Virtual Private Cloud architecture
  • All inbound traffic filtered; outbound traffic monitored

04Monitoring

  • Every access to customer data logged with immutable audit trails
  • SIEM in place; anomalous access patterns trigger automated alerts
  • Logs retained for a minimum of 12 months
  • Weekly vulnerability scans; annual independent penetration test
03Reliability

Built to stay up, rehearsed to come back

Availability lives in the Service Level Agreement, not in adjectives: a monthly uptime target, defined recovery objectives, and a restore process that is tested every quarter rather than assumed.

99.9%
monthly uptime target
4 h
recovery point objective
8 h
recovery time objective
Backups
Daily, encrypted, stored offsite
Restore tests
Backup restoration tested quarterly
Maintenance window
Sundays 2:00–4:00 AM IST, communicated in advance
During incidents
Status updates published at status.strai8.ai
04Incident response

Four severities, each with a committed clock

Every incident is classified on detection and runs a documented response with named owners and an escalation path — including AI-specific failures, where the affected model is suspended from production before anything else.

P1CriticalActive data breach, ransomware, complete service outage, AI safety failureContainment ≤ 30 min
P2HighSuspected unauthorized access, significant AI model degradation, partial disruptionContainment ≤ 4 h
P3MediumFailed login anomalies, minor service degradation, policy violationsAssessment ≤ 24 h
P4LowMinor bugs, informational security alerts, process deviationsResolution ≤ 7 days
If personal data is affected
Customer notification
Within 24 hours if customer data is affected
Regulatory notification
Within 72 hours where required — including CERT-In
Data Protection Officer
Escalation within 4 hours of a personal-data breach
Post-incident review
Formal review of every P1 and P2 within 5 business days
05AI governance

The framework we score you on, applied to ourselves

Strai8's own models run under the same AI Governance Policy the platform assesses customers against — eight pillars, oversight thresholds with real numbers, model cards, and uses the policy refuses outright.

01Secure
02Transparent
03Reliable
04Accountable
05Interpretable
06Governed
07Humane
08Traceable
Human oversight
AI decisions below 70% confidence escalate to a human reviewer
Overrides
Human override is available on every AI-assisted decision, logged and reviewed monthly
Model cards
Maintained for every significant model — purpose, training data, bias testing, known limits
Bias testing
At development, pre-deployment, and quarterly in production
Prohibited uses
No social scoring, mass surveillance, real-time biometric identification, subliminal manipulation, or autonomous weapons

Aligned to NIST AI RMF · ISO/IEC 23894 · EU AI Act risk tiers · IndiaAI governance principles

06Compliance

What we align to, and where each stands

The security program is built on these frameworks. Each card states exactly where it stands today — no seals, no claims ahead of the audit — and the underlying policies are available on request.

ISO/IEC 27001:2022Aligned

Security controls follow the 27001:2022 control set; the Information Security Policy is available on request.

SOC 2 Type IIIn progress

The security program's stated attestation target.

NIST Cybersecurity FrameworkAligned

Detection, response and recovery practices mapped to the NIST CSF functions.

CIS Controls v8Aligned

Baseline hardening and operational controls follow CIS v8.

DPDPA 2023Technical safeguards

Consent, retention, grievance redressal and breach notification built to the Act's obligations.

GDPRAligned

Lawful bases, data subject rights, and SCC-based transfers for EU personal data.

07Responsible disclosure

Security research is welcome here

The Vulnerability Disclosure Policy commits us to answer researchers, to patch on a published clock, and to take no legal action against research done in good faith.

In scope: strai8.ai and its subdomains — the web application and the public APIs. Out of scope: physical attacks, social engineering against employees, denial of service, and third-party services outside our control.

Acknowledgement
Within 48 hours of your report
Status updates
Every 10 business days until resolved
Disclosure window
90 days, coordinated with you
Safe harbor
No legal action against good-faith research
Patch commitments by severity
Critical
Patch ≤ 24 h
High
Patch ≤ 7 days
Medium
Patch ≤ 30 days
Low
Patch ≤ 90 days
08Trust documents

The policies behind this page, in writing

Every claim above is a sentence in a governed document with a reference code and a review cycle. Due-diligence and procurement teams can request the full set.

Information Security PolicySTRAI8-SEC-001
Data Protection PolicySTRAI8-SEC-002
Incident Response PolicySTRAI8-SEC-003
Vulnerability Disclosure PolicySTRAI8-SEC-004
AI Governance PolicySTRAI8-GOV-001
Responsible AI PolicySTRAI8-GOV-002
Service Level AgreementSTRAI8-OPS-001
Data Processing AgreementSTRAI8-OPS-002

Available on request — legal@strai8.ai

09Questions

What due‑diligence teams ask

The answers security questionnaires come for — each one backed by the documents above.

Security & Trust

Bring your due-diligence questions

Walk through the security program, the DPA and the data boundary with the team that runs them — and see the platform on your own estate.