Security and trust at Strai8
Strai8 scores how enterprises govern AI — so the platform is run to the standard it scores. Where your data lives, who can touch it, and what happens when something breaks are written commitments, and the documents behind them are available on request.
Where your data lives, and the law it answers to
Data sovereignty is a location and a legal regime, not a slogan. Customer data is stored on secure cloud infrastructure located primarily in India, held to DPDPA 2023 and the GDPR — and it crosses that boundary only with safeguards attached.
- Your personal data is never sold to any third party.
- Assessment data is never used to train our AI models without your explicit consent.
You retain ownership of everything you upload. Strai8 takes only the limited licence needed to process it for the service — and on termination, personal data is deleted or returned under the Data Processing Agreement.
| Category | Providers | Purpose |
|---|---|---|
| Cloud infrastructure | AWS, Azure | Hosting and compute |
| Payments | Razorpay, Stripe | Payment processing — payment data only |
| Communications | SendGrid | Transactional emails |
| Analytics | Google Analytics | Anonymized usage data |
| AI model providers | OpenAI, Anthropic | AI-assisted assessments, subject to data processing agreements |
Sub-processor changes are notified at least 30 days in advance. How each category handles personal data is set out in the Privacy Policy.
Defense in layers, from the edge to the audit log
The Information Security Policy behind the platform is aligned to ISO/IEC 27001:2022 and available on request. These are its load-bearing controls.
01Encryption
- AES-256 for all data at rest; TLS 1.2 or higher for all data in transit
- Trust Score reports protected with end-to-end encryption
- Database backups encrypted before transfer to backup storage
- Keys managed in a dedicated Key Management Service
02Access control
- Role-based access control across all platform components
- Least privilege enforced; access rights reviewed quarterly and revoked immediately on exit
- MFA mandatory for every account — TOTP apps or hardware security keys
- Dual authorization required for critical privileged operations
03Network
- Web Application Firewall in front of all public endpoints
- DDoS protection at the network edge
- Internal systems segmented in a Virtual Private Cloud architecture
- All inbound traffic filtered; outbound traffic monitored
04Monitoring
- Every access to customer data logged with immutable audit trails
- SIEM in place; anomalous access patterns trigger automated alerts
- Logs retained for a minimum of 12 months
- Weekly vulnerability scans; annual independent penetration test
Built to stay up, rehearsed to come back
Availability lives in the Service Level Agreement, not in adjectives: a monthly uptime target, defined recovery objectives, and a restore process that is tested every quarter rather than assumed.
- Backups
- Daily, encrypted, stored offsite
- Restore tests
- Backup restoration tested quarterly
- Maintenance window
- Sundays 2:00–4:00 AM IST, communicated in advance
- During incidents
- Status updates published at status.strai8.ai
Four severities, each with a committed clock
Every incident is classified on detection and runs a documented response with named owners and an escalation path — including AI-specific failures, where the affected model is suspended from production before anything else.
- Customer notification
- Within 24 hours if customer data is affected
- Regulatory notification
- Within 72 hours where required — including CERT-In
- Data Protection Officer
- Escalation within 4 hours of a personal-data breach
- Post-incident review
- Formal review of every P1 and P2 within 5 business days
The framework we score you on, applied to ourselves
Strai8's own models run under the same AI Governance Policy the platform assesses customers against — eight pillars, oversight thresholds with real numbers, model cards, and uses the policy refuses outright.
- Human oversight
- AI decisions below 70% confidence escalate to a human reviewer
- Overrides
- Human override is available on every AI-assisted decision, logged and reviewed monthly
- Model cards
- Maintained for every significant model — purpose, training data, bias testing, known limits
- Bias testing
- At development, pre-deployment, and quarterly in production
- Prohibited uses
- No social scoring, mass surveillance, real-time biometric identification, subliminal manipulation, or autonomous weapons
Aligned to NIST AI RMF · ISO/IEC 23894 · EU AI Act risk tiers · IndiaAI governance principles
What we align to, and where each stands
The security program is built on these frameworks. Each card states exactly where it stands today — no seals, no claims ahead of the audit — and the underlying policies are available on request.
Security controls follow the 27001:2022 control set; the Information Security Policy is available on request.
The security program's stated attestation target.
Detection, response and recovery practices mapped to the NIST CSF functions.
Baseline hardening and operational controls follow CIS v8.
Consent, retention, grievance redressal and breach notification built to the Act's obligations.
Lawful bases, data subject rights, and SCC-based transfers for EU personal data.
This page is about how Strai8 secures itself. For how the platform maps your AI estate to the frameworks you answer to, see the Compliance module.
Security research is welcome here
The Vulnerability Disclosure Policy commits us to answer researchers, to patch on a published clock, and to take no legal action against research done in good faith.
In scope: strai8.ai and its subdomains — the web application and the public APIs. Out of scope: physical attacks, social engineering against employees, denial of service, and third-party services outside our control.
- Acknowledgement
- Within 48 hours of your report
- Status updates
- Every 10 business days until resolved
- Disclosure window
- 90 days, coordinated with you
- Safe harbor
- No legal action against good-faith research
The policies behind this page, in writing
Every claim above is a sentence in a governed document with a reference code and a review cycle. Due-diligence and procurement teams can request the full set.
Available on request — legal@strai8.ai
What due‑diligence teams ask
The answers security questionnaires come for — each one backed by the documents above.
Bring your due-diligence questions
Walk through the security program, the DPA and the data boundary with the team that runs them — and see the platform on your own estate.