Skip to main content
Enterprise Security

Security at STRAETCH

Your marketing data is protected by enterprise-grade security. We prioritize privacy, compliance, and transparency in everything we do.

GDPR Compliant
SOC 2 (via infrastructure)
ISO 27001 (via infrastructure)
EU Data Residency
Data Protection

Your Data, Protected

STRAETCH is built with privacy by design. We implement comprehensive data protection measures to ensure your marketing strategies and business data remain secure.

EU Data Residency

All primary data is stored and processed in AWS EU (Ireland). Your data never leaves the European Union for core processing.

Encryption

  • In Transit: TLS 1.3 encryption for all connections
  • At Rest: AES-256 encryption for stored data
  • Backups: Separately encrypted with dedicated keys

AI Data Anonymization

When using our AI features, personal identifiable information (PII) is stripped before transmission. Your company's sensitive data is anonymized to protect your business intelligence.

Data Minimization

We only collect and process data necessary for providing our services. No hidden tracking, no data selling, no surprises.

Infrastructure

Enterprise-Grade Infrastructure

STRAETCH runs on industry-leading cloud infrastructure with multiple layers of security.

FeatureImplementation
Cloud ProviderAWS via Supabase (SOC 2, ISO 27001 certified)
RegionEU (Ireland) - eu-west-1
DDoS ProtectionCloudflare enterprise protection
Network SecurityWAF, firewall, network segmentation
Physical Security24/7 surveillance, biometric access

Uptime

  • 99% Uptime SLA commitment
  • Real-time monitoring and alerting
  • Automatic failover and redundancy
View current status
Access Control

Secure Access Management

Control who has access to your STRAETCH workspace with granular permissions and modern authentication.

Multi-Factor Authentication (MFA)

Add an extra layer of security with TOTP-based two-factor authentication for all team members.

Session Security

  • • Automatic session expiry
  • • Secure token management
  • • Session revocation capability
  • • Activity logging

Role-Based Access Control (RBAC)

Four permission levels to match your team structure:

RoleDescription
AdminFull access including billing and security settings
EditorCreate and modify content, strategies, and campaigns
ViewerRead-only access to dashboards and reports
Content ContributorLimited access to AI content tools only
Compliance

Compliance You Can Trust

We maintain compliance with major data protection regulations and inherit certifications from our infrastructure providers.

GDPR Compliance

  • Data Processing Agreement (DPA) available
  • Data Subject Rights support (access, rectification, erasure)
  • 72-hour breach notification
  • Data portability and export
  • Privacy Impact Assessments

Inherited Certifications

Through our infrastructure partners (AWS/Supabase):

  • SOC 2 Type II
  • ISO 27001
  • ISO 27017 (Cloud Security)
  • ISO 27018 (Cloud Privacy)
  • CSA STAR
Data Protection

Protecting Your Data from Unauthorized Access

We take a principled approach to government and law enforcement data requests. Our formal policy ensures your data is protected from overreaching or unlawful demands.

Legality Review

Every request is reviewed for legal validity before any data is disclosed. We verify the requesting authority, jurisdiction, and legal basis.

Challenge Inappropriate Requests

We challenge requests that are overly broad, lack proper legal authority, or appear unlawful. We engage legal counsel and pursue formal challenges when necessary.

Data Minimization

When we must comply with a valid legal request, we disclose only the minimum data necessary—never more than legally required.

Full Documentation

We maintain comprehensive records of all requests received, our legal analysis, and our responses for accountability and transparency.

Customer Notification

We notify affected customers of data requests unless legally prohibited from doing so.

Transparency

We publish an annual transparency report summarizing the government data requests we receive.

Subprocessors

Our Data Subprocessors

We work with carefully selected third-party providers to deliver STRAETCH. All subprocessors have appropriate data protection agreements in place.

ServicePurposeData ProcessedLocation
Supabase / AWSDatabase, AuthAll application data
EU (Ireland)
OpenAIAI Content Verification & AnalyticsAnonymized prompts only
US*
AnthropicAI Content CreationAnonymized prompts only
US*
StripePaymentsBilling info
EU
ResendEmailsEmail addresses
US
Google CloudSEO AnalyticsSearch metrics
EU
DataForSEOKeywordsSearch queries
EU
FirecrawlWeb ScrapingPublic URLs
US
LovableHostingApplication code
EU

*OpenAI: No PII transmitted; data anonymized before processing

Change Notification

Customers receive 30 days' advance notice before any new subprocessor is added. You have the right to object within 14 days.

Incident Response

Rapid Incident Response

Our security team monitors for threats 24/7 and maintains documented procedures for rapid response.

SeverityResponse TimeResolution Target
P1 Critical
15 min4 hours
P2 High
1 hour24 hours
P3 Medium
4 hours72 hours
P4 Low
24 hours1 week

Breach Notification

In the unlikely event of a data breach affecting your information:

  • • Notification within 72 hours (GDPR requirement)
  • • Full incident details provided
  • • Remediation steps communicated
  • • Post-incident report available
Resources

Security Documentation

Responsible Disclosure

We welcome responsible security research. If you discover a vulnerability, please contact compliance@straetch.com. We commit to:

  • • Acknowledging receipt within 24 hours
  • • Providing updates on remediation progress
  • • Crediting researchers (with permission)

Ready to Get Started?

Join thousands of marketing teams who trust STRAETCH with their strategy.

Legal Entity: Action & Consequence AB • Product: STRAETCH • Last Updated: January 2026

We use cookies to enhance your experience.