S STRAITUM Request Demo
← Back to straitum.com

Privacy Policy

Effective Date: June 8, 2026 · Last Updated: June 8, 2026

Straitum ("Straitum," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit straitum.com or use the Straitum security risk platform at app.straitum.com (collectively, the "Services"). Please read this policy carefully. If you disagree with its terms, discontinue use of the Services.

1. Information We Collect

1.1 Information You Provide Directly

We collect information you voluntarily provide when you:

  • Submit the early access or demo request form (name, work email, company, asset count, tools used, data preference)
  • Create an account on the platform (name, work email, password hash)
  • Communicate with us via email or other channels

1.2 Security Data You Import

When you use the Straitum platform, you may upload or import vulnerability scan data, asset inventories, vendor information, and related security data from third-party tools (e.g., Tenable, Qualys, CrowdStrike). This data belongs to you. We process it solely to provide the Services.

1.3 Automatically Collected Information

When you visit our websites, we may automatically collect:

  • IP address and approximate geographic location
  • Browser type, version, and operating system
  • Pages visited, time spent, and referring URLs
  • Device identifiers

We do not currently use third-party analytics tools that track users across sites.

2. How We Use Your Information

We use the information we collect to:

  • Respond to demo requests and schedule product demonstrations
  • Create and manage your platform account
  • Provide, operate, and improve the Services
  • Send transactional emails (account confirmation, password reset, demo follow-up)
  • Send product updates and early access communications (you may opt out at any time)
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

We do not sell your personal information. We do not use your security data for any purpose other than providing the Services to you.

3. Legal Basis for Processing (EEA / UK Users)

If you are located in the European Economic Area or United Kingdom, we process your personal data under the following legal bases:

  • Contract: Processing necessary to provide the Services you requested
  • Legitimate interests: Improving our Services, preventing fraud, communicating about product updates
  • Consent: Marketing emails (you may withdraw consent at any time)
  • Legal obligation: Compliance with applicable laws

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share information with:

  • Service providers: Third-party vendors who help us operate the Services (see Section 6 — Subprocessors)
  • Legal requirements: When required by law, subpoena, or legal process, or to protect the rights and safety of Straitum, our users, or the public
  • Business transfers: In connection with a merger, acquisition, or sale of all or substantially all of our assets, with notice provided to affected users

5. Data Retention

We retain personal information for as long as necessary to provide the Services and fulfill the purposes described in this policy, unless a longer retention period is required by law.

  • Lead / demo request data: Retained for 2 years or until you request deletion
  • Platform account data: Retained for the duration of your account plus 90 days after closure
  • Imported security data: Retained for the duration of your active subscription; deleted within 30 days of account closure upon request
  • Audit logs: Retained for 12 months

6. Subprocessors

We use the following third-party subprocessors to help deliver our Services. All subprocessors are bound by appropriate data protection agreements.

6.1 Current Subprocessors

Provider Purpose Location
Railway Application and database hosting United States
Resend Transactional email delivery United States
Anthropic AI-assisted CVE summarization (optional feature) United States

We will update this list when we add new subprocessors. Material changes will be communicated to platform users.

7. Security

We implement administrative, technical, and physical safeguards designed to protect your information, including:

  • Encryption in transit (TLS 1.2+) and at rest
  • Password hashing using bcrypt
  • JWT-based authentication with refresh token rotation
  • Role-based access controls within the platform
  • Audit logging of administrative actions

No method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we will promptly notify affected users of any confirmed breach as required by applicable law.

8. Cookies and Tracking

The straitum.com marketing site does not currently use tracking cookies or third-party analytics. The platform at app.straitum.com uses only essential cookies required for authentication (session tokens). We do not use advertising cookies or cross-site tracking.

If this changes, we will update this policy and provide appropriate notice and consent mechanisms.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information ("right to be forgotten")
  • Portability: Request your data in a machine-readable format
  • Objection / Restriction: Object to or request restriction of certain processing
  • Opt-out of marketing: Unsubscribe from marketing emails at any time using the link in any email, or by contacting us

To exercise any of these rights, contact us at hello@straitum.com. We will respond within 30 days.

10. Children's Privacy

The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will delete it promptly.

11. International Data Transfers

Straitum is based in the United States. If you access the Services from outside the United States, your information may be transferred to and processed in the United States, which may have different data protection laws than your country of residence. By using the Services, you consent to this transfer. For EEA/UK users, we rely on Standard Contractual Clauses where applicable.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy with a new effective date and, for platform users, by sending an in-app notification or email. Your continued use of the Services after changes take effect constitutes your acceptance of the revised policy.


Questions about this Privacy Policy? Contact us at hello@straitum.com

S STRAITUM

The unified security risk platform for mid-market enterprises.

© 2026 Straitum All rights reserved.

Product

  • Features
  • How It Works
  • Request Demo

Company

  • About
  • hello@straitum.com
  • app.straitum.com ↗
  • Privacy Policy
  • Terms of Service
  • Security

Built by security practitioners, for security practitioners.

© 2026 Straitum All rights reserved. · Privacy · Terms · Security