← Back to straitum.com
Security & Trust
Built secure from day one.
Straitum stores some of the most sensitive operational data your organization has —
vulnerability scans, asset inventories, and security posture data. Here is exactly
how we protect it.
Six things you should know.
The headline security properties of the Straitum platform.
🔒
Isolated Database Per Customer
Each customer is provisioned on a dedicated, isolated database — no shared tables, no tenant_id filtering. Isolation by infrastructure, not application logic.
🔐
End-to-End Encryption
TLS 1.2+ in transit. Data encrypted at rest at the storage level. bcrypt (cost 12) for passwords. TOTP secrets encrypted at rest.
🛡
Zero AI Training
Your security data is never used to train AI models. Our AI enrichment uses only public CVE IDs — never your asset or environment data.
⚡
72-Hour Breach Notice
If a confirmed breach affects your data, we notify you within 72 hours. Formalized in our DPA.
🔑
MFA Built In
TOTP-based multi-factor authentication with per-user enforcement, admin controls, and server-enforced step-up authentication on destructive actions.
📋
Audit Logging
Security-relevant actions and administrative access logged with user, timestamp, and action. Available to customers on request.
Your data is yours. Completely.
Most SaaS platforms store all customers in one shared database and rely on filtering to keep
data separate. A single bug can expose one customer's data to another.
Straitum takes a different approach: each customer is provisioned on a dedicated, isolated database. There is no shared database and no tenant_id filtering — isolation by infrastructure rather than application logic.
✗ Shared database model
- All customers in one database
- tenant_id filtering required
- Bug can expose cross-tenant data
- Common in cost-optimized SaaS
✓ Straitum model
- Dedicated database per customer
- No shared tables
- Isolation by infrastructure, not application logic
- Standard for security platforms
What we will never do.
These are not just policies. They are architectural constraints.
✗
Sell your data
We do not sell, rent, or trade customer data. Ever.
✗
Train AI on your data
Your vulnerability scans, asset inventories, and security posture data are never used to train
AI or machine learning models. Our AI features use only publicly available CVE data from NIST.
✗
Share without consent
Customer data is shared only with the subprocessors listed below — and only what is necessary
to deliver the service.
Subprocessors
Straitum uses the following third-party services to deliver the platform. No other services
have access to customer data.
| Provider |
Purpose |
Location |
| Railway |
Application hosting and database infrastructure |
United States |
| Cloudflare |
DNS, content delivery, TLS termination, static site hosting |
United States (global edge network) |
| Resend |
Transactional email delivery |
United States |
| Browserless |
PDF report rendering (processes report content during generation) |
United States |
| Anthropic |
AI enrichment of public CVE data only — no customer environment data transmitted |
United States |
Security Controls
A summary of our implemented security controls. Full details are available in our
Security Whitepaper.
✓ Encryption in transit (TLS 1.2+)
✓ Encryption at rest (storage level)
✓ bcrypt password hashing (cost 12)
✓ JWT authentication
✓ Role-based access control (RBAC)
✓ Multi-factor authentication (TOTP)
✓ Admin route protection
✓ Rate limiting on authentication and public endpoints
✓ Security headers (Helmet.js)
✓ CORS allowlist policy
✓ Audit logging of security-relevant actions
✓ Database connections encrypted in transit (TLS)
✓ Dedicated database per customer
✓ Decoupled least-privilege DB roles for public endpoints, fail-closed in production
✓ Server-enforced MFA step-up on destructive actions
✓ Data deletion on termination
✓ 72-hour breach notification
✓ Responsible disclosure process
✓ Fail-closed posture on public endpoints
✓ Tokenized, expiring links for external data sharing
✓ Signing-secret validation enforced at startup
⏳ Trusted device management (rolling out)
⏳ Penetration testing
⏳ SOC 2 Type I (Q1 2027)
⏳ SSO / SAML integration (Q3 2026)
⏳ Per-tenant encryption keys
Compliance & Certifications
Where we stand on the frameworks your security team cares about.
GDPR
✓ Controls in place
Data processing agreement available. Customer data is stored in the United States.
Request DPA
HIPAA
✓ BAA available
Business Associate Agreement available for healthcare customers.
Contact us before uploading PHI.
Request BAA
SOC 2 Type I
⏳ Target Q1 2027
Controls implementation in progress. This page documents our current security posture
while the formal audit process begins.
PCI DSS
— Not applicable
Straitum does not process cardholder data. We help you track your own
PCI scope assets and manage associated risk.
Questions or concerns?
We respond to every security inquiry. Usually same day.
We commit to acknowledging security reports within 48 hours. We do not pursue legal action
against good-faith researchers.