← Back to straitum.com
Security & Trust

Built secure from day one.

Straitum stores some of the most sensitive operational data your organization has — vulnerability scans, asset inventories, and security posture data. Here is exactly how we protect it.

Download Security Whitepaper Request DPA

Six things you should know.

The headline security properties of the Straitum platform.

🔒
Isolated Database Per Customer
Each customer is provisioned on a dedicated, isolated database — no shared tables, no tenant_id filtering. Isolation by infrastructure, not application logic.
🔐
End-to-End Encryption
TLS 1.2+ in transit. Data encrypted at rest at the storage level. bcrypt (cost 12) for passwords. TOTP secrets encrypted at rest.
🛡
Zero AI Training
Your security data is never used to train AI models. Our AI enrichment uses only public CVE IDs — never your asset or environment data.
72-Hour Breach Notice
If a confirmed breach affects your data, we notify you within 72 hours. Formalized in our DPA.
🔑
MFA Built In
TOTP-based multi-factor authentication with per-user enforcement, admin controls, and server-enforced step-up authentication on destructive actions.
📋
Audit Logging
Security-relevant actions and administrative access logged with user, timestamp, and action. Available to customers on request.

Your data is yours. Completely.

Most SaaS platforms store all customers in one shared database and rely on filtering to keep data separate. A single bug can expose one customer's data to another.

Straitum takes a different approach: each customer is provisioned on a dedicated, isolated database. There is no shared database and no tenant_id filtering — isolation by infrastructure rather than application logic.

✗  Shared database model
  • All customers in one database
  • tenant_id filtering required
  • Bug can expose cross-tenant data
  • Common in cost-optimized SaaS
✓  Straitum model
  • Dedicated database per customer
  • No shared tables
  • Isolation by infrastructure, not application logic
  • Standard for security platforms

What we will never do.

These are not just policies. They are architectural constraints.

Sell your data
We do not sell, rent, or trade customer data. Ever.
Train AI on your data
Your vulnerability scans, asset inventories, and security posture data are never used to train AI or machine learning models. Our AI features use only publicly available CVE data from NIST.
Share without consent
Customer data is shared only with the subprocessors listed below — and only what is necessary to deliver the service.

Subprocessors

Straitum uses the following third-party services to deliver the platform. No other services have access to customer data.

Provider Purpose Location
Railway Application hosting and database infrastructure United States
Cloudflare DNS, content delivery, TLS termination, static site hosting United States (global edge network)
Resend Transactional email delivery United States
Browserless PDF report rendering (processes report content during generation) United States
Anthropic AI enrichment of public CVE data only — no customer environment data transmitted United States

Security Controls

A summary of our implemented security controls. Full details are available in our Security Whitepaper.

✓ Encryption in transit (TLS 1.2+) ✓ Encryption at rest (storage level) ✓ bcrypt password hashing (cost 12) ✓ JWT authentication ✓ Role-based access control (RBAC) ✓ Multi-factor authentication (TOTP) ✓ Admin route protection ✓ Rate limiting on authentication and public endpoints ✓ Security headers (Helmet.js) ✓ CORS allowlist policy ✓ Audit logging of security-relevant actions ✓ Database connections encrypted in transit (TLS) ✓ Dedicated database per customer ✓ Decoupled least-privilege DB roles for public endpoints, fail-closed in production ✓ Server-enforced MFA step-up on destructive actions ✓ Data deletion on termination ✓ 72-hour breach notification ✓ Responsible disclosure process ✓ Fail-closed posture on public endpoints ✓ Tokenized, expiring links for external data sharing ✓ Signing-secret validation enforced at startup ⏳ Trusted device management (rolling out) ⏳ Penetration testing ⏳ SOC 2 Type I (Q1 2027) ⏳ SSO / SAML integration (Q3 2026) ⏳ Per-tenant encryption keys

Compliance & Certifications

Where we stand on the frameworks your security team cares about.

GDPR
✓ Controls in place

Data processing agreement available. Customer data is stored in the United States.

Request DPA
HIPAA
✓ BAA available

Business Associate Agreement available for healthcare customers. Contact us before uploading PHI.

Request BAA
SOC 2 Type I
⏳ Target Q1 2027

Controls implementation in progress. This page documents our current security posture while the formal audit process begins.

PCI DSS
— Not applicable

Straitum does not process cardholder data. We help you track your own PCI scope assets and manage associated risk.


Questions or concerns?

We respond to every security inquiry. Usually same day.

Security questions
hello@straitum.com
General security and privacy questions.
Send email
Request DPA or BAA
hello@straitum.com
Subject: DPA Request
Request document
Report a vulnerability
hello@straitum.com
Responsible disclosure welcome.
Subject: Security Disclosure
Report vulnerability

We commit to acknowledging security reports within 48 hours. We do not pursue legal action against good-faith researchers.