Security

Security at Strajist AI

We take security seriously. Here's how we protect your data.

Last updated: January 7, 2025

Our Approach to Security

Security is built into everything we do at Strajist. As a growing company, we are committed to implementing and continuously improving security practices that protect your data.

Rather than making claims we can't back up, we believe in transparency about our actual security measures. We leverage best-in-class infrastructure partners who maintain rigorous security standards, and we implement security controls appropriate for the data we handle.

Infrastructure Partner Security

Our backend infrastructure is powered by Supabase, which maintains SOC 2 Type II certification and implements comprehensive security controls. This means our database, authentication, and core infrastructure benefit from enterprise-grade security practices.

How We Protect Your Data

A detailed look at the security measures we have in place.

Data Encryption

All data is encrypted both in transit and at rest. We use HTTPS with TLS 1.2+ for all connections, and our database provider implements AES-256 encryption for stored data.

Secure Cloud Infrastructure

Our platform runs on enterprise-grade cloud infrastructure with automatic SSL/TLS certificates, content delivery network (CDN), and built-in DDoS protection.

Authentication Security

User authentication is handled by Supabase Auth, which implements secure password hashing (bcrypt), session management with secure tokens, and email verification.

Data Isolation

Row Level Security (RLS) ensures complete data isolation between customers. Each organization can only access their own data, enforced at the database level.

Automatic Backups

Daily automated backups with point-in-time recovery capability. Backups are encrypted and stored in geo-redundant storage for disaster recovery.

Incident Response

We have documented incident response procedures in place. In the event of a security incident affecting customer data, we will notify affected customers promptly.

Encryption Details

Data in Transit

  • All connections to our platform are secured via HTTPS
  • TLS 1.2 or higher is enforced for all encrypted connections
  • HTTP Strict Transport Security (HSTS) is enabled
  • Modern cipher suites only, legacy and weak ciphers are disabled

Data at Rest

  • Database encryption at rest using AES-256 (via Supabase)
  • Encrypted database connections
  • Encrypted backup storage

Authentication and Access Control

User Authentication

  • Secure password hashing using bcrypt via Supabase Auth
  • Email verification for new accounts
  • Secure session management with token-based authentication
  • Password reset via secure, time-limited links

Application-Level Security

  • Row Level Security (RLS) policies enforce data isolation at the database level
  • Each customer's data is logically separated, users cannot access other organizations' data
  • API authentication using secure tokens

Backups and Disaster Recovery

  • Automatic daily backups via Supabase
  • Point-in-time recovery capability for database restoration
  • Backups stored in geo-redundant storage
  • Documented recovery procedures
  • Regular testing of backup restoration processes

Data Handling Practices

  • Data minimization: We collect only the data necessary to provide our services
  • Clear retention policies: Data is retained only as long as needed for its purpose
  • Right to deletion: Customers can request deletion of their data at any time
  • Data export: Customers can export their data in standard machine-readable formats (JSON, CSV)
  • No selling of data: We do not sell customer data to third parties

Incident Response

We have incident response procedures in place to handle security events:

  • Detection: We monitor for unusual activity and potential security issues
  • Response: Documented procedures for investigating and containing incidents
  • Communication: Affected customers will be notified of security incidents that impact their data
  • Post-incident review: Analysis and improvement of security measures following any incident

What We're Working Toward

Security is an ongoing journey. We're committed to continuous improvement:

  • Regular review and enhancement of security practices
  • Staying current with security best practices and emerging threats
  • Security awareness and training for our team
  • Evaluating formal security assessments as we grow

We believe in honest communication about our security posture rather than making claims we can't substantiate.

Vulnerability Disclosure

We appreciate the work of security researchers and welcome responsible disclosure of security vulnerabilities. If you believe you've found a security issue in our platform, please report it to us.

Report a Security Issue

Email: security@strajist.ai

Please include as much detail as possible about the vulnerability, including steps to reproduce, potential impact, and any relevant screenshots or logs. We will acknowledge receipt within 48 hours and work with you to understand and address the issue.

Have Security Questions?

We're happy to answer questions about our security practices. For security inquiries, contact us at security@strajist.ai. For general privacy questions, see our Privacy Policy.