Legal
Security
Last updated: 10 May 2026
We treat security as a product feature. This page sets out what we do to protect your account, your data, and the integrity of the Platform.
StratAi Ltd is registered with the UK Information Commissioner's Office (ICO) as a data controller under UK GDPR. Registration reference ZC143495.
1. Authentication
- Email and password sign-in via Supabase Auth — passwords are hashed with bcrypt and never stored in plain text
- StrategyAI never sees your password; authentication is handled entirely by Supabase Auth
- Sessions are issued and refreshed automatically by Supabase Auth
- Every sign-in is logged with IP address, device and timestamp
2. Data Storage and Encryption
- Database: Supabase Postgres, hosted in the EU (Stockholm)
- Encryption in transit: TLS 1.3 across all connections
- Encryption at rest: AES-256 (managed by Supabase)
- Row-Level Security (RLS): enforced on every table — partners can only ever read or write their own data
- Database backups: daily, retained 30 days, encrypted
3. Payment Security
- All payments processed by Stripe (PCI-DSS Level 1 certified)
- We never see, store, or transmit card numbers, CVCs or bank details
- Stripe webhooks are signature-verified before being acted on
4. Confidentiality
- All beta partners sign a Beta Confidentiality & Feedback Agreement (NDA v1.0) on first login
- Acceptance is logged with timestamp, IP and user agent in a tamper-evident audit table
- Internal access to user data is restricted to the founder, logged, and audited
5. Infrastructure
| Layer | Provider | Region |
|---|---|---|
| Application | Managed application hosting | EU |
| Database & Auth | Cloud database & authentication | EU (Stockholm) |
| Transactional email provider | EU | |
| Payments | Stripe | EU & US |
| AI scoring (no PII) | Large language model (LLM) provider | US |
| WhatsApp alerts (opt-in) | Messaging & alerts provider | EU & US |
All cross-border transfers are covered by UK International Data Transfer Agreements or EU Standard Contractual Clauses.
A full list of our named sub-processors is available on request.
6. Application Security
- Daily automated dependency scanning
- Secret management: all keys stored in GitHub Secrets / Supabase Vault — never in source code
- API rate limiting to prevent abuse
- Input validation on every form and API endpoint
- Audit logs on signal feedback, NDA acceptance, subscription events and admin actions
7. Data Minimisation
We collect only what we need to deliver the Platform — name, work email, firm, role, geography and signal preferences. We do not buy, sell, or trade personal data, and we do not use customer data to train any AI model.
Signals are scored using public-source data (Companies House, SEC EDGAR, NewsAPI, Adzuna, RSS feeds). No personal data about end users is ever sent to the Anthropic API.
8. Responsible Disclosure
If you identify a security vulnerability, please email admin@strategyai.co.uk with details. We aim to acknowledge within 48 hours and resolve critical issues within 7 days. We do not take legal action against researchers acting in good faith.
9. Incident Response
In the event of a security incident affecting personal data, we will:
- Investigate and contain the issue immediately
- Notify the ICO within 72 hours if required under UK GDPR
- Notify affected users without undue delay
- Publish a post-incident summary with root cause and remediation
10. Roadmap
Items planned and currently in delivery:
- SOC 2 Type I — targeted Q4 2026
- SSO (SAML / OIDC) — Enterprise plan, Q3 2026
- Audit log export — Enterprise plan, Q3 2026
- Penetration testing — annual, first scheduled pre-public launch
11. Contact
Security and incident reporting: admin@strategyai.co.uk