Security
String AI builds data infrastructure for enterprise and quantitative-research customers. This page describes how to report a security issue to us. Our Trust center summarizes the security, confidentiality, and availability practices that protect our services and the data entrusted to us.
Report a security issue
If you believe you have found a security vulnerability in our services, or need to report a security, confidentiality, integrity, or availability failure, email support@usestring.ai with “SECURITY” in the subject line. Use “PRIVACY” for privacy matters and “LEGAL” for legal requests.
Reports are triaged under our documented incident-response process, which covers detection, containment, eradication, recovery, communications, and post-incident review. If an incident affects customer data, we will notify affected customers in accordance with applicable law and contractual commitments.
A machine-readable version of this contact information is published at /.well-known/security.txt.
Our security program
Our security program assigns accountable owners for security and compliance, maintains documented policies, reviews risks and access, and tracks identified issues through remediation or formal risk treatment. Personnel complete security-awareness training and acknowledge the policies that apply to their work.
We have established a documented security program and are preparing for an independent SOC 2 Type I examination covering Security, Confidentiality, and Availability. No audit report has been issued, and we do not claim to be SOC 2 certified, compliant, or audited. We will update our Trust center only after an independent auditor issues a report.
For the full summary of our practices covering identity and access, encryption and secrets, network and infrastructure security, secure development, logging and monitoring, data protection, incident response, and business continuity, see the Trust center.