NewLaunching String Web Access APIRead the manifesto →

Trust center

Last updated: Aug 27, 2026

String AI builds data infrastructure for enterprise and quantitative-research customers. This page summarizes the security, confidentiality, and availability practices that protect our services and the data entrusted to us. Our published Terms of Service and Privacy Policy govern use of the services.

Compliance status

FrameworkScopeStatus
SOC 2Security, Confidentiality, AvailabilityType I examination preparation in progress; no report issued
GDPR (EU and UK)Article 27 representationEU and UK representatives appointed; certificate EV103335 issued by Euverify (verify)

We have established a documented security program and are preparing for an independent SOC 2 Type I examination. We intend to progress to Type II after the Type I milestone and an observation period. We will update this page only after an independent auditor issues a report.

Security governance

Our security program assigns accountable owners for security and compliance, maintains documented policies, reviews risks and access, and tracks identified issues through remediation or formal risk treatment. Personnel complete security-awareness training and acknowledge the policies that apply to their work.

Security practices

Identity and access. We use managed company identities, multi-factor authentication, least-privilege access, and documented joiner, mover, and leaver procedures. Access rights and privileged roles are reviewed on a recurring basis, and access is revoked when it is no longer required.

Encryption and secrets. Our API and public web endpoints enforce TLS 1.2 or higher. Data at rest is encrypted using provider-managed AES-256 or equivalent encryption. Secrets are kept in a managed secrets service and are not committed to source code or placed in logs. Full-disk encryption is required on endpoints used to access company systems.

Network and infrastructure security. We use managed cloud security controls, restricted administrative access paths, firewall rules, and centralized identity controls to protect production services. Network exposure and privileged access are reviewed as part of change management and recurring security reviews.

Secure development and change management. Source code is version-controlled. Production changes use a documented pull-request workflow, automated testing and security checks where applicable, controlled deployment steps, and post-deployment monitoring. Changes leave an auditable record from review through deployment.

Logging, monitoring, and vulnerability management. We centralize cloud audit logs and monitor security-relevant and availability events with automated alerting. Alerts are triaged under documented response procedures and reviewed for effectiveness. We scan for committed secrets and known vulnerable dependencies and prioritize remediation based on risk.

Penetration testing. Practical Assurance, an independent security firm, performed a web application penetration test and an unauthenticated external network scan of our customer-facing endpoints in July 2026 (final report July 25, 2026). All findings were remediated and retested, and the updated report was re-issued on August 3, 2026. The current report is available to customers and prospective customers under NDA.

Data protection

Data location and confidentiality. Customer data is processed and stored primarily in the United States using major cloud and software service providers. Specific location or transfer requirements are addressed in customer agreements. Personnel with access to confidential information are subject to confidentiality obligations.

Classification and retention. We classify data as Public, Internal, Sensitive, or Critical and apply handling and access controls according to sensitivity. We retain data according to contractual requirements, legal obligations, and the practices described in our Privacy Policy, then delete or de-identify it when it is no longer required.

AI agent governance

AI agents are part of our operating environment. We are formalizing a governance program that inventories agents, classifies the trust level of their inputs and the impact of their permitted actions, documents boundaries, and applies additional safeguards to agents that process externally influenced content. Detailed governance material will be made available only after its internal approval gate is complete.

Incident response

We maintain a documented incident-response process covering detection, containment, eradication, recovery, communications, and post-incident review. If an incident affects customer data, we will notify affected customers in accordance with applicable law and contractual commitments.

Business continuity

We maintain documented business-continuity and disaster-recovery procedures with recovery objectives for in-scope services and data stores. Recovery procedures and supporting evidence are being tested and matured as part of our SOC 2 audit preparation.

Third-party service providers

We maintain an internal inventory and risk-review process for third parties that support our services. Our current sub-processor list is available to customers and prospective customers on request via our sub-processors page. We update the list before engaging a new sub-processor; customers holding a Data Processing Addendum are notified of sub-processor changes per its terms.

Web data collection and acceptable use

Our services collect publicly available web data and transform it into structured datasets, analytics, and monitoring. Customer-directed requests remain subject to our acceptable-use requirements and product controls. Our Terms of Service and Privacy Policy describe the governing terms in more detail.

Request documentation

Additional security documentation is being prepared for approved release under mutual NDA. A security questionnaire and compliance summary will be available after internal review. A Data Processing Addendum is under legal review. A SOC 2 report will be available only after an independent auditor issues one.

Security contact: support@usestring.ai with “SECURITY” in the subject line. Use “PRIVACY” for privacy matters and “LEGAL” for legal requests. See also our security page for how to report a vulnerability.

© 2026 StringEU and UK GDPR Article 27 representative — appointment verified by EuverifyBuilt in New York City 🗽 🍎