NewLaunching String Web Access APIRead the manifesto →

Trust center

Last updated: Aug 4, 2026

String AI builds data infrastructure for enterprise and quantitative-research customers. This page summarizes the security, confidentiality, and availability practices that protect our services and the data entrusted to us. Our published Terms of Service and Privacy Policy govern use of the services.

Compliance status

FrameworkScopeStatus
SOC 2Security, Confidentiality, AvailabilityType I examination preparation in progress; no report issued

We have established a documented security program and are preparing for an independent SOC 2 Type I examination. We intend to progress to Type II after the Type I milestone and an observation period. We will update this page only after an independent auditor issues a report.

Security governance

Our security program assigns accountable owners for security and compliance, maintains documented policies, reviews risks and access, and tracks identified issues through remediation or formal risk treatment. Personnel complete security-awareness training and acknowledge the policies that apply to their work.

Security practices

Identity and access. We use managed company identities, multi-factor authentication, least-privilege access, and documented joiner, mover, and leaver procedures. Access rights and privileged roles are reviewed on a recurring basis, and access is revoked when it is no longer required.

Encryption and secrets. Our API and public web endpoints enforce TLS 1.2 or higher. Data at rest is encrypted using provider-managed AES-256 or equivalent encryption. Secrets are kept in a managed secrets service and are not committed to source code or placed in logs. Full-disk encryption is required on endpoints used to access company systems.

Network and infrastructure security. We use managed cloud security controls, restricted administrative access paths, firewall rules, and centralized identity controls to protect production services. Network exposure and privileged access are reviewed as part of change management and recurring security reviews.

Secure development and change management. Source code is version-controlled. Production changes use a documented pull-request workflow, automated testing and security checks where applicable, controlled deployment steps, and post-deployment monitoring. Changes leave an auditable record from review through deployment.

Logging, monitoring, and vulnerability management. We centralize cloud audit logs and monitor security-relevant and availability events with automated alerting. Alerts are triaged under documented response procedures and reviewed for effectiveness. We scan for committed secrets and known vulnerable dependencies and prioritize remediation based on risk.

Data protection

Data location and confidentiality. Customer data is processed and stored primarily in the United States using major cloud and software service providers. Specific location or transfer requirements are addressed in customer agreements. Personnel with access to confidential information are subject to confidentiality obligations.

Classification and retention. We classify data as Public, Internal, Sensitive, or Critical and apply handling and access controls according to sensitivity. We retain data according to contractual requirements, legal obligations, and the practices described in our Privacy Policy, then delete or de-identify it when it is no longer required.

AI agent governance

AI agents are part of our operating environment. We are formalizing a governance program that inventories agents, classifies the trust level of their inputs and the impact of their permitted actions, documents boundaries, and applies additional safeguards to agents that process externally influenced content. Detailed governance material will be made available only after its internal approval gate is complete.

Incident response

We maintain a documented incident-response process covering detection, containment, eradication, recovery, communications, and post-incident review. If an incident affects customer data, we will notify affected customers in accordance with applicable law and contractual commitments.

Business continuity

We maintain documented business-continuity and disaster-recovery procedures with recovery objectives for in-scope services and data stores. Recovery procedures and supporting evidence are being tested and matured as part of our SOC 2 audit preparation.

Third-party service providers

We maintain an internal inventory and risk-review process for third parties that support our services. Customer-facing subprocessor information is subject to legal review and contractual approval before release.

Web data collection and acceptable use

Our services collect publicly available web data and transform it into structured datasets, analytics, and monitoring. Customer-directed requests remain subject to our acceptable-use requirements and product controls. Our Terms of Service and Privacy Policy describe the governing terms in more detail.

Request documentation

Additional security documentation is being prepared for approved release under mutual NDA. A security questionnaire and compliance summary will be available after internal review. A Data Processing Addendum is under legal review. A SOC 2 report will be available only after an independent auditor issues one.

Security contact: support@usestring.ai with “SECURITY” in the subject line. Use “PRIVACY” for privacy matters and “LEGAL” for legal requests. See also our security page for how to report a vulnerability.

© 2026 StringBuilt in New York City 🗽 🍎