Is this your company?Buyers are checking Strise here. Claim strise.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Under "Resources" below you will find the most requested information for assessing Strise. We highly recommend to download these first to kick start your process. Privacy - Strise Standard Agreement with DPA - Data Privacy Impact Assessment (DPIA) - Privacy Policy Security - Strise Architectural Overview - Strise SOC 2 Type II Report These documents cover the majority of questions our customers ask. You can find additional documentation by searching.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Strise SOC 2 compliant?
Strise is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Strise GDPR compliant?
According to Strise's public trust center, Strise is GDPR compliant. On SOC2C this listing is Listed.
Is Strise ISO 27001 certified?
According to Strise's public trust center, Strise is ISO 27001 certified. On SOC2C this listing is Listed.
Is Strise SOC 2 Type I or Type II?
Strise is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Strise's SOC 2 for a vendor risk assessment?
Yes. Strise's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Strise penetration tested?
Strise hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Strise secure?
Security isn't a single yes/no, but Strise is SOC 2 Type II compliant and holds GDPR, SOC 2 Type II, ISO 27001. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Strise have a bug bounty or vulnerability disclosure program?
Strise hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@strise.ai or via a /security page (Strise lists a security contact).
Who are Strise's subprocessors?
Strise lists 5 subprocessors on its trust center, including Google Cloud Platform, Auth0, Mailgun Technologies Inc, Intercom, Signicat AS. Buyers use this for fourth-party risk review.
Where does Strise host or store data?
Strise hosts on GCP. Data residency details are on its trust center.
Where is Strise's trust center or security page?
Strise's trust center is at https://trust.strise.ai. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
I am assessing Strise. Which are the most important documents for me to download first?
Below are the most requested documents for assessing Strise. We highly recommend to download these first to kick start your process. Privacy - Strise Standard Agreement with DPA - Data Privacy Impact Assessment (DPIA) - Privacy Policy Security - Strise Architectural Overview - Strise SOC 2 Type II Report These documents cover the majority of questions our customers ask at this stage of the process. You can find additional documentation by searching on the Vanta Trust page above.
Who should I get in contact with if I can't find what I need?
Please get in contact with the person managing the agreement process at Strise. They are probably the person who has sent you access to this page. Let them know the question you need answers to and they will be able to guide you to the correct documentation on this page or send you a link directly to what you need. You can reach Strise through the following email addresses for specific inquiries: Sales: sales@strise.ai General support: support@strise.ai Privacy: privacy@strise.ai
Considering registering Strise as outsourcing with the relevant financial authority?
Strise have created a memorandum to describe the considerations as a customer regarding whether Strise should be registered as an outsourcing partner with the relevant financial authority. The document is not designed to give a definitive answer on the subject, but to help guide our customers with what the system does and where this may intersect with relevant rules on registration. This document is named as Strise Outsourcing Memorandum.
Where is the data processed?
Our data is hosted on Google Cloud Platform (GCP) servers, which are located in Belgium within the European Union (EU). This setup ensures that your data is stored securely and in compliance with GDPR and other relevant data protection regulations.
How do Strise ensure compliance with GDPR?
Strise complies with GDPR by implementing data minimization, purpose limitation, and retention controls. We collect only the data necessary for our services, limit data usage to purposes agreed upon with customers, and adhere to specified data retention periods. Additionally, we have procedures in place for handling Data Subject Access Requests (DSARs) and incident responses as per GDPR requirements.
Where can I find information about Strise’s privacy practices?
You can access Strise's Privacy Policy on our website or access the policy at the Trust center directly.
How can I request the deletion of my personal data from Strise?
Individuals seeking to have their personal data deleted can contact Strise's Data Protection Officer (DPO) or designated privacy expert at privacy@strise.ai. The request should include information necessary for identity verification.
What is Strise's approach to incident response?
We have a detailed Incident Response Plan in place to handle security incidents. This plan includes steps for identifying, reporting, and managing incidents to minimize impact. In case of a security breach, we are committed to notifying affected parties promptly and taking corrective actions to prevent future occurrences.
Want to report a potential security issue?
To report a potential security issue, please contact our security team immediately via security@strise.ai. Include a detailed description of the issue, the systems involved, and any relevant logs or evidence. Our team will respond promptly to address the situation in accordance with our Incident Response Plan. Your report is crucial in helping us maintain a secure environment for all our users.
Does Strise use third-party services, and how is data managed with these providers?
Strise uses trusted third-party providers for certain operational needs, such as cloud hosting through Google Cloud. We have data processing agreements (DPAs) with all third-party providers to ensure they meet our security and privacy standards. Providers are assessed annually, and their systems are monitored to align with our security policies.
How does Strise handle data deletion?
Customer data is securely deleted following predefined data retention policies or upon the termination of our services, depending on contractual obligations and regulatory requirements. Strise uses secure methods for deletion, including routine database cleaning and full de-identification processes when applicable.
What type of encryption to Strise us
Strise applies encryption both in transit and at rest to secure data. This involves: TLS for Data in Transit: All web traffic carrying confidential data is transmitted using TLS v1.2 or higher. This standard is used to ensure that data remains protected from interception while moving across networks. AES for Data at Rest: Strise uses AES encryption for storing data securely at rest, providing strong confidentiality measures for sensitive information. These practices align with industry standards and are part of Strise's broader Cryptography Policy, which emphasizes strong encryption protocols, key management, and regulatory compliance.