SOC2C

Is this your company? Buyers are checking Strise here. Claim strise.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Strise logo

Strise

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Strise is SOC 2 Type II compliant. Strise also holds GDPR, and ISO 27001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Under "Resources" below you will find the most requested information for assessing Strise. We highly recommend to download these first to kick start your process. Privacy - Strise Standard Agreement with DPA - Data Privacy Impact Assessment (DPIA) - Privacy Policy Security - Strise Architectural Overview - Strise SOC 2 Type II Report These documents cover the majority of questions our customers ask. You can find additional documentation by searching.

Compliance & infrastructure

Hosting
GCP

Subprocessors

5
  • G
    Google Cloud Platform · Cloud Provider
    GCP in Belgium
  • A
    Auth0 · Authentication
    AWS in Germany
  • M
    Mailgun Technologies Inc · Email notifications and updates
    GCP in Germany & Belgium, AWS in Germany
  • I
    Intercom · In-app chat and product tour
    AWS in Ireland
  • S
    Signicat AS · Identity Verification (IDV) and/or Customer Facing Forms (CFF)
    GCP in Netherlands and Finland

Compliance leadership

The person who leads Strise's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Strise's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Strise SOC 2 compliant?
Strise is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Strise GDPR compliant?
According to Strise's public trust center, Strise is GDPR compliant. On SOC2C this listing is Listed.
Is Strise ISO 27001 certified?
According to Strise's public trust center, Strise is ISO 27001 certified. On SOC2C this listing is Listed.
Is Strise SOC 2 Type I or Type II?
Strise is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Strise's SOC 2 for a vendor risk assessment?
Yes. Strise's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Strise

Reproduced from Strise's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

I am assessing Strise. Which are the most important documents for me to download first?
Below are the most requested documents for assessing Strise. We highly recommend to download these first to kick start your process. Privacy - Strise Standard Agreement with DPA - Data Privacy Impact Assessment (DPIA) - Privacy Policy Security - Strise Architectural Overview - Strise SOC 2 Type II Report These documents cover the majority of questions our customers ask at this stage of the process. You can find additional documentation by searching on the Vanta Trust page above.
Who should I get in contact with if I can't find what I need?
Please get in contact with the person managing the agreement process at Strise. They are probably the person who has sent you access to this page. Let them know the question you need answers to and they will be able to guide you to the correct documentation on this page or send you a link directly to what you need. You can reach Strise through the following email addresses for specific inquiries: Sales: sales@strise.ai General support: support@strise.ai Privacy: privacy@strise.ai
Considering registering Strise as outsourcing with the relevant financial authority?
Strise have created a memorandum to describe the considerations as a customer regarding whether Strise should be registered as an outsourcing partner with the relevant financial authority. The document is not designed to give a definitive answer on the subject, but to help guide our customers with what the system does and where this may intersect with relevant rules on registration. This document is named as Strise Outsourcing Memorandum.
Where is the data processed?
Our data is hosted on Google Cloud Platform (GCP) servers, which are located in Belgium within the European Union (EU). This setup ensures that your data is stored securely and in compliance with GDPR and other relevant data protection regulations.
How do Strise ensure compliance with GDPR?
Strise complies with GDPR by implementing data minimization, purpose limitation, and retention controls. We collect only the data necessary for our services, limit data usage to purposes agreed upon with customers, and adhere to specified data retention periods. Additionally, we have procedures in place for handling Data Subject Access Requests (DSARs) and incident responses as per GDPR requirements.

Business & Industrial peers that completed SOC 2