Home/ Trust Centre

Security &
Compliance.

How we handle data, secure systems and meet the compliance requirements of regulated industries. Transparency is not a policy for us — it's how we work.

Last updatedApril 2026
Contactsecurity@stringlab.org
Security · Posture

Infrastructure Security

All production infrastructure deployed on AWS/GCP with VPC isolation, encryption at rest (AES-256) and in transit (TLS 1.3), secrets management via AWS Secrets Manager / GCP Secret Manager, and automated vulnerability scanning on every deployment.

Security · Access

Access Control

Role-based access control, MFA enforced for all staff accounts, principle of least privilege, SSO via Okta, and quarterly access reviews. Client environment access is logged and time-limited.

Security · Code

Secure Development

SAST and dependency scanning in every CI/CD pipeline, code review required before merge, no secrets in version control, and annual penetration testing by an external firm.

Compliance · Data

Data Handling

Client data is never used to train our models unless explicitly contracted. Data is deleted within 30 days of engagement end unless retention is agreed. We maintain data processing agreements (DPAs) with all clients that handle personal data.

Compliance · Regulations

Regulatory Coverage

We've built production systems under GDPR, HIPAA, FCA requirements, FINTRAC, India's DPDP Act and ISO 27001-aligned practices. We engage external legal counsel for regulatory scoping on each regulated-industry engagement.

Compliance · Roadmap

SOC 2 Type II Roadmap

We are currently implementing SOC 2 Type II controls with a target certification date of Q4 2026. ISO 27001 certification is on the 2027 roadmap. Clients requiring certification today can request our current security questionnaire.

Incident response

How we respond to security incidents.

We maintain a documented incident response plan reviewed quarterly. In the event of a security incident affecting client data:

  • Affected clients are notified within 24 hours of confirmation
  • Root cause analysis completed within 72 hours
  • Written post-incident report provided to clients within 7 business days
  • Regulatory notifications made per applicable law (72-hour window for GDPR)

To report a security concern, contact security@stringlab.org. We have a responsible disclosure policy for external researchers.

Documents
Data Processing Agreement (DPA) Template Request →
Security Questionnaire (InfoSec) Request →
Penetration Test Summary (2025) Request under NDA →
Privacy Policy View →