Data handling
- Encryption in transit. All traffic to and from StratumCheck runs over TLS 1.3.
- Encryption at rest. Uploaded PDFs, extracted findings, and generated reports are encrypted at rest using AES-256.
- No model training on your data. Your plan sets are not used to train any AI models — ours or anyone else’s.
- No third-party sharing. Your data is never sold, licensed, or shared with third parties.
- Workspace isolation. Your reviews, findings, and reports are visible only to you and members of your workspace you’ve explicitly invited.
Account security
- Two-factor authentication required. Every account uses 2FA — no exceptions.
- Strong password requirements. Minimum 12 characters, checked against known breach databases.
- Session management. View active sessions and revoke any device from your account settings.
- Sign-in alerts. Email notifications when a new device authenticates.
Infrastructure
StratumCheck runs on commercial cloud infrastructure with SOC 2 Type II–attested providers. SOC 2 Type II for StratumCheck itself will be available with the Design Review tier launch. Until then, infrastructure-level attestations cover storage, compute, and networking.
Reporting a vulnerability
If you believe you’ve found a security issue, email hello@stratumcheck.com with details. We respond to all reports within two business days. We don’t run a public bug bounty yet, but we acknowledge responsible disclosures in our changelog.
Data deletion and export
You can export your reviews, findings, and reports at any time from your account. On cancellation, your data remains accessible for 90 days for export, then is permanently deleted. Backup data is rotated out within an additional 30 days.
Questions about security? We’re a small team and we read every message.
Email us — you’ll hear back from a real engineer.