strategical
Sign In
Trust & Safety

Security

Last updated: March 13, 2026. At Strategical, protecting your data is foundational to our platform. This page outlines the security measures we implement to safeguard your personas, research data, and account information.

1. Data Encryption

We employ encryption to protect data in transit and at rest:

In Transit: All data transmitted between your browser and our servers is protected using HTTPS. We do not support unencrypted connections.

At Rest: Stored data — including persona research, user accounts, and workshop sessions — is encrypted at rest by our cloud infrastructure provider. Database backups are also encrypted.

Secrets Management: API keys, tokens, and sensitive configuration values are stored in encrypted vaults and never committed to source code.

2. Authentication & Access Control

We implement multiple layers of access control:

Authentication is handled by a managed identity provider. We do not store or process raw passwords.

Session tokens are securely generated and expire after a period of inactivity.

Role-based access control restricts what each user can see and do within the platform.

Team members only see data associated with their assigned clients.

Administrative actions are logged for audit purposes.

3. Infrastructure & Hosting

Our infrastructure is designed for reliability and security:

The platform is hosted on established cloud infrastructure with strong security controls.

Automated deployment pipelines ensure consistent and auditable releases.

System dependencies and packages are regularly reviewed for known vulnerabilities.

Infrastructure access is limited to authorized personnel.

Regular backups are performed to support data recoverability.

4. Data Isolation

Your data is kept separate and secure:

Each client organization’s data is logically isolated within our database.

Application-level access controls are designed to prevent cross-tenant data access.

AI processing requests are scoped to your organization’s data only.

Third-party integrations (Stripe, OpenAI, Resend) receive only the minimum data necessary to perform their function.

5. Incident Response

We maintain an incident response process:

Security incidents are prioritized and investigated by our engineering team.

Affected users will be notified promptly following a confirmed data breach, in accordance with applicable law.

Post-incident reviews are conducted to identify root causes and implement preventive measures.

Critical security patches are applied promptly upon discovery of vulnerabilities.

6. Compliance

We are committed to responsible data handling:

Our data handling practices are designed to support GDPR and CCPA compliance.

We conduct regular internal security reviews.

Third-party vendors are evaluated for their security posture before integration.

7. Responsible Disclosure

We value the work of security researchers. If you discover a security vulnerability, please report it responsibly:

Email: support@strategical.ai

Please include a detailed description of the vulnerability and steps to reproduce it.

We ask that you give us reasonable time to investigate and address reported issues before public disclosure. We will acknowledge your report promptly and provide updates on our progress.