Home / Trust & Security
Trust & Security
Strataigize (Strat-Ai-Gize Marketing & Automation Ltd.) runs growth marketing and AI automation for clients who hand us access to systems that matter: ad accounts, CRMs, analytics, and internal workflows. This page states how we protect that access, how we handle data, and how our AI operation is governed. A data processing agreement is available on request, and we complete vendor security questionnaires on request. Questions to ian@strataigize.com.
Bringing this to a procurement team? A printable one-page summary lives at the security summary, built to be attached to a vendor review.
Security posture
This website is a static site served through Cloudflare with TLS on every request. It has no customer accounts, no database of yours to breach, and takes no payments. The only data it accepts is what you submit through a lead form, protected against abuse by Cloudflare Turnstile and relayed directly to our CRM.
Access to client systems follows least privilege. We work through platform-native, client-granted roles (Meta Business Manager, Google Ads account access, and equivalents), which means you can see exactly what we can touch and revoke it yourself at any time. We default to read-only analysis; changes to budgets, campaigns, or client-facing systems follow a propose-first discipline with a named human approving them. Credentials live in managed credential stores, never in code, never in version control, and business-critical accounts carry multi-factor authentication.
Data handling
Your campaign data stays in your own ad platforms; we access it under the roles you grant rather than copying it out. Website leads (your email and what you choose to tell us) go to HubSpot, our CRM. Analytics on this site run behind a Termly-managed consent layer. We do not sell data, we do not share client data with third parties beyond the subprocessors listed below, and when an engagement ends we return or delete client materials on request.
The AI systems we build on are commercial model APIs used under terms that exclude training on your inputs and outputs. Client data is never used to train models, ours or anyone else's.
AI governance, aligned to the NIST AI RMF
We run our own company on AI agents, which is exactly why our governance is concrete rather than aspirational. Our practices align to the four functions of the NIST AI Risk Management Framework. Aligned means aligned: NIST offers no certification, and we do not claim one.
Govern. Accountability is named and human. Anything that moves money, messages a client, or writes to a client system requires explicit approval from a named principal, not an agent. Automations carry written scopes with hard bounds.
Map. Every agent workflow is documented before it runs: what it does, which systems it can reach, what data it can read, and what it must never do. Client data access is scoped per engagement.
Measure. Automated work is verified, not trusted: runs are logged, outputs are checked against measured baselines, and changes are validated after every write. Data windows and attribution settings are confirmed before any performance judgment.
Manage. Changes are incremental and reversible. Automations operate inside strict, pre-agreed bounds and escalate to a human on anything outside them. When something breaks, we fix the class of failure, not just the instance, and write the guard so it cannot recur silently.
Subprocessors
Core vendors that process data on our behalf: Cloudflare (hosting, security, anti-abuse), HubSpot (CRM and scheduling), Google (analytics and ads platforms), Meta (ads platform), PostHog (product analytics and session replay on this website), and Anthropic (AI processing). The current complete list ships with the DPA.
Data processing agreement
A DPA covering processing scope and instructions, confidentiality, security measures, subprocessors, data subject requests, breach notification, and return or deletion of data is available on request at ian@strataigize.com. We are headquartered in Vancouver, Canada and operate under PIPEDA; the DPA covers GDPR-style processor obligations for clients who need them.
Certifications and formal audits
Third-party certifications are published in the list below the day they are verified, each with an evidence link, and never a day earlier. The same registry that renders this list also feeds our structured data, so a badge and its machine-readable claim can never disagree. Formal audits get triggered by client requirements, and the controls above operate regardless of certification status.
- Strataigize (self-declaration): PIPEDA compliance statement
- Strataigize (self-declaration): GDPR processor obligations statement
- Clutch: Clutch, business verification
- Semrush: Semrush Agency Partner
- Semrush: Semrush for Digital Agencies Certification
Legal entity
Strataigize operates as Strat-Ai-Gize Marketing & Automation Ltd., a British Columbia company founded in 2022 and headquartered at 25th Floor, 700 West Georgia Street, Vancouver, British Columbia, V7Y 1B6, Canada. Phone (604) 720-3967. Engagements are contracted under British Columbia law unless agreed otherwise in writing.
Accessibility
This site is built against WCAG 2.2 AA as the working target: semantic structure with one h1 per page, a skip link, keyboard-operable menus, visible focus states, meaningful alt text, and color contrast checked against tokens designed for it. Automated accessibility checks run in our build pipeline on every change, currently at zero first-party errors.
Known exception: animations run for all visitors by a deliberate design decision, so the reduced-motion preference is not currently honored. Interactive motion pauses off-screen and no content is conveyed by motion alone. This is a self-declared statement, not a third-party conformance evaluation. If anything here is hard for you to use, email us at ian@strataigize.com and we will fix it or provide the content another way.
Reporting a security issue
Found a vulnerability on this site or in anything we operate? Email ian@strataigize.com with the details. We read every report, we will acknowledge yours, and we will not take legal action against good-faith research.
Common questions
Do you have a SOC 2 report?
Not yet. We are a small, senior firm. We complete vendor security questionnaires on request, and this page describes the controls we actually operate today. A formal audit gets triggered by client requirements.
Do AI models train on our data?
No. We build on commercial model APIs under terms that exclude training on your inputs and outputs. Your campaign data stays in your own ad accounts, and we do not feed client data into any system that trains on it.
Can we get a DPA?
Yes. A data processing agreement covering processing scope, subprocessors, breach notification, and deletion is available on request at ian@strataigize.com.
How do we revoke your access?
Instantly, and in your own platform: remove our role in Meta Business Manager, Google Ads, or whichever system you granted. We work through platform-native permissions, so we never hold your logins.
What data does your website collect?
Only what you submit: lead forms collect your email plus the details you choose to share, protected by Cloudflare Turnstile and relayed to our CRM. Analytics run behind a consent manager.
Want the specifics for your procurement team?
Book a call and bring your security questionnaire. We answer it live.
LET'S TALK Rated 5.0 on Clutch