Home / Trust & Security
Trust & Security
Strataigize (Strat-Ai-Gize Marketing & Automation Ltd.) runs growth marketing and AI automation for clients who hand us access to systems that matter: ad accounts, CRMs, analytics, and internal workflows. This page states plainly how we protect that access, how we handle data, and how our AI operation is governed. A data processing agreement is available on request, and we complete vendor security questionnaires on request. Questions to[email protected].
Security posture
This website is a static site served through Cloudflare with TLS on every request. It has no customer accounts, no database of yours to breach, and takes no payments. The only data it accepts is what you submit through a lead form, protected against abuse by Cloudflare Turnstile and relayed directly to our CRM.
Access to client systems follows least privilege. We work through platform-native, client-granted roles (Meta Business Manager, Google Ads account access, and equivalents), which means you can see exactly what we can touch and revoke it yourself at any time. We default to read-only analysis; changes to budgets, campaigns, or client-facing systems follow a propose-first discipline with a named human approving them. Credentials live in managed credential stores, never in code, never in version control, and business-critical accounts carry multi-factor authentication.
Data handling
Your campaign data stays in your own ad platforms; we access it under the roles you grant rather than copying it out. Website leads (your email and what you choose to tell us) go to HubSpot, our CRM. Analytics on this site run behind a Termly-managed consent layer. We do not sell data, we do not share client data with third parties beyond the subprocessors listed below, and when an engagement ends we return or delete client materials on request.
The AI systems we build on are commercial model APIs used under terms that exclude training on your inputs and outputs. Client data is never used to train models, ours or anyone else's.
AI governance, aligned to the NIST AI RMF
We run our own company on AI agents, which is exactly why our governance is concrete rather than aspirational. Our practices align to the four functions of the NIST AI Risk Management Framework. Aligned means aligned: NIST offers no certification, and we do not claim one.
Govern. Accountability is named and human. Anything that moves money, messages a client, or writes to a client system requires explicit approval from a named principal, not an agent. Automations carry written scopes with hard bounds.
Map. Every agent workflow is documented before it runs: what it does, which systems it can reach, what data it can read, and what it must never do. Client data access is scoped per engagement.
Measure. Automated work is verified, not trusted: runs are logged, outputs are checked against measured baselines, and changes are validated after every write. Data windows and attribution settings are confirmed before any performance judgment.
Manage. Changes are incremental and reversible. Automations operate inside strict, pre-agreed bounds and escalate to a human on anything outside them. When something breaks, we fix the class of failure, not just the instance, and write the guard so it cannot recur silently.
Subprocessors
Core vendors that process data on our behalf: Cloudflare (hosting, security, anti-abuse), HubSpot (CRM and scheduling), Google (analytics and ads platforms), Meta (ads platform), and Anthropic (AI processing). The current complete list ships with the DPA.
Data processing agreement
A DPA covering processing scope and instructions, confidentiality, security measures, subprocessors, data subject requests, breach notification, and return or deletion of data is available on request at[email protected]. We are headquartered in Vancouver, Canada and operate under PIPEDA; the DPA covers GDPR-style processor obligations for clients who need them.
Reporting a security issue
Found a vulnerability on this site or in anything we operate? Email[email protected] with the details. We read every report, we will acknowledge yours, and we will not take legal action against good-faith research.
Common questions
Do you have a SOC 2 report?
Not yet. We are a 10-person firm and we are transparent about that. We complete vendor security questionnaires on request, and this page describes the controls we actually operate today. A formal audit gets triggered by client requirements.
Do AI models train on our data?
No. We build on commercial model APIs under terms that exclude training on your inputs and outputs. Your campaign data stays in your own ad accounts, and we do not feed client data into any system that trains on it.
Can we get a DPA?
Yes. A data processing agreement covering processing scope, subprocessors, breach notification, and deletion is available on request at [email protected].
How do we revoke your access?
Instantly, and in your own platform: remove our role in Meta Business Manager, Google Ads, or whichever system you granted. We work through platform-native permissions, so we never hold your logins.
What data does your website collect?
Only what you submit: lead forms collect your email plus the details you choose to share, protected by Cloudflare Turnstile and relayed to our CRM. Analytics run behind a consent manager.
Want the specifics for your procurement team?
Book a call and bring your security questionnaire. We answer it live.
LET'S TALK