Home / Trust & Security / Security Summary

Security summary

Strataigize, one page for your vendor review. Full detail at strataigize.com/trust/. Current as of the date printed below.

Legal entity
Strat-Ai-Gize Marketing & Automation Ltd., British Columbia, Canada. Founded 2022. 25th Floor, 700 West Georgia Street, Vancouver, BC V7Y 1B6. Phone (604) 720-3967.
Service scope
Growth marketing (paid media, ASO, SEO and AI search) and AI automation delivered through client-granted platform access. No payment processing, no customer accounts, no hosting of client production systems.
Access model
Least privilege through platform-native roles the client grants and can revoke instantly (Meta Business Manager, Google Ads, and equivalents). We never hold client logins. Business-critical accounts carry multi-factor authentication; credentials live in managed stores, never in code.
Change discipline
Read-only analysis by default. Changes to budgets, campaigns or client-facing systems follow a propose-first discipline with a named human approving them.
Data handling
Campaign data stays in the client’s own platforms. Website leads go to HubSpot. No sale of data, no sharing beyond listed subprocessors, return or deletion of client materials on request at engagement end.
AI governance
Aligned to the four functions of the NIST AI Risk Management Framework (no certification is claimed; NIST offers none). Commercial model APIs under terms that exclude training on client inputs and outputs. Anything that moves money, messages a client, or writes to a client system requires explicit approval from a named person.
Subprocessors
Cloudflare (hosting, security), HubSpot (CRM, scheduling), Google (analytics, ads), Meta (ads), PostHog (product analytics on our website), Anthropic (AI processing). Complete current list ships with the DPA.
Certifications
No third-party security certification is held today, and we say so rather than implying otherwise. We complete vendor security questionnaires on request; a formal audit is triggered by client requirements. Verified certifications are published at strataigize.com/trust/ the day they are real.
Privacy regime
Headquartered in Canada, operating under PIPEDA. A DPA covering processing scope, subprocessors, breach notification, data subject requests and deletion is available on request, including GDPR-style processor obligations.
Vulnerability reports
security contact: ian@strataigize.com. Good-faith research is acknowledged, never met with legal action.

Prepared by Strataigize · strataigize.com · ian@strataigize.com · (604) 720-3967 · Printed