Security summary
Strataigize, one page for your vendor review. Full detail at strataigize.com/trust/. Current as of the date printed below.
- Legal entity
- Strat-Ai-Gize Marketing & Automation Ltd., British Columbia, Canada. Founded 2022. 25th Floor, 700 West Georgia Street, Vancouver, BC V7Y 1B6. Phone (604) 720-3967.
- Service scope
- Growth marketing (paid media, ASO, SEO and AI search) and AI automation delivered through client-granted platform access. No payment processing, no customer accounts, no hosting of client production systems.
- Access model
- Least privilege through platform-native roles the client grants and can revoke instantly (Meta Business Manager, Google Ads, and equivalents). We never hold client logins. Business-critical accounts carry multi-factor authentication; credentials live in managed stores, never in code.
- Change discipline
- Read-only analysis by default. Changes to budgets, campaigns or client-facing systems follow a propose-first discipline with a named human approving them.
- Data handling
- Campaign data stays in the client’s own platforms. Website leads go to HubSpot. No sale of data, no sharing beyond listed subprocessors, return or deletion of client materials on request at engagement end.
- AI governance
- Aligned to the four functions of the NIST AI Risk Management Framework (no certification is claimed; NIST offers none). Commercial model APIs under terms that exclude training on client inputs and outputs. Anything that moves money, messages a client, or writes to a client system requires explicit approval from a named person.
- Subprocessors
- Cloudflare (hosting, security), HubSpot (CRM, scheduling), Google (analytics, ads), Meta (ads), PostHog (product analytics on our website), Anthropic (AI processing). Complete current list ships with the DPA.
- Certifications
- No third-party security certification is held today, and we say so rather than implying otherwise. We complete vendor security questionnaires on request; a formal audit is triggered by client requirements. Verified certifications are published at strataigize.com/trust/ the day they are real.
- Privacy regime
- Headquartered in Canada, operating under PIPEDA. A DPA covering processing scope, subprocessors, breach notification, data subject requests and deletion is available on request, including GDPR-style processor obligations.
- Vulnerability reports
- security contact: ian@strataigize.com. Good-faith research is acknowledged, never met with legal action.
Prepared by Strataigize · strataigize.com · ian@strataigize.com · (604) 720-3967 · Printed