Straticum
Join nowSign in

Security

Last updated 9 August 2026

Straticum is only useful if you are willing to put real information into it: your numbers, your strategy, the documents you would not email to a stranger. Here is what happens to all of it.

The short version

  • Your data is encrypted, in transit and in storage.
  • It is private to your workspace. Only the colleagues you invite can see it.
  • It is never used to train an AI model.
  • We never sell it, and we do not run advertising or third-party tracking inside the product.
  • You can delete it, and we will confirm when it is done.

Your data is encrypted

Everything you send to Straticum travels over an encrypted connection, and everything we store stays encrypted at rest: your database records, our backups of them, and every file you upload.

Credentials for services you connect get a second layer on top. They are encrypted with a key kept outside the database, so they are not readable even to someone holding a copy of it.

Only your workspace can see it

Your company’s data is visible to the colleagues you invite, and to nobody else. Every request checks your membership before returning anything, and roles decide what each person can do once inside.

We do not read your content ourselves, except where you ask us to help with something specific, or where we have to in order to investigate abuse or comply with the law.

Our infrastructure runs in Amazon Web Services data centres. The database sits on a private network with no public address, so it cannot be reached from the internet at all.

Documents you upload

A document is the most sensitive thing you will put into Straticum, so this is worth being specific about.

Your files are stored privately and encrypted. They are never given a public link: there is no address that works without being signed in, because the only way to open a file is through Straticum, which checks that you belong to the workspace first. We keep the original so you can download exactly what you put in, and we read the text out of it so the assistant can search it and cite the section an answer came from.

Your content never trains an AI model

Straticum uses Anthropic and OpenAI to produce analysis and to make your knowledge base searchable. Both are used through their commercial APIs, under terms that do not allow your content to be used to train their models.

Neither is ever given your password, your session, or the credentials for anything you have connected.

Services you connect

Nothing is connected unless you connect it. Where a provider offers read-only access we ask for that and nothing more, so Straticum can read your Google Analytics but cannot change or delete anything in it. You can disconnect any service at any time, which revokes our access immediately.

Support tickets get extra care, because that is where your customers speak in their own words. Names, email addresses, phone numbers and card numbers are removed before the content is stored or sent to a model, so we keep the substance of a complaint without the person’s details.

Who else processes your data

A small number of providers help run the service. Each one receives only what its job requires.

  • Amazon Web Services: Hosting, the database, file storage and email delivery.
  • Google: Verifying who you are when you sign in.
  • Anthropic: The analysis and assistant answers described above.
  • OpenAI: Search across your knowledge base.
  • Polar: Payments and billing. Card details go to the payment provider and never reach our servers.
  • Services you choose to connect yourself, such as Google Analytics, RevenueCat or Zendesk.

The Privacy Policy sets out what each of these receives and the rights you have over the information we hold.

Keeping it, and deleting it

Your data is kept for as long as your company exists in Straticum. Deleting a document removes it from your library and from search, and deleting a company removes its data from the product. Backups are kept for seven days so that a mistake or a failure is recoverable.

If you want your account removed entirely, or you want us to confirm that every copy of something is gone, write to hello@straticum.com and we will do it and tell you when it is finished.

Found a problem?

No system is perfect, and we would rather hear it from you than not. If you think you have found a vulnerability, write to hello@straticum.com instead of posting it publicly. We will get back to you, keep you updated while we fix it, and we will not pursue anyone who reports something in good faith.

Straticum is owned and operated by Simfolio (Pty) Ltd. Questions about this document, or any request concerning your data, can be sent to hello@straticum.com.

Straticum

The AI assistant that helps your business grow.

Get started

© 2026 Straticum

PrivacyTerms