stratify procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ We may process data in the United States or other jurisdictions where our infrastructure or providers operate. All transfers comply with applicable data protection laws, and, where required, standard contractual clauses or equivalent safeguards are used.” | Captured 2026-08-11Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Stratify follows strict data minimization and retention standards across all integrations: We request only the minimal data necessary to perform campaign management and analytics. Integration tokens and credentials (e.g., OAuth tokens from LinkedIn, Google, HubSpot, Salesforce) are encrypted at rest using AES-256 and stored exclusively in AWS Secrets Manager. Tokens are never stored in our application database (Supabase) and are automatically refreshed or rotated as required. Temporary campaign data and social activity metrics retrieved from advertising platforms are cached only as needed to complete requests and are deleted or refreshed within 24–48 hours in accordance with API data storage requirements. Redis is used only for ephemeral caching and queuing — it does not store PII or any persistent records. Campaign-level metrics (e.g., CTR, spend, cost per lead) may be retained in aggregated form for up to 90 days, configurable per tenant. Logs and analytics data are scrubbed of PII and retained for no more than 30 days. Data is never exported, redistributed, or combined with unrelated datasets to build profiles, leads, or audience segments.” | Captured 2026-08-11Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We retain data only for as long as necessary to provide services or meet legal obligations. Campaign performance metrics are stored for a maximum of 90 days unless otherwise required for billing or contractual purposes. Cached data obtained via advertising or CRM APIs is refreshed or deleted within 24–48 hours, consistent with the storage requirements of our API partners. You may request deletion of your account or associated data at any time by contacting privacy@stratify.ai.” | Captured 2026-08-11Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We do not sell, rent, or trade your personal data. We only share data with trusted third-party service providers essential to delivering Stratify's functionality. These include:” | Captured 2026-08-11Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ OpenAI, Anthropic Language model–based features (never involving user PII) ” | Captured 2026-08-11Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ All third-party providers are bound by strict confidentiality and data-protection agreements.” | Captured 2026-08-11Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Network Edge: Cloudflare provides CDN, WAF, and DDoS protection. Monitoring: Sentry is used for performance monitoring and error logging; PostHog for anonymized analytics. Authentication: Enterprise SSO handled through WorkOS for secure identity management. We maintain internal audit logs of key system actions to ensure compliance and traceability.” | Captured 2026-08-11Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.