Skip to main content
Platform Review
PricingSign in
stratify assessment

stratify procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for stratify
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow We may process data in the United States or other jurisdictions where our infrastructure or providers operate. All transfers comply with applicable data protection laws, and, where required, standard contractual clauses or equivalent safeguards are used.Captured 2026-08-11Open source →Finding permalink →
Data retentionAll applicable tiersunknown Stratify follows strict data minimization and retention standards across all integrations: We request only the minimal data necessary to perform campaign management and analytics. Integration tokens and credentials (e.g., OAuth tokens from LinkedIn, Google, HubSpot, Salesforce) are encrypted at rest using AES-256 and stored exclusively in AWS Secrets Manager. Tokens are never stored in our application database (Supabase) and are automatically refreshed or rotated as required. Temporary campaign data and social activity metrics retrieved from advertising platforms are cached only as needed to complete requests and are deleted or refreshed within 24–48 hours in accordance with API data storage requirements. Redis is used only for ephemeral caching and queuing — it does not store PII or any persistent records. Campaign-level metrics (e.g., CTR, spend, cost per lead) may be retained in aggregated form for up to 90 days, configurable per tenant. Logs and analytics data are scrubbed of PII and retained for no more than 30 days. Data is never exported, redistributed, or combined with unrelated datasets to build profiles, leads, or audience segments.Captured 2026-08-11Open source →Finding permalink →
Data retentionAll applicable tiersmedium We retain data only for as long as necessary to provide services or meet legal obligations. Campaign performance metrics are stored for a maximum of 90 days unless otherwise required for billing or contractual purposes. Cached data obtained via advertising or CRM APIs is refreshed or deleted within 24–48 hours, consistent with the storage requirements of our API partners. You may request deletion of your account or associated data at any time by contacting privacy@stratify.ai.Captured 2026-08-11Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow We do not sell, rent, or trade your personal data. We only share data with trusted third-party service providers essential to delivering Stratify's functionality. These include:Captured 2026-08-11Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown OpenAI, Anthropic Language model–based features (never involving user PII) Captured 2026-08-11Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown All third-party providers are bound by strict confidentiality and data-protection agreements.Captured 2026-08-11Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Network Edge: Cloudflare provides CDN, WAF, and DDoS protection. Monitoring: Sentry is used for performance monitoring and error logging; PostHog for anonymized analytics. Authentication: Enterprise SSO handled through WorkOS for secure identity management. We maintain internal audit logs of key system actions to ensure compliance and traceability.Captured 2026-08-11Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.