Security and compliance

String Trust Center

We take the security and confidentiality of the data entrusted to us seriously. This page summarizes our security practices and the current status of our compliance program.

Last reviewed: July 2026

Compliance status

Framework
SOC 2
Scope
Security, Confidentiality, and Availability

Type I in progress - pursuing

We are building toward a SOC 2 Type I examination. No audit has been completed and no report has been issued. We do not represent String as SOC 2 certified, compliant, or audited.

Our approach

Security practices

We communicate our practices at a high level here while keeping implementation details and sensitive materials protected.

Access and authentication

Access to our systems is managed through authentication controls and role-appropriate access practices. We are formalizing a recurring access-review cadence as part of our SOC 2 program.

Encryption

We use encryption for data in transit and at rest, and we use managed secrets controls to protect credentials.

Secure development

We use version control, pull requests, and automated security checks as part of our development workflow. Production changes follow controlled release practices.

Monitoring and logging

We maintain logging and monitoring capabilities for security-relevant events, and continue to expand and document their coverage as part of our program.

Data handling

We classify data by sensitivity and apply handling and access controls proportionate to that classification. Retention and processing requirements are addressed through our customer commitments and internal practices.

AI agent governance

We are maturing a governance framework for automation and AI agents, with controls that scale with an agent's context and potential impact.

Incident response and continuity

We maintain incident-response and business-continuity processes covering detection, containment, recovery, and post-incident review. We notify affected customers in accordance with our contractual obligations.

Compliance documentation

Download our current public summaries below. The named NDA package remains unavailable until each document completes its security, compliance, and legal release review.

Markdown

Security and compliance overview

Available now

Our current security practices, SOC 2 posture, and public program commitments.

Download

Markdown

SOC 2 readiness statement

Available now

A concise statement of the examination status, intended scope, and pre-audit qualification.

Download

NDA package

Compliance summary

Release review pending

Program scope, policy coverage, readiness, and remediation summary for diligence review.

Not available for external distribution

NDA package

Security and compliance questionnaire

Release review pending

Evidence-backed answers to common customer security and compliance questions.

Not available for external distribution

NDA package

AI agent governance summary

Release review pending

A sanitized summary of the agent-governance design and current program maturity.

Not available for external distribution

NDA package

Data Processing Addendum

Legal review pending

Customer data-processing terms for review during contracting.

Not available for external distribution