Access and authentication
Access to our systems is managed through authentication controls and role-appropriate access practices. We are formalizing a recurring access-review cadence as part of our SOC 2 program.
We take the security and confidentiality of the data entrusted to us seriously. This page summarizes our security practices and the current status of our compliance program.
Last reviewed: July 2026
Compliance status
Type I in progress - pursuing
We are building toward a SOC 2 Type I examination. No audit has been completed and no report has been issued. We do not represent String as SOC 2 certified, compliant, or audited.
Our approach
We communicate our practices at a high level here while keeping implementation details and sensitive materials protected.
Access to our systems is managed through authentication controls and role-appropriate access practices. We are formalizing a recurring access-review cadence as part of our SOC 2 program.
We use encryption for data in transit and at rest, and we use managed secrets controls to protect credentials.
We use version control, pull requests, and automated security checks as part of our development workflow. Production changes follow controlled release practices.
We maintain logging and monitoring capabilities for security-relevant events, and continue to expand and document their coverage as part of our program.
We classify data by sensitivity and apply handling and access controls proportionate to that classification. Retention and processing requirements are addressed through our customer commitments and internal practices.
We are maturing a governance framework for automation and AI agents, with controls that scale with an agent's context and potential impact.
We maintain incident-response and business-continuity processes covering detection, containment, recovery, and post-incident review. We notify affected customers in accordance with our contractual obligations.
Download our current public summaries below. The named NDA package remains unavailable until each document completes its security, compliance, and legal release review.
Markdown
Our current security practices, SOC 2 posture, and public program commitments.
DownloadMarkdown
A concise statement of the examination status, intended scope, and pre-audit qualification.
DownloadNDA package
Program scope, policy coverage, readiness, and remediation summary for diligence review.
Not available for external distribution
NDA package
Evidence-backed answers to common customer security and compliance questions.
Not available for external distribution
NDA package
A sanitized summary of the agent-governance design and current program maturity.
Not available for external distribution
NDA package
Customer data-processing terms for review during contracting.
Not available for external distribution