Skip to content
Security and data

Your customers' data, treated like it's yours. Because it is.

A CRM holds the most sensitive commercial data a small company has. This page says plainly where it lives, who can see it, and what we do and don't do with it.

SOC 2 Type IIGDPRLGPDEU + BR data residency

Where your data lives

Each account is pinned to one region at creation: the EU (Frankfurt) or Brazil (São Paulo). It does not move.Backups stay in the same region, encrypted, with 35 days of point-in-time recovery.Data residency is in the contract on Scale, and in the account settings on every plan.

Encryption and access

TLS 1.2+ in transit, AES-256 at rest, including backups and email content.Our staff cannot open your account without a support request from you; every access is logged and visible to account owners.Passwords are hashed with Argon2; sessions expire and can be revoked from settings.

Who sees what inside your account

Four fixed roles (owner, admin, member, read-only) mapped to explicit scopes. No hidden super-user.API keys carry their own scopes and can expire. The full key is shown once.Hiding an object from navigation is presentation only; access is decided by role, never by what is on screen.

Email and tracking

You send from your own domain with SPF, DKIM and DMARC. We never send from a shared pool under your name.Open and click tracking is per-message and off by default for contacts without marketing consent.The website snippet sets a first-party cookie only after your consent banner allows it.

Audit and retention

Every record change carries who, when and from where; the timeline is the audit trail.Deleted records are recoverable for 30 days by an admin, then purged.When you cancel, the account and its data are deleted immediately and we send a written confirmation.

Operations

Production is separated from staging; changes go through review and automated tests before deploy.Uptime, incidents and maintenance are published on the status page; account owners can subscribe.Annual penetration test by an independent firm; summary available on request.

What the AI assistant sees

The assistant reads only the records the asking user can see, through the same permission checks as the UI. Prompts and outputs are not used to train models. Anything that would change data is a proposal the user confirms. That is a product rule, not a setting.

Sub-processors

Cloud hosting in the EU and Brazil, an email delivery provider, an AI model provider and an error-tracking service. The current list with locations is in the DPA, and we email account owners 30 days before adding one.

Reporting a vulnerability

Write to security@stretto.app. We acknowledge within two business days, keep you informed, and credit you if you want. No legal action against good-faith research.

Need the documents?

SOC 2 report, DPA, sub-processor list and the security questionnaire we've already filled in.

Request the security pack