Your customers' data, treated like it's yours. Because it is.
A CRM holds the most sensitive commercial data a small company has. This page says plainly where it lives, who can see it, and what we do and don't do with it.
Where your data lives
Encryption and access
Who sees what inside your account
Email and tracking
Audit and retention
Operations
What the AI assistant sees
The assistant reads only the records the asking user can see, through the same permission checks as the UI. Prompts and outputs are not used to train models. Anything that would change data is a proposal the user confirms. That is a product rule, not a setting.
Sub-processors
Cloud hosting in the EU and Brazil, an email delivery provider, an AI model provider and an error-tracking service. The current list with locations is in the DPA, and we email account owners 30 days before adding one.
Reporting a vulnerability
Write to security@stretto.app. We acknowledge within two business days, keep you informed, and credit you if you want. No legal action against good-faith research.
Need the documents?
SOC 2 report, DPA, sub-processor list and the security questionnaire we've already filled in.