Security and data protection (Trust)

Last updated: April 13, 2026

The Strike platform is built on secure-by-default principles, protecting customer information at every stage of the process.


Data use and AI models

Is my data used to train models?

No. Customer data is never used to train AI models.

👉 The platform operates in inference mode only: data is processed, but not stored or reused.

Is data shared with other customers?

No. Every customer operates in a fully isolated environment.

  • No shared memory

  • No cross-access between organizations

👉 Isolation is total.

Is data shared with third parties?

No. Strike doesn't sell or share customer data.

Information is used exclusively to run the platform and deliver the service.

What about external models like OpenAI or Anthropic?

  • They don't store or use data for training

  • They don't retain information beyond immediate processing

  • Strike sends only the strictly necessary information

👉 On top of that, data is filtered and sanitized before any interaction.


Data handling and storage

  • Data encrypted in transit (TLS) and at rest

  • Role-based access control

  • Storage on secure infrastructure (AWS)

👉 Only authorized personnel can access data, and only when needed.

What happens when an assessment ends?

  • The execution context is deleted

  • Temporary data is wiped

  • The environment used is destroyed

👉 No unnecessary data sticks around.


Customer control

Can I control what tests run?

Yes. You can define exclusions for:

  • Brute force

  • DoS

  • Destructive payloads

  • Data exfiltration

👉 This lets you match testing to your risk appetite.

Can I stop tests?

Yes. The platform includes a kill switch to stop executions in real time.


Human oversight

Strike runs on a Human-in-the-loop model:

  • Validation of findings

  • False positive removal

  • Real impact assessment

👉 AI assists, but decisions stay human.


Compliance and certifications

The platform holds international certifications:

  • ISO 27001

  • SOC 2

It also operates in alignment with standards like HIPAA.

Information security isn't an add-on — it's a core principle baked into how the platform is designed and operated.