Trust Center
Security, privacy, resilience, and responsible AI are built into how Strover develops and operates its cloud decision-intelligence platform.
01 Our trust commitment
Strover helps enterprises turn cloud-security and compliance signals into explainable, governed actions. We recognize that this requires strong protection of customer data, transparent operating practices, and controls that support enterprise assurance reviews.
This Trust Center provides a public overview. Detailed evidence, architecture information, and contractual commitments may be made available to customers and qualified prospects under confidentiality obligations.
02 Assurance and governance
- An information security management system certified to ISO 27001:2022, supported by a risk-based control program.
- A quality management system certified to ISO 9001:2015 for the applicable certification scope.
- Documented ownership for security, privacy, incident response, change management, access review, and vendor risk.
- Periodic risk assessments, control reviews, and corrective-action tracking.
Certificate details and assurance evidence are available to qualified customers and prospects upon request, subject to appropriate confidentiality requirements.
03 Platform and infrastructure security
- Cloud-hosted architecture on Amazon Web Services (AWS), with environment separation appropriate to development, testing, and production.
- Encryption in transit using current industry-standard transport security and encryption at rest for supported production data stores.
- Role-based access control, least-privilege access, multi-factor authentication for privileged access, and periodic access reviews.
- Centralized logging and monitoring designed to support security investigation, operational oversight, and auditability.
- Secure configuration, vulnerability management, patching, secrets management, and change-control practices appropriate to system risk.
04 Secure product development
Strover applies security throughout the software-development lifecycle, including peer review, automated testing where appropriate, dependency and vulnerability checks, controlled releases, and remediation tracking. Material production changes are reviewed and deployed through authorized processes.
05 Customer data and tenant protection
- Customer content remains owned by the customer and is processed only to provide, secure, support, and improve the contracted service, subject to the applicable agreement.
- Access to customer content is restricted to authorized personnel with a legitimate business need and is logged where technically supported.
- Strover uses logical controls designed to separate customer environments and reduce unauthorized cross-tenant access.
- Cloud integrations should use least-privilege permissions. Customers control the accounts and permissions they grant to Strover.
- Customer content is not sold. It is not used to train public or general-purpose AI models unless the customer expressly agrees in writing.
06 Responsible AI and decision governance
Nova combines machine-assisted analysis with deterministic policy logic, customer context, and human governance. Recommendations may be incomplete or incorrect and should be reviewed by authorized users before changes are approved or executed.
- Explainable findings and recommendations designed to show relevant evidence and reasoning.
- Approval-based remediation and role separation where configured by the customer.
- Audit trails for supported decision and remediation workflows.
- Testing and monitoring intended to reduce unsafe, misleading, or operationally harmful outputs.
07 Availability, resilience, and incident response
Strover maintains operational monitoring, backup, recovery, and incident-response processes appropriate to the platform. Service levels, backup frequency, recovery objectives, notification timelines, and support response targets are governed by the customer’s Order Form, service-level agreement, data-processing agreement, or other written contract.
Strover assesses security events, contains and remediates confirmed incidents, preserves relevant records, and notifies affected customers or authorities when required by applicable law or contract.
08 Privacy and data protection
Strover follows data-minimization, purpose-limitation, access-control, retention, and secure-deletion practices appropriate to the processing. When Strover processes personal data in customer content on a customer’s behalf, the customer generally determines the purpose and means of processing and Strover acts as its service provider or processor, subject to contract and applicable law.
Read the Privacy Policy and Terms of Service.
09 Third-party service providers
Strover may use vetted infrastructure, communications, analytics, support, and AI service providers. Providers are evaluated according to risk and are contractually required, where appropriate, to protect data and use it only for authorized purposes. A current subprocessor list may be provided to enterprise customers or published separately as the platform matures.
10 Responsible disclosure
If you believe you have found a security vulnerability affecting a Strover service, report it privately with enough detail for us to investigate. Do not access, modify, download, or disclose data that is not yours; disrupt services; or perform destructive testing. We will acknowledge and assess good-faith reports and coordinate remediation and disclosure where appropriate.
11 Contact
- Security and vulnerability reports: Hello@strover.ai
- Privacy requests: Hello@strover.ai
- General and assurance enquiries: Hello@strover.ai
- Company: Strover AI Labs Private Limited, Coimbatore, Tamil Nadu, India
- Website: https://strover.ai