Trust Center
Strataflows connects to your Salesforce and revenue tools to build sales intelligence. Here is exactly how we handle your data — the same facts we take into a security review. If you are reviewing us before authorizing a connection, this is everything in one place.
How we connect
Read-only OAuth. Nothing is installed in your Salesforce org.
- Strataflows connects to Salesforce as an external OAuth client — there is no managed package and no code installed in your Salesforce org.
- OAuth 2.0 Authorization Code flow with PKCE (RFC 7636, S256) and least-privilege scopes.
- Read-only: Strataflows reads opportunities, accounts, contacts, and activities. It never writes, modifies, or deletes Salesforce records — the only outbound call is an OAuth token revoke when you disconnect.
Encryption
AES-256-GCM at rest, TLS 1.3 in transit.
- OAuth tokens are encrypted at rest with AES-256-GCM at the application layer; the encryption key is held outside the database, so a database compromise alone does not expose tokens.
- All data is encrypted in transit with TLS.
- Beneath that, the database provider adds storage-layer encryption at rest (AES-256).
Tenant isolation
Every customer's data is walled off, enforced in three layers.
- Each customer's data is partitioned by organization and isolated by Postgres row-level security.
- An application-layer access gate re-checks every account read and write.
- A mechanical build-time check keeps privileged queries scoped — so one customer can never read another's data.
Subprocessors & the AI data path
We are upfront about where data goes — including our AI provider.
- Strataflows uses OpenAI as an LLM subprocessor: to generate intelligence, prompts that include content derived from your CRM data (account names, opportunity stage/amount/close-date, and deal signals) are sent over TLS to OpenAI for model inference. OpenAI returns generated text; Strataflows stores only token-count and cost metadata about each call — never the prompt or the completion.
- Infrastructure subprocessors: Supabase (database, US-West) and Vercel (hosting). Stripe receives billing identifiers only. Resend handles transactional email. Sentry captures masked error telemetry.
- Salesforce, Gong, Google, and Microsoft are read-only data sources — Strataflows never sends your CRM data to them.
Infrastructure & compliance
Built on SOC 2 Type II / ISO 27001 infrastructure.
- Strataflows runs on Supabase (Postgres, Auth, Storage) and Vercel, hosted in the US-West region.
- The underlying infrastructure provider (Supabase) maintains SOC 2 Type II and ISO 27001 certifications.
- Strataflows is completing the Salesforce AppExchange Security Review.
You're in control
Disconnect, export, or delete anytime.
- Disconnect any integration at any time from Settings; you can also revoke access on the provider's side.
- Export your data whenever you want.
- Request deletion of your account and data at any time.
Security documents
Download our open security documents. The full vulnerability-scan reports are available on request.
- DownloadSecurity overview (PDF)A one-page summary of how Strataflows protects your data.
- DownloadAPI calloutsThe external endpoints Strataflows calls.
- DownloadFalse-positives explanationContext for our dynamic-scan results.
- DownloadOWASP ZAP DAST summaryA summary of our dynamic application security test.
- Available on requestCASA Tier 2 assessment (full report)Our full CASA Tier 2 security assessment, available on request.
- Available on requestOWASP ZAP DAST (full report)The complete dynamic application security scan, available on request.
Prefer email? Reach us at security@strataflows.io.
Security questions? Email security@strataflows.io.
Salesforce, Gong, Google, and Microsoft are trademarks of their respective owners. Strataflows is not affiliated with, endorsed by, or sponsored by them.