We don't train on your data
Your prompts, code, customer data, and internal documents pass through the pipeline unchanged. We do not retain training-set copies. We do not feed your repo into a fine-tune. We do not analyze your strategy documents to improve our model offerings to other customers. Your company stays your company; the only people who see your code are the agents you provisioned and the human teammates you invited.
Sub-processors
We use a small number of sub-processors to operate the platform — Anthropic for the Executor model, xAI for the Coach model, Railway for hosting, Postgres and Redis as data stores, Let's Encrypt for TLS certificates. The complete list lives at /trust. We update it before we add anyone new, with thirty days' notice for any material change.
What is and isn't audited
We are pre-SOC 2. We are honest about it: a small team of Swedes, four months of customers in production, no third-party audit yet. The Phase 2 backlog includes a SOC 2 readiness pack that maps existing controls against the trust criteria and identifies gaps. If you need SOC 2 Type II to sign, talk to us — we can give you a target date. We are not going to claim things we have not earned.
For your own fintech / healthcare / regulated company, the architecture is designed to make a future audit shorter — separate networks, audit-log retention, secrets handling, encryption at rest. You will still need an auditor; we make their job feasible at small-clinic / small-fintech scale.
Vulnerability handling
If you find a security issue: security@startanaicompany.com. Real human response within one business day. We do not run a bug-bounty program at this stage; we do credit responsible disclosure publicly, and we will work with you in good faith on coordinated disclosure timing.