Trust & security

Your team's work.
Yours alone.

StrideP is built and hosted in the European Union, engineered so that the strongest privacy rights anywhere are simply how the product works everywhere: for teams in Europe, the Americas, Africa, and beyond. And if your rules say the data can't leave the building, run StrideP yourself.

Made in Europe Data hosted in the EU (Netherlands) Self-hosting available

Where your data lives

StrideP Cloud runs in the European Union: the application and its database are co-located in the Netherlands, so customer data is stored and processed inside the EU. Everything travels over TLS, storage is encrypted at rest by our infrastructure provider, and integration credentials carry an extra layer of application-level encryption on top.

One standard, every jurisdiction

Your rights, everywhere.

European Union & EEA

GDPR

Data is stored and processed inside the EU. Self-serve export (portability), verifiable workspace deletion (erasure), access on request, and a DPA available for your records. AI features are governed per workspace and never train on your data.

United States

CCPA / CPRA-aligned

The rights California codified are StrideP defaults for every US customer: know what's stored, export it, delete it. We don't sell or share personal data with anyone, full stop.

Africa

POPIA · NDPR-aligned

Built on the same principles South Africa's POPIA and Nigeria's NDPR require: lawful minimal collection, purpose limitation, security safeguards, and honoring access and deletion requests.

Everywhere else

One global standard

Your rights don't depend on your geography. Export, deletion, audit, and AI controls are the same product features for every customer in every country, on every plan.

In the product today, on every plan

Controls that are shipped, not promised.

One-click export & backups

Full workspace export (JSON + CSV) from settings, any time, no ticket. Your data is portable by design: no lock-in, ever.

Verifiable deletion

Deleting a workspace removes its data: projects, tasks, comments, files, tokens. The danger zone asks you to type the name, then it's gone.

Tenant isolation on every query

Every database query is scoped to your workspace at the data layer. Private projects add a second scope: only added members (and workspace owners) can even see they exist.

Full audit trail

Who did what, when, via which token: humans, AI, and agents alike, exportable as CSV. Resolved security questions come from the log, not from memory.

Encrypted secrets

TLS everywhere in transit; storage encrypted at rest by our infrastructure provider; integration credentials sealed with application-level encryption on top.

Least-privilege access

Owner / Admin / Member / Guest roles enforced server-side, project-scoped guests for outsiders, scoped API tokens that are admin-only and revocable in one click.

AI & agents, governed

A real off switch

AI is governed per workspace: one admin toggle disables every AI feature for the whole tenant.

No training on your data

Your workspace content is never used to train models. AI reads your board to serve you, and that's the end of it.

Agents are accountable

Agent and API actions carry the same attribution and audit trail as humans: who, what, when, via which token.

If the data can't leave the building, run it yourself.

StrideP self-hosts on your own infrastructure: one Docker image plus PostgreSQL, nothing else required. Every external service is optional with a built-in fallback, so it runs fully featured with zero outside credentials, on your cloud, your datacenter, or an air-gapped network.

docker compose -f docker-compose.selfhost.yml up -d
Your region, your residency rules Works with no external services Same product, same updates

The guide ships with the source: SELF-HOSTING.md. Questions or licensing? Talk to us.

On the certification path, not claimed before earned

  • SOC 2 Type II (controls program, then audit)
  • ISO 27001
  • MFA / passkeys
  • Postgres row-level-security backstop beneath app-layer isolation
  • SIEM streaming for enterprise audit

You'll see badges here when the audits are done, not before. In the meantime, the audit log, the export button, and the delete button are things you can verify yourself in five minutes on the Free plan.