Trust & security
StrideP is built and hosted in the European Union, engineered so that the strongest privacy rights anywhere are simply how the product works everywhere: for teams in Europe, the Americas, Africa, and beyond. And if your rules say the data can't leave the building, run StrideP yourself.
StrideP Cloud runs in the European Union: the application and its database are co-located in the Netherlands, so customer data is stored and processed inside the EU. Everything travels over TLS, storage is encrypted at rest by our infrastructure provider, and integration credentials carry an extra layer of application-level encryption on top.
One standard, every jurisdiction
Data is stored and processed inside the EU. Self-serve export (portability), verifiable workspace deletion (erasure), access on request, and a DPA available for your records. AI features are governed per workspace and never train on your data.
The rights California codified are StrideP defaults for every US customer: know what's stored, export it, delete it. We don't sell or share personal data with anyone, full stop.
Built on the same principles South Africa's POPIA and Nigeria's NDPR require: lawful minimal collection, purpose limitation, security safeguards, and honoring access and deletion requests.
Your rights don't depend on your geography. Export, deletion, audit, and AI controls are the same product features for every customer in every country, on every plan.
In the product today, on every plan
Full workspace export (JSON + CSV) from settings, any time, no ticket. Your data is portable by design: no lock-in, ever.
Deleting a workspace removes its data: projects, tasks, comments, files, tokens. The danger zone asks you to type the name, then it's gone.
Every database query is scoped to your workspace at the data layer. Private projects add a second scope: only added members (and workspace owners) can even see they exist.
Who did what, when, via which token: humans, AI, and agents alike, exportable as CSV. Resolved security questions come from the log, not from memory.
TLS everywhere in transit; storage encrypted at rest by our infrastructure provider; integration credentials sealed with application-level encryption on top.
Owner / Admin / Member / Guest roles enforced server-side, project-scoped guests for outsiders, scoped API tokens that are admin-only and revocable in one click.
AI & agents, governed
AI is governed per workspace: one admin toggle disables every AI feature for the whole tenant.
Your workspace content is never used to train models. AI reads your board to serve you, and that's the end of it.
Agent and API actions carry the same attribution and audit trail as humans: who, what, when, via which token.
StrideP self-hosts on your own infrastructure: one Docker image plus PostgreSQL, nothing else required. Every external service is optional with a built-in fallback, so it runs fully featured with zero outside credentials, on your cloud, your datacenter, or an air-gapped network.
The guide ships with the source: SELF-HOSTING.md. Questions or licensing? Talk to us.
On the certification path, not claimed before earned
You'll see badges here when the audits are done, not before. In the meantime, the audit log, the export button, and the delete button are things you can verify yourself in five minutes on the Free plan.