Every connection is TLS 1.2 or better. Data at rest is encrypted (AES-256) by the storage layer, and the few secrets we hold for you (connected-app tokens, pixel keys) are encrypted again with our own key before they are stored.
Your leads are your business.
Everything a security review asks for, in one place: how data is protected, who can see it, where it lives, who we share it with, and the paper that backs it up. Live uptime is on the status page; the commitment is in the Service Level Agreement; the contract is the Data Processing Addendum.
Each workspace is its own tenant: row-level security on every table is enforced by the database itself, not only by application code, and is proven by an automated audit in every test run.
Password, Google, and SAML single sign-on (Okta, Microsoft Entra, Google Workspace, OneLogin and any SAML provider), with SCIM provisioning so your identity provider adds and removes teammates. Two-factor sign-in with an authenticator app for every account; an Enterprise workspace can require it for every member.
Owner, admin and member roles; member edits to live routes can require approval; every action a person takes is in a workspace audit log that exports to CSV or streams to your webhook.
Per-lead export and erasure, workspace-wide retention windows for untouched leads, PII redaction for connected AI assistants, and ad-consent recorded with each lead.
Production is probed from outside our network every five minutes and published on the status page. Backups are taken daily. Dependencies are audited on every change and secrets are scanned before code ships.
Questions a security review asks
Where is data stored?
In the United States (AWS us-west-2, Oregon). Video is delivered from a global edge; the data stays in the US.
Do you train AI models on our data?
No. AI features send only the text a request needs to our AI subprocessors under terms that forbid training on it, and PII redaction can mask lead details before they leave.
Is StreamAgent SOC 2 certified?
Not yet. A SOC 2 audit is planned; until it completes we answer security questionnaires directly and share the controls on this page. Ask support@streamagent.io.
GDPR and CCPA?
Our Data Processing Addendum covers GDPR Article 28, the Standard Contractual Clauses with the UK Addendum, and the CCPA service-provider terms. It is executed on request.
How do you handle a security incident?
Affected customers are notified without undue delay and within 72 hours of confirmation, with what happened, what data was involved and what we did. Incidents are posted on the status page.
Can we delete everything?
Yes. A workspace owner can delete the workspace in Settings; data is removed after a 30-day grace window, and a lead can be erased individually at any time.
Subprocessors
The vendors that process customer or lead data on our behalf, as of October 7, 2026. Enterprise customers are told of a change at least 30 days before a new subprocessor handles their data (see the Data Processing Addendum).
Amazon Web Services, Inc.
United States (us-west-2, Oregon)All customer and lead data at rest
Supabase, Inc.
United StatesAll customer and lead data at rest
Vercel, Inc.
United States (global edge for static assets)Data in transit through the app and API; server logs
Mux, Inc.
United StatesUploaded videos, playback events
Stripe, Inc.
United StatesBilling contact, payment details (held by Stripe), purchase records
Resend, Inc.
United StatesRecipient addresses and message content
Anthropic, PBC
United StatesThe text of the request (transcripts, questions, workspace notes); not used to train models
OpenAI, L.L.C.
United StatesTranscript and knowledge text; not used to train models
Google LLC
United StatesSign-in identity; public page text for the visibility check
Functional Software, Inc. (Sentry)
United StatesError traces with the user and workspace id; no lead data
The paperwork
Data Processing Addendum (GDPR Article 28, Standard Contractual Clauses, UK Addendum, CCPA) · Service Level Agreement · Privacy Policy · Terms of Service. To execute the DPA, request a security questionnaire, or report a vulnerability, email support@streamagent.io.