Sign in
Trust & security

Your leads are your business.

Everything a security review asks for, in one place: how data is protected, who can see it, where it lives, who we share it with, and the paper that backs it up. Live uptime is on the status page; the commitment is in the Service Level Agreement; the contract is the Data Processing Addendum.

Encryption

Every connection is TLS 1.2 or better. Data at rest is encrypted (AES-256) by the storage layer, and the few secrets we hold for you (connected-app tokens, pixel keys) are encrypted again with our own key before they are stored.

Tenant isolation

Each workspace is its own tenant: row-level security on every table is enforced by the database itself, not only by application code, and is proven by an automated audit in every test run.

Sign-in

Password, Google, and SAML single sign-on (Okta, Microsoft Entra, Google Workspace, OneLogin and any SAML provider), with SCIM provisioning so your identity provider adds and removes teammates. Two-factor sign-in with an authenticator app for every account; an Enterprise workspace can require it for every member.

Access and roles

Owner, admin and member roles; member edits to live routes can require approval; every action a person takes is in a workspace audit log that exports to CSV or streams to your webhook.

Lead data controls

Per-lead export and erasure, workspace-wide retention windows for untouched leads, PII redaction for connected AI assistants, and ad-consent recorded with each lead.

Operations

Production is probed from outside our network every five minutes and published on the status page. Backups are taken daily. Dependencies are audited on every change and secrets are scanned before code ships.

Enterprise uptime commitment
99.9%monthly, with service credits · priority support in 4 business hours

Questions a security review asks

Where is data stored?

In the United States (AWS us-west-2, Oregon). Video is delivered from a global edge; the data stays in the US.

Do you train AI models on our data?

No. AI features send only the text a request needs to our AI subprocessors under terms that forbid training on it, and PII redaction can mask lead details before they leave.

Is StreamAgent SOC 2 certified?

Not yet. A SOC 2 audit is planned; until it completes we answer security questionnaires directly and share the controls on this page. Ask support@streamagent.io.

GDPR and CCPA?

Our Data Processing Addendum covers GDPR Article 28, the Standard Contractual Clauses with the UK Addendum, and the CCPA service-provider terms. It is executed on request.

How do you handle a security incident?

Affected customers are notified without undue delay and within 72 hours of confirmation, with what happened, what data was involved and what we did. Incidents are posted on the status page.

Can we delete everything?

Yes. A workspace owner can delete the workspace in Settings; data is removed after a 30-day grace window, and a lead can be erased individually at any time.

Subprocessors

The vendors that process customer or lead data on our behalf, as of October 7, 2026. Enterprise customers are told of a change at least 30 days before a new subprocessor handles their data (see the Data Processing Addendum).

Amazon Web Services, Inc.

United States (us-west-2, Oregon)
Cloud infrastructure for the database, authentication and file storage (via Supabase)

All customer and lead data at rest

Supabase, Inc.

United States
Managed database, authentication and file storage

All customer and lead data at rest

Vercel, Inc.

United States (global edge for static assets)
Application hosting, edge network and serverless compute

Data in transit through the app and API; server logs

Mux, Inc.

United States
Video ingest, encoding, streaming and viewer playback analytics

Uploaded videos, playback events

Stripe, Inc.

United States
Subscription billing, and in-video payments on the customer’s own Stripe account

Billing contact, payment details (held by Stripe), purchase records

Resend, Inc.

United States
Transactional and lead-facing email delivery

Recipient addresses and message content

Anthropic, PBC

United States
AI features: the in-app support assistant, AI-generated summaries, captions and suggestions

The text of the request (transcripts, questions, workspace notes); not used to train models

OpenAI, L.L.C.

United States
AI features: text embeddings for search and retrieval

Transcript and knowledge text; not used to train models

Google LLC

United States
Google sign-in, and the AI search-visibility check (Gemini)

Sign-in identity; public page text for the visibility check

Functional Software, Inc. (Sentry)

United States
Error monitoring

Error traces with the user and workspace id; no lead data

The paperwork

Data Processing Addendum (GDPR Article 28, Standard Contractual Clauses, UK Addendum, CCPA) · Service Level Agreement · Privacy Policy · Terms of Service. To execute the DPA, request a security questionnaire, or report a vulnerability, email support@streamagent.io.