StraitForward
PrivacyStart security review

Trust Center

Security controls for live claims work.

Before a live or unredacted claim file moves, StraitForward and the client complete a data and security schedule covering the transfer route, processors, region, access, permitted use, retention, deletion and incident contacts.

Last reviewed 9 August 2026Independent assurance is not currently claimedNo live transfer before the readiness gate

Readiness gate

The control record comes before the file.

No live or unredacted claim file is accepted until the engagement data schedule is complete and the approved route is confirmed.

01

Approved transfer

The client-approved intake and return route is recorded before files move. Confidential claim documents should not be sent through an unapproved channel.

02

Processor and region record

Every material provider, processing purpose, region, retention term and transfer condition is entered in the engagement register.

03

Named access

Authorized users, roles, workspace boundary, MFA requirement, download rule and access-review owner are agreed for the engagement.

04

Provider and model terms

Any software or model route must be disclosed and its data-use and retention terms verified before it receives client content.

05

Retention and deletion

Active files, derived outputs, backups, legal holds, deletion timing and confirmation evidence receive named owners and written rules.

06

Incident and recovery record

Security contacts, escalation, customer notification, backup handling and recovery expectations are completed before live-data acceptance.

Framework status

Reference frameworks, stated without borrowed assurance.

SOC 2 and ISO/IEC 27001 are used as review references. StraitForward does not claim third-party certification or attestation.

FrameworkStatusCoverage
SOC 2 Trust Services CriteriaReference only

No SOC 2 attestation is claimed. Selected criteria can structure the customer control review.

ISO/IEC 27001Reference only

No ISO/IEC 27001 certification is claimed. The framework can inform governance and risk review.

Privacy and data protectionContract-specific

Controller and processor roles, lawful basis, providers, transfers and data-subject support are documented for the applicable engagement.

Customer security reviewBefore transfer

Architecture, data flow, questionnaires, evidence requests and open remediation items are reviewed before live-data acceptance.

Operating detail

Evidence before assurance.

Current assurance

No public third-party certification or attestation is claimed. A cloud provider's certification is not presented as StraitForward's own.

Client-specific schedule

Data categories, providers, regions, access, retention, deletion and incident responsibilities must be marked ready before a live or unredacted file is accepted.

Human review and software use

Material evidence, calculations and commercial judgment remain subject to named analyst review. Every software or model route that receives client content must appear in the processor register.

Open items stay visible

An unresolved provider, region, access, retention, deletion or incident-control item blocks live-data intake rather than being hidden behind general security language.

Diligence record

Complete the evidence for your engagement.

The review pack distinguishes ready controls, open items and client decisions.

  • Data Processing & Security Schedule
  • Processor and residency register
  • Architecture and data-flow review
  • Authorized-access record
  • Retention and deletion plan
  • Incident contacts and escalation path
  • DPA and transfer terms where required
  • SIG, CAIQ and customer questionnaire support
Start a security review

Responsible disclosure

Report a security concern.

How to report

Email hello@straitforward.io with the affected page or service, steps to reproduce and potential impact. Do not attach a live claim file.

Good-faith handling

Reports are reviewed directly and coordinated privately. Avoid accessing customer data, disrupting service or publishing details before there has been reasonable time to investigate.