Approved transfer
The client-approved intake and return route is recorded before files move. Confidential claim documents should not be sent through an unapproved channel.
Trust Center
Before a live or unredacted claim file moves, StraitForward and the client complete a data and security schedule covering the transfer route, processors, region, access, permitted use, retention, deletion and incident contacts.
Readiness gate
No live or unredacted claim file is accepted until the engagement data schedule is complete and the approved route is confirmed.
The client-approved intake and return route is recorded before files move. Confidential claim documents should not be sent through an unapproved channel.
Every material provider, processing purpose, region, retention term and transfer condition is entered in the engagement register.
Authorized users, roles, workspace boundary, MFA requirement, download rule and access-review owner are agreed for the engagement.
Any software or model route must be disclosed and its data-use and retention terms verified before it receives client content.
Active files, derived outputs, backups, legal holds, deletion timing and confirmation evidence receive named owners and written rules.
Security contacts, escalation, customer notification, backup handling and recovery expectations are completed before live-data acceptance.
Framework status
SOC 2 and ISO/IEC 27001 are used as review references. StraitForward does not claim third-party certification or attestation.
No SOC 2 attestation is claimed. Selected criteria can structure the customer control review.
No ISO/IEC 27001 certification is claimed. The framework can inform governance and risk review.
Controller and processor roles, lawful basis, providers, transfers and data-subject support are documented for the applicable engagement.
Architecture, data flow, questionnaires, evidence requests and open remediation items are reviewed before live-data acceptance.
Operating detail
No public third-party certification or attestation is claimed. A cloud provider's certification is not presented as StraitForward's own.
Data categories, providers, regions, access, retention, deletion and incident responsibilities must be marked ready before a live or unredacted file is accepted.
Material evidence, calculations and commercial judgment remain subject to named analyst review. Every software or model route that receives client content must appear in the processor register.
An unresolved provider, region, access, retention, deletion or incident-control item blocks live-data intake rather than being hidden behind general security language.
Diligence record
The review pack distinguishes ready controls, open items and client decisions.
Responsible disclosure
Email hello@straitforward.io with the affected page or service, steps to reproduce and potential impact. Do not attach a live claim file.
Reports are reviewed directly and coordinated privately. Avoid accessing customer data, disrupting service or publishing details before there has been reasonable time to investigate.