Read-only, by design

Strafi reads. It does not write. No invoice is raised, no payment taken, no record changed and no message sent on your behalf, on any connected platform.

This is not a setting you switch on. Every integration requests read scopes only, so writing is not something Strafi could do even if it tried.

You authorise access. We never see your credentials.

Every connection is made through the platform's own authorisation flow. You log in to FreeAgent, Xero, Stripe or HubSpot directly, on their site, and approve the access there. Your password never passes through Strafi and is never stored by us.

What Strafi holds is a revocable access token. You can withdraw it from inside the connected platform at any time, without contacting us and without waiting for us to act.

What Strafi stores, and why

Some products claim to hold nothing at all. Strafi keeps a record of each analysis it runs, and it is worth being straight about that, because it is how the product works rather than an oversight.

When Strafi produces a briefing, it stores the financial observations it used and the intelligence it produced. Over time this builds a picture of what is normal for your business: your typical invoice cycle, your usual cash headroom, your seasonal pattern. That history is why a briefing in month six is sharper than one in month one. Without it, every briefing would reason from a snapshot with no memory of your business.

That record is yours alone. It is never pooled with other businesses, never sold, never shared with third parties for their own purposes, and never used to build anything other than your own briefings.

Where your data lives

Strafi runs on a PostgreSQL database hosted by Railway in the EU West region, in Amsterdam, the Netherlands.

Who else processes your data

Strafi uses a small number of third parties to operate. Each one is listed here with what it does and where it is based.

ProcessorPurposeLocation
RailwayApplication hosting and databaseEU (Amsterdam)
TwilioWhatsApp message deliveryUS
AnthropicReasoning and narration in briefingsUS
ElevenLabsVoice note generationUS
ResendEmail deliveryUS
StripeSubscription billingUS / EU
Companies HousePublic filings on your clients and suppliersUK

The accounting, payment and CRM platforms you choose to connect (FreeAgent, Xero, Stripe, HubSpot) are sources rather than processors. You control that relationship directly and can end it at any time from inside those platforms.

Where data is transferred outside the UK, those transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

AI providers and your data

Strafi sends financial data to Anthropic's Claude API to produce the reasoning in your briefings. Anthropic's Commercial Terms commit that customer inputs and outputs are not used to train their models, and API data is deleted from their systems within 30 days.

Briefing text is sent to ElevenLabs to generate the voice note version. ElevenLabs allows customers to opt out of their content being used to improve its models, and Strafi has done so. A data processing agreement is in place with them.

Your controls

What Strafi does not have

Strafi is an early-stage product built by one person. It does not hold SOC 2, ISO 27001 or Cyber Essentials certification, and there has been no third-party penetration test.

We would rather say that plainly than let you find out by asking. If your practice requires a formal security assessment before recommending a tool to clients, tell us what the standard is and we will tell you honestly whether we meet it today.

Reporting a security issue

If you believe you have found a vulnerability in Strafi, email info@strafi.co with the detail. We will acknowledge within two working days. Please give us a reasonable opportunity to fix the issue before disclosing it publicly.

Contact

Scalepoint Partners Ltd, company number 15622199 · info@strafi.co

See also our privacy policy and terms of service.