UK Data Residency
Customer evidence and investigation data are hosted in UK infrastructure.
Primary data services operate in AWS London (eu-west-2) with UK residency controls.
Technical Security and Data Protection
Strand Intelligence is a DFIR platform that handles sensitive forensic evidence and incident findings. Security controls are built into infrastructure, access, and application design rather than added as a final step.
Customer investigation data is hosted in United Kingdom infrastructure. Frontend code is globally distributed for performance, but customer data is retrieved from UK-hosted systems.
These controls represent currently implemented safeguards. This section is intentionally technical and based on verifiable platform controls.
Customer evidence and investigation data are hosted in UK infrastructure.
Primary data services operate in AWS London (eu-west-2) with UK residency controls.
Stored application data is encrypted at rest.
PostgreSQL data is protected with AES-256 encryption-at-rest controls.
Service-to-service and user traffic is encrypted in transit.
Platform communications are served over TLS 1.2 or higher.
Privileged backend access is controlled through layered authentication.
Access combines allowlisting, client certificate requirements, credentials, and OTP MFA.
Data access boundaries are enforced at database-policy level.
Row-level security validates user session state, organization membership, and investigation-level authorization before records are returned.
Strand currently holds Cyber Essentials.
Trust-center assurance statements focus on controls that are implemented and verifiable in the current environment.
Strand is designed with separated tiers so that compromise of one layer does not inherently expose another.
Next.js web application hosted on Vercel with authenticated access via Supabase Auth.
Dedicated UK-hosted compute tier used for evidence processing and investigation workflows.
PostgreSQL and ClickHouse data stores, each scoped to its function and secured independently.
Strand control statements are organized into practical implementation families used during security diligence.
Controls governing privileged access to backend infrastructure and investigation data.
4 controls published
Controls focused on confidentiality, isolation, and residency of investigation data.
4 controls published
Controls reducing exposure of backend services and protecting service perimeters.
4 controls published
Identity, session, and API-layer controls in the application stack.
4 controls published
Monitoring, key management, and response-oriented operational controls.
4 controls published
Access public documentation, processor disclosures, and change history from the sections below.
Control families and implementation details.
Open sectionPublic trust and legal documentation.
Open sectionThird-party service providers and data scope.
Open sectionTechnical buyer and security assurance FAQ.
Open sectionTrust-center and policy change log.
Open sectionSecurity media and briefings.
Open section