Strike Graph platform
Evidence items stored in your Strike Graph platform are used for audit purposes only. Whether you have opted to engage with our internal audit team or work with an external audit firm, rest assured that your evidence is secure, only viewed by those necessary, and never shared. You can get more information on Strike Graph’s security and data management practices in our SOC 2 report (request access here).
You can also limit your own company’s user access to uploaded evidence by defining their role as either a contributor or manager via our roles and permissions feature.
Strike Graph staff
In addition to our GRC platform being secure, all Strike Graph staff signed a non disclosure agreement upon hire. We will never share your data.
What if an evidence item seems too sensitive to provide?
If an evidence item in your organization’s repository requests information that you are uncomfortable providing, it is likely acceptable to redact certain information from these documents. This often comes up with employee performance evaluations, background checks, and, in some cases, sensitive security configuration items and network diagrams.
If you are hesitant to upload even a redacted copy, your Customer Success Manager can set up a screen-sharing session when it comes time for the audit. In this way, you can showcase evidence to the audit team without retaining a file or screenshot within the Strike Graph platform.
Questions?
Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.
