StralaTrust Center

Trust Center

Security, Compliance & Governance

Strala administers claims on behalf of carriers, self-insured programs, and captives. This page is the standing record of how that responsibility is secured, attested, and governed. Documents are available under NDA via request access.

Last updated —

Compliance & attestations

AICPA SOC for Service Organizations badge

SOC 1 Type 1

Attested.

Independent auditor's report on the design of controls relevant to financial reporting. Report available under NDA via request access.

AICPA SOC for Service Organizations badge

SOC 2 Type 2

Attested.

Independent auditor's report on the operating effectiveness of security controls over time. Report available under NDA via request access.

HIPAA compliance logo

HIPAA

Compliant.

Safeguards for protected health information in claims handling. BAA available in contracting.

Regulatory standing

Strala is a licensed third-party administrator in all 50 U.S. states.

A licensed adjuster is assigned to every file. Statutory reporting obligations, including Medicare Section 111, are tracked as measured internal KPIs. Every file carries a full activity trail of actions, timestamps, and decisions, which supports regulator examinations and client audit.

Strala maintains errors & omissions, general liability, and cyber coverage at limits sized for enterprise programs; certificates of insurance are available via request access.

AI governance

A human signs every decision.

The AI never releases a payment, closes a file, or issues a denial on its own; a licensed adjuster makes the final call on every file.

Client data never trains models.

AI accounts are locked; data is never used to train models, ours or anyone's.

One client, one warehouse.

Each client's data lives in its own warehouse — nothing is pooled across clients or shared with competitors.

No single point of failure.

Multiple model providers are used in parallel; if one goes down, claims handling continues.

Model-provider details and AI-control documentation are available via request access.

Security practices

Data protection

  • Encryption in transit and at rest
  • Per-client data segregation
  • Data deleted on request

Access

  • SSO and MFA for internal systems
  • Role-based access
  • Access reviews daily

Operations

  • Logging and monitoring on production systems
  • Incident response plan maintained
  • Background checks on employees

Assurance

  • Annual third-party penetration testing
  • SOC audits (see compliance & attestations)
  • Vendor risk review of subprocessors

Subprocessors

Core infrastructure subprocessors are listed below; the complete list, including model providers, is available via request access.

Amazon Web Services logoAmazon Web Services
Cloud Infrastructure & Platform Services
United States
GCP Service logoGCP Service
Cloud Infrastructure & Platform Services
United States
Cloudflare logoCloudflare
Network & Edge Security
Global

Resources

SOC 1 Type 1 report

Auditor's report on the design of controls relevant to financial reporting.

SOC 2 Type 2 report

Auditor's report on the operating effectiveness of security controls over time.

Penetration test summary

Summary of the most recent third-party penetration test.

Data Processing Agreement (template)

Strala's standard data processing terms.

Certificates of insurance (E&O, GL, cyber)

Current certificates for errors & omissions, general liability, and cyber.

Full subprocessor list (incl. model providers)

Complete subprocessor register, including AI model providers.

AI-control documentation

Model-provider details and the controls governing AI use on claim files.

All documents are shared under NDA after approval — typically within one business day.

Questions