
SOC 1 Type 1
Attested.
Independent auditor's report on the design of controls relevant to financial reporting. Report available under NDA via request access.
Trust Center
Strala administers claims on behalf of carriers, self-insured programs, and captives. This page is the standing record of how that responsibility is secured, attested, and governed. Documents are available under NDA via request access.
Last updated ——

Attested.
Independent auditor's report on the design of controls relevant to financial reporting. Report available under NDA via request access.

Attested.
Independent auditor's report on the operating effectiveness of security controls over time. Report available under NDA via request access.

Compliant.
Safeguards for protected health information in claims handling. BAA available in contracting.
Strala is a licensed third-party administrator in all 50 U.S. states.
A licensed adjuster is assigned to every file. Statutory reporting obligations, including Medicare Section 111, are tracked as measured internal KPIs. Every file carries a full activity trail of actions, timestamps, and decisions, which supports regulator examinations and client audit.
Strala maintains errors & omissions, general liability, and cyber coverage at limits sized for enterprise programs; certificates of insurance are available via request access.
A human signs every decision.
The AI never releases a payment, closes a file, or issues a denial on its own; a licensed adjuster makes the final call on every file.
Client data never trains models.
AI accounts are locked; data is never used to train models, ours or anyone's.
One client, one warehouse.
Each client's data lives in its own warehouse — nothing is pooled across clients or shared with competitors.
No single point of failure.
Multiple model providers are used in parallel; if one goes down, claims handling continues.
Model-provider details and AI-control documentation are available via request access.
Data protection
Access
Operations
Assurance
Core infrastructure subprocessors are listed below; the complete list, including model providers, is available via request access.
Amazon Web Services
GCP Service
CloudflareSOC 1 Type 1 report
Auditor's report on the design of controls relevant to financial reporting.
SOC 2 Type 2 report
Auditor's report on the operating effectiveness of security controls over time.
Penetration test summary
Summary of the most recent third-party penetration test.
Data Processing Agreement (template)
Strala's standard data processing terms.
Certificates of insurance (E&O, GL, cyber)
Current certificates for errors & omissions, general liability, and cyber.
Full subprocessor list (incl. model providers)
Complete subprocessor register, including AI model providers.
AI-control documentation
Model-provider details and the controls governing AI use on claim files.
All documents are shared under NDA after approval — typically within one business day.