Privacy Policy
Who we are
This Privacy Policy is issued by OmniSecure, Inc., a Delaware corporation ("Strix", "we", "us"), which operates the Strix platform and the website strix.ai. Strix is an autonomous, AI-driven penetration testing platform delivered as software-as-a-service (SaaS) at app.strix.ai, including the Strix Cloud MCP server that connects Strix to AI assistants and to third-party cloud accounts such as Google Cloud. This policy also covers the Strix Startup Program and customer support.
Controller: OmniSecure, Inc., 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States.
Data Protection Officer: privacy@usestrix.com
EU representative (Art. 27 GDPR): EDPO, Avenue Huart Hamoir 71, 1030 Brussels, Belgium. You can contact EDPO through its online request form at https://edpo.com/gdpr-data-request/.
UK representative (Art. 27 UK GDPR): EDPO UK Ltd, Unit 33, Waterside, Schooner Court, 44-48 Wharf Road, London N1 7UX, United Kingdom. You can contact EDPO UK regarding matters relating to the UK GDPR, or complaints under section 164A of the Data Protection Act 2018, through its online request and complaint form at https://edpo.com/uk-gdpr-data-request/.
Our Article 27 representative compliance certificates can be verified here: EU representative certificate and UK representative certificate.
Scope and application
This policy applies to personal information we process about website visitors, registered users of the Strix platform, customer personnel, prospects, and business contacts. It applies whether you are browsing strix.ai, using the platform as a registered user, or engaging with us as a customer.
Customer Data and our role as processor
When a customer uses the Strix platform to test its own applications, code repositories, cloud projects, or infrastructure, the data the customer submits or connects, and the findings Strix generates from it ("Customer Data"), are processed on the customer's documented instructions under our customer agreement and, where applicable, a Data Processing Agreement (DPA) or Business Associate Agreement (BAA). For Customer Data, the customer is the controller and Strix is the processor. We do not use Customer Data for our own purposes, including to train, fine-tune, or improve models, except as the customer agreement expressly permits. If you are an individual whose personal information is contained in a customer's Customer Data, please direct requests to that customer; we will assist them in responding.
For the personal information described in the rest of this policy (for example account, billing, website, and marketing data), Strix is the controller.
Personal information we collect
We collect the following categories of personal information:
Identity and contact data: first and last name, email address, telephone number, company name and role. Collected when you create an account, request a demo, contact support, or apply to the Strix Startup Program.
Account and authentication data: login credentials, authentication tokens, single sign-on identifiers (including your Google Account name and email if you sign in with Google), organization membership, and role within your organization.
Payment information: billing name, billing address, and payment card details. Card details are collected and stored by our payment processor, Stripe; Strix does not store full card numbers.
Device and technical data: IP address, IP-based approximate location, device identifiers, operating system and version, browser type and language.
Usage and interaction data: pages visited, features used, actions taken in the platform, timestamps, and email engagement such as opens and link clicks in messages we send you.
Communications: the content of support requests, feedback, and correspondence with us.
Connected account data: information received when you connect a third-party account such as Google Cloud, described in the section "Google Account and Google Cloud data" below.
We collect this information directly from you, automatically from your device and your use of our services, and from third parties such as identity providers you choose to sign in with, our payment processor, and publicly available business sources.
We do not knowingly collect special categories of personal data (such as health, biometric, or genetic data) or government identification numbers through our website or platform.
How we use personal information and our lawful bases
| Purpose | Data used | Lawful basis (GDPR) |
|---|---|---|
| Providing the Strix platform, including authentication, account administration, running security tests you request, and delivering findings | Identity, account, usage, connected account data | Performance of a contract |
| Billing, payment processing, and account management | Identity, payment information | Performance of a contract; legal obligation (tax and accounting) |
| Customer support and responding to inquiries | Identity, communications, account, usage | Performance of a contract; legitimate interest |
| Security, fraud prevention, abuse detection, and protecting our systems and customers | Device, usage, account data | Legitimate interest; legal obligation |
| Service communications such as onboarding, product updates, and security notices | Identity, account, email engagement | Performance of a contract; legitimate interest |
| Marketing communications about our products and events | Identity, contact, email engagement | Consent where required; otherwise legitimate interest, with the right to opt out at any time |
| Analytics and performance measurement of our website and platform | Device, usage data, cookies | Consent (non-essential cookies); legitimate interest (aggregate platform analytics) |
| Research and development, and improving our services, using aggregated or de-identified data | Usage data, de-identified Customer Data as permitted by the customer agreement | Legitimate interest |
| Compliance with legal obligations, and establishing or defending legal claims | Any of the above as required | Legal obligation; legitimate interest |
Where we rely on legitimate interest, we have balanced that interest against your rights and you may object as described under "Your rights". Where we rely on consent, you may withdraw it at any time.
Google Account and Google Cloud data
Strix lets customers connect a Google Cloud project to the Strix platform so that Strix can read selected resources in that project as part of the security testing you request. This section describes how Strix handles information received from Google when you use that feature. It supplements the rest of this Privacy Policy.
What Google user data Strix accesses
When you connect Google Cloud to Strix, you sign in with your Google Account and grant Strix the Google Cloud Platform scope (https://www.googleapis.com/auth/cloud-platform). Strix uses that permission during a one-time setup that you start, and accesses only the following:
Your basic Google Account profile: name and email address, used to identify you and your Strix account.
The list of Google Cloud projects your account can access, so that you can choose which project to connect.
In the project you select, Strix acts as you once to create a dedicated read-only service account named strix-reader, grant it read-only roles only for the Google Cloud services you choose, and authorize Strix's own service account (strix-scanner) to impersonate strix-reader and to delete it when you disconnect.
The roles granted to strix-reader are roles/mcp.toolUser and, for each service you select: Cloud Run roles/run.viewer; Compute Engine roles/compute.viewer; Cloud Storage roles/storage.viewer and roles/storage.objectViewer; Google Kubernetes Engine roles/container.viewer; Firestore roles/datastore.viewer. These roles allow Strix to read resource configuration and metadata and, for Cloud Storage and Firestore, the contents of objects and documents in the buckets and databases you selected. Strix does not create, modify, or delete resources in your project other than the strix-reader service account and its role bindings.
Strix requests online access only, so Google does not issue a refresh token. Your sign-in token is stored encrypted for at most ten minutes while setup runs, is deleted when setup completes or the session expires, and is never reused. At scan time, Strix authenticates as its own service account and obtains a short-lived (one-hour) token for strix-reader, which Strix's Google MCP server uses to read the resources you selected. You are not involved at that point, and Strix never uses your personal Google credentials again.
Strix requests the full Google Cloud Platform scope because creating a service account and setting IAM policy cannot be performed with a read-only scope. Strix does not request access to Gmail, Google Drive, Google Calendar, or other Google Workspace data.
How Strix uses Google user data
Strix uses the information above solely to:
Identify you and associate the connected project with your Strix organization.
Set up strix-reader and the permissions you approved.
Perform the security testing and vulnerability detection you request against the connected project, and present the findings to you and your team in the Strix platform.
Maintain security, prevent abuse, and comply with law.
Strix does not use Google user data for advertising, does not sell it, does not share it with data brokers or information resellers, and does not use it to determine creditworthiness or for lending. Strix does not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
AI processing. Strix performs security testing using AI agents. During a scan, the information read from your project (such as IAM policies, Cloud Run configurations, bucket listings, and the contents of objects the agent reads) is provided to the AI model as context so that it can analyze your environment. Before it is sent, Strix redacts common credential patterns (such as API keys, access tokens, passwords, and authorization headers) and wraps the content in an untrusted-data guard so that the model treats it as data rather than instructions. The models are served by the third-party AI providers listed under "Data sharing and disclosure". This processing is performed solely to carry out the scan you requested and is covered by the Customer Data terms of this policy and our customer agreement.
Strix's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
If Strix changes how it uses Google user data, we will update this policy and ask for your consent before using the data in a new way.
How Strix shares Google user data
Strix does not sell Google user data and does not share it with third parties except:
Service providers that host or process data for Strix, only as needed to provide the features you use and under written agreements limiting their use of the data. These are listed under "Data sharing and disclosure" below.
For security purposes, such as investigating abuse or a security incident.
To comply with applicable law, regulation, legal process, or enforceable governmental request.
As part of a merger, acquisition, or sale of assets, only after obtaining your explicit prior consent.
Strix personnel do not read your Google Cloud data unless you have asked for support and given permission, it is necessary for security purposes, it is required by law, or the data has been aggregated and anonymized for internal operations.
How Strix protects Google user data
Encryption in transit using TLS and at rest using AES-256.
Your Google OAuth token is used only during the one-time setup, is held encrypted for at most ten minutes, and is never reused. No refresh token is requested. Tokens used to read your project at scan time are issued to strix-reader, expire after one hour, and are never transmitted in plaintext.
Access to production systems is restricted to authorized personnel on a least-privilege basis and protected by multi-factor authentication.
Common credential patterns are redacted from project data before it is provided to AI models, and that data is wrapped in an untrusted-data guard to protect against prompt injection.
Logging and monitoring of production access, vulnerability management, and regular independent penetration testing. Strix maintains an information security program aligned to SOC 2 and ISO/IEC 27001.
Retention and deletion of Google user data
Your Google OAuth token is deleted when setup completes or within ten minutes of sign-in, whichever is first, and is not retained.
Your Google Account name and email are retained as part of your Strix account for as long as your account is active.
Configuration data and findings read from your project through strix-reader are Customer Data and are retained for the duration of your subscription so that you can track remediation over time, unless you delete them earlier.
When you click disconnect in Strix, Strix deletes the strix-reader service account from your project, removes the connection from your Strix account, and stops accessing the project. If Strix is unable to delete strix-reader (for example because its permissions were changed), we tell you how to remove it yourself. You can also revoke all Strix access yourself at any time in the Google Cloud console by removing the role binding that lets Strix's service account impersonate strix-reader, or by deleting strix-reader. You can review or revoke the original sign-in grant at https://myaccount.google.com/permissions.
If you delete your Strix account or your subscription ends, associated Customer Data is deleted within 30 days, except where retention is required by law.
You can request deletion of your Google user data at any time by emailing privacy@usestrix.com.
Data storage and protection
Data storage
Personal information is stored on secure servers located in the United States, operated by our hosting providers Amazon Web Services and Vercel. For services that require international data transfer, we ensure that such transfers comply with applicable law as described under "International data transfers".
Data protection measures
Encryption: data is encrypted in transit using TLS and at rest using AES-256.
Access control: access to personal information is limited to authorized personnel with a legitimate business need, enforced through least-privilege roles and multi-factor authentication, and reviewed regularly.
Security audits and monitoring: we perform vulnerability management, regular independent penetration testing, and continuous monitoring of our systems for unusual activity. Strix maintains an information security program aligned to SOC 2 and ISO/IEC 27001.
Incident response: we maintain an incident response plan. If a personal data breach occurs, we will notify affected customers, individuals, and regulators without undue delay and as required by applicable law and our contracts.
Data sharing and disclosure
We do not sell personal information. We share it only as follows:
Service providers (subprocessors)
We share personal information with service providers that perform services on our behalf, on a need-to-know basis and under written agreements that prohibit them from using it for any other purpose. Our current categories and providers are:
Cloud hosting, database, and infrastructure: Amazon Web Services; Vercel; Supabase (database and file storage); Convex (agent run data).
Payment processing: Stripe.
Transactional and marketing email delivery: Resend.
Source code hosting and CI: GitHub.
Business productivity and support tooling: Google Workspace; Slack.
AI model providers used to perform security testing and generate text in the platform: OpenRouter (which routes requests to the model vendors Z.ai, Moonshot AI, DeepSeek, and OpenAI), OpenAI, and Perplexity (web search used by the testing agent). Customer Data, including data read from connected Google Cloud projects, is processed by these providers only to perform the tests you request.
Consent management and website analytics: Usercentrics and the services listed in our cookie banner.
Other disclosures
Legal requirements: where required by law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of Strix, our customers, or others.
Security: to investigate, prevent, or respond to fraud, abuse, or security incidents.
Business transfers: to a successor in connection with a merger, acquisition, or sale of assets. For Google user data, only after obtaining your explicit prior consent.
Aggregated or de-identified data that does not identify you.
Data processing agreements
When we share personal data with service providers, we do so under Data Processing Agreements that require them to implement appropriate technical and organizational measures and to process the data only on our instructions, in accordance with GDPR and other applicable data protection laws.
Data retention and deletion
We retain personal information only for as long as needed for the purposes described in this policy, unless a longer period is required by law. When a retention period ends, we delete or de-identify the data.
| Data | Retention period |
|---|---|
| Account and profile data | For the life of your account, then deleted within 30 days of account closure or subscription termination |
| Customer Data (test targets, connected project configuration, findings) | For the life of the subscription (or until you delete them), then deleted within 30 days of termination, or earlier on the customer's instruction |
| Google OAuth tokens | Not stored; used only during connection setup |
| Billing and transaction records | 7 years, to meet tax and accounting obligations |
| Security, access, and audit logs | Up to 12 months |
| Support communications | 3 years after the request is closed |
| Marketing contact data and email engagement | Until you unsubscribe or object, then suppressed; inactive contacts deleted after 24 months |
| Website analytics and cookie data | As stated in our Cookie Policy for each cookie |
You may request deletion of your personal information at any time by emailing privacy@usestrix.com. Customers may delete their account and Customer Data through the platform or by contacting support@strix.ai. Database backups are retained for 7 days, so data deleted from production is removed from all backups within a further 7 days. Confirmation of deletion is available to customers on request.
International data transfers
Strix is based in the United States and processes personal information there. If you are located in the European Economic Area, the United Kingdom, or Switzerland, your personal information is transferred outside your jurisdiction. We protect these transfers using the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary measures as appropriate. You may request a copy of the relevant safeguards by contacting privacy@usestrix.com.
Your rights
Depending on where you live, you have the following rights regarding your personal information, in accordance with the General Data Protection Regulation (GDPR), the UK GDPR, and other applicable laws:
Right of access (Art. 15 GDPR): to request access to the personal information we hold about you and information about how we process it.
Right to rectification (Art. 16 GDPR): to request correction or completion of inaccurate or incomplete personal information.
Right to erasure (Art. 17 GDPR): to request deletion of your personal information when it is no longer necessary for the purposes for which it was collected, among other circumstances.
Right to restriction of processing (Art. 18 GDPR): to request that we restrict processing under certain conditions.
Right to data portability (Art. 20 GDPR): to receive your personal information in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to object (Art. 21 GDPR): to object to processing based on legitimate interest, including processing for direct marketing.
Right to withdraw consent (Art. 7(3) GDPR): where processing is based on consent, to withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Right to lodge a complaint (Art. 77 GDPR): with a supervisory authority in your country of residence, place of work, or where an alleged infringement occurred. In the UK, this is the Information Commissioner's Office.
Exercising your rights
To exercise any of these rights, contact us at privacy@usestrix.com, or through our EU or UK representative listed under "Who we are". We will respond within the timeframes required by applicable law. We may need to verify your identity before acting on your request. If your request concerns Customer Data processed on behalf of a Strix customer, we will refer it to that customer and assist them in responding.
Cookies and tracking technologies
We use cookies and similar technologies on strix.ai and in the Strix platform. Cookies are small data files placed on your device that enable us to remember your preferences and collect information about your website usage. Tracking technologies such as web beacons and pixel tags help us understand how you interact with our site and our emails.
How we use these technologies
Essential cookies: necessary for the website and platform to function, such as authentication, security, and remembering your consent choices. They do not require consent.
Performance and analytics cookies: collect information about how visitors use our website, which pages are visited most frequently, and whether errors occur, to help us improve. We use Umami and PostHog. PostHog may also record how you interact with pages (session replay, heatmaps, and click tracking); form inputs are masked in these recordings.
Functional cookies: enable enhanced functionality and personalization, such as remembering your preferences.
Advertising and targeting cookies: used to measure the effectiveness of our advertising campaigns and to deliver advertisements more relevant to you. We use Google Ads conversion and remarketing tags, the X (Twitter) pixel, and the Scarf pixel. We also use RB2B, a service that attempts to identify business visitors to our site by matching device and network signals to a business contact profile; this is used only for visitors in the United States and only after consent.
Your choices and consent
On your first visit, our website presents a cookie consent banner where you can accept all cookies, reject non-essential cookies, or customize your preferences by category. Non-essential cookies are not set until you consent. You can change your choices at any time using the "Privacy settings" link in the website footer.
For a list of the cookies we use, their purposes, and durations, see our Cookie Policy.
Children's privacy
Our website and services are intended for business use by adults. They are not directed to anyone under the age of 18, and we do not knowingly collect personal information from anyone under 18. If you believe that a person under 18 has provided us with personal information, contact us at privacy@usestrix.com and we will delete it promptly.
Additional information for United States residents
If you are a resident of California or another U.S. state with a comprehensive privacy law, you have the following rights in addition to those described above, subject to applicable exceptions:
Right to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for collection, and the categories of third parties with whom we share it. This information is set out in this policy.
Right to delete personal information we have collected from you.
Right to correct inaccurate personal information.
Right to opt out of sale or sharing. We do not sell personal information. We may "share" personal information (as defined by the California Consumer Privacy Act) with advertising and analytics partners, including Google, X (Twitter), and RB2B, through advertising cookies and pixels for cross-context behavioral advertising. You can opt out by rejecting advertising cookies in our cookie banner or through the "Privacy settings" link in the website footer. We honor Global Privacy Control signals.
Right to limit use of sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted by law.
Right to non-discrimination for exercising your rights.
Submitting requests: email privacy@usestrix.com. We will verify your request by matching the information you provide against our records. You may designate an authorized agent to submit a request on your behalf.
Appeals: if we decline to act on your request, you may appeal within 60 days of our response by emailing privacy@usestrix.com with your original request, the date of our response, and why you believe the decision was incorrect. We will respond to your appeal as required by law.
In the preceding 12 months we have collected the categories of personal information listed under "Personal information we collect" and disclosed them for business purposes to the categories of service providers listed under "Data sharing and disclosure". We have not sold personal information.
Direct marketing and communications
We may send you marketing communications by email about our products, services, and events. Where required by law we obtain your opt-in consent first. Every marketing email includes an unsubscribe link, and you may opt out at any time; we will honor your request promptly. Service communications necessary to operate your account (such as security notices, billing, and changes to terms) are not marketing and will continue while you hold an account.
Policy updates and changes
We may update this policy to reflect changes in law, industry standards, or our business. When we make significant changes that affect your rights or the way we handle your personal information, we will notify you by email, by notice on our website or platform, or other appropriate means, and we will update the effective date at the top of this page. Where a change concerns how we use data received from Google, we will ask for your consent before applying it. Your continued use of our services after other changes take effect signifies acceptance of the updated policy.
Contact us
OmniSecure, Inc.
131 Continental Dr, Suite 305
Newark, Delaware 19713, United States
Email: privacy@usestrix.com
Support: support@strix.ai
EU representative: EDPO, Avenue Huart Hamoir 71, 1030 Brussels, Belgium, https://edpo.com/gdpr-data-request/
UK representative: EDPO UK Ltd, Unit 33, Waterside, Schooner Court, 44-48 Wharf Road, London N1 7UX, United Kingdom, https://edpo.com/uk-gdpr-data-request/
