Your plant data is yours. We treat it that way.
Operational data — barrels, recipes, customers, payroll — is some of the most sensitive information a small producer holds. Strong Systems is built so that every record you create has exactly one owner: your tenant. Here's how we keep it that way.

Every record has exactly one owner.
From the filling line to outbound shipping, each scan, reading, and document is scoped to your tenant and written to an immutable audit trail — enforced at the database row level, never commingled across customers.
Encryption everywhere
TLS 1.2+ on every request, AES-256 for data at rest, and per-tenant encryption boundaries on object storage for label artwork, scans, and exports.
Per-tenant isolation
Every API call carries a tenant id that's enforced at the database row level. There is no shared cross-tenant view; even our admin console scopes reads to one tenant at a time.
Scoped API keys
Generate keys per integration, scoped to the modules they need. Rotate or revoke from Settings → Integrations without touching the rest of the workspace.
SSO on every plan
SAML and OIDC are not an upcharge. Bring Okta, Google, Microsoft Entra, or your IdP of choice. Provision and de-provision users via SCIM.
Full audit log
Every reading, transfer, sign-in, AI prompt, and admin action is recorded with actor, IP, and timestamp. Exportable to your SIEM.
Least-privilege roles
Operator, plant manager, compliance officer, bookkeeper, and owner — each role sees only what they need. Custom roles available on Plant and Multi-site.
The unglamorous work, done.
Security is a habit, not a banner. These are the recurring practices that keep your workspace boring in the best way.
Hosted on hardened US-region cloud infrastructure with 24×7 monitoring.
Backups encrypted, geographically replicated, and tested with quarterly restore drills.
Dependency and SAST scans run on every pull request. Secrets are never logged.
Penetration test on file from a third-party CREST-accredited firm; summary available under NDA.
Subprocessors disclosed in the DPA. We do not train AI models on your data.
Your data is not anyone's training set.
Strong Systems uses third-party AI providers (OpenAI, Anthropic, Gemini) strictly through their zero-retention APIs. We do not fine-tune on your data, our providers do not train on your data, and every AI prompt is logged in your audit trail with the model that handled it. Tenants can disable AI features per module from Settings.
How the AI co-pilot worksWhen something goes wrong, you hear from us first.
Our incident response runbook commits us to notify affected tenants of any confirmed security incident within 72 hours, alongside the scope, the impact, and the remediation steps. Report a suspected issue to security@strongsystems.io — PGP key on request.