Architecture & data-flow
Single-page architecture diagram. What runs where, where customer data lives, what leaves the perimeter, trust boundaries explicitly labeled, failure modes documented.
Download PDF →Security & Compliance
Srasta is self-hosted by design. Every Srasta service runs inside the customer's infrastructure perimeter — their VPC, their cluster, their on-prem hosts. Customer data (documents, prompts, responses, audit records) never leaves that perimeter in normal operation.
Srasta is committed to SOC 2 Type I attestation by Q1 2027 and SOC 2 Type II attestation by Q4 2027. Drata is our compliance automation vendor; auditor selection from Drata's partner network is finalized within two weeks of seed-close. The Type I audit period runs Q4 2026, with the Type I report issued in Q1 2027. The Type II observation period runs from Q1 2027 through Q3 2027, with the Type II report issued by end of Q4 2027. Until then, our SOC 2 Common Criteria controls matrix and architectural data-flow diagram are the operative evidence artifacts for buyer security review.
For any security review, design-partner conversation, or auditor sniff test, these four documents are the canonical sources. All four are versioned in the public repo and updated as the platform evolves.
Single-page architecture diagram. What runs where, where customer data lives, what leaves the perimeter, trust boundaries explicitly labeled, failure modes documented.
Download PDF →Every SOC 2 Common Criteria control (CC1–CC9) mapped to current Srasta implementation, evidence pointer, and a status flag (shipped / partial / planned). Honest — no over-claiming.
Download PDF →What Gandiva itself processes (license-server, support, marketing — narrow). What it does NOT process (everything else, by architecture). GDPR / UK GDPR / CCPA rights, sub-processors, retention.
View privacy policy → · PDFPre-drafted CAIQ Lite responses across all 17 CCM domains. ~45 questions, honest answers, reproducible evidence pointers. Paste-ready when a buyer's security team sends their questionnaire.
Download PDF →SRASTA_TELEMETRY=off.