Security & privacy

Protect the deals, documents, and relationships that make your firm.

Offering memoranda, rent rolls, NDAs, and client files do not belong in a consumer chatbot. StratiqAI keeps your firm's work inside a private environment built for commercial real estate, so your team can use AI without putting confidential deals at risk.

Your firm's work stays yours

Deal files, CRM notes, and conversation history live in your private StratiqAI environment, not in a shared pool with other companies.

Built for NDAs and listings

Honor confidentiality on OMs, LOIs, tenant financials, and commission details with a clear answer for where a document was handled.

People stay in control

Your brokers and analysts approve consequential actions. AI prepares the work; your team owns the decisions and the client relationship.

Standards your clients expect

Designed to align with SOC 2 and ISO 27001 control themes so security and compliance conversations have a straight answer.

Why this matters on the desk

Your competitive advantage is confidential. Treat it that way.

In commercial real estate and finance, the value is in the relationships and the information: who is selling, what the rent roll shows, what the buyer will pay, and what your client asked you not to share. When that material lands in a free or consumer AI tool, it can leave the firm under terms you did not negotiate, and that your NDA may not allow.

StratiqAI exists so your producers can move faster with AI while your firm still honors listing agreements, NDAs, and client expectations. Sensitive materials stay inside your dedicated environment. You can tell a client, a partner, or an auditor where the work happened, and that another brokerage cannot see it.

How StratiqAI helps you

Document security that matches how CRE actually works.

Paste or upload the materials you already handle every week: offering memoranda, rent rolls, leases, underwriting packs, and portfolio updates, without routing them through a mass-market chatbot. Agents work with the CRM and deal tools your desk already uses, so adoption does not start with a rip-and-replace project.

Choose from 50+ AI models, or bring your own provider credentials under terms your firm already trusts. That makes day-to-day work simpler: brokers and analysts get help screening deals, organizing diligence, and drafting updates, while compliance and leadership get a story they can stand behind.

Why firms make this mandatory

If your team is already using AI, you need a controlled path.

Teams will use AI with or without a firm standard. The risk is not curiosity. It is unmanaged use of consumer tools on NDA-bound files. A private StratiqAI environment gives leadership a yes: producers get the speed they want, and the firm keeps control of where deal documents and client data live.

That is why security-minded brokerages and investment shops treat this as infrastructure, not a nice-to-have. It protects reputation, reduces accidental disclosure, and lets you answer client security questionnaires with specifics instead of hope.

SOC 2 & ISO alignment

Aligned with the standards your clients and insurers ask about.

StratiqAI is designed to align with SOC 2 themes your security reviewers care about: who can access systems, how data is encrypted, and how boundaries are protected, and with ISO 27001 themes around separating environments, protecting credentials, and running secure configurations. We also follow widely used NIST guidance on protecting systems and managing encryption keys.

In plain terms: access is limited to your firm, sensitive material is encrypted, environments are separated so customers do not share each other's workspace, and important changes are logged. We describe this as alignment with those frameworks, not as a completed certification, unless and until a formal audit attestation is in place. Bring your questionnaire; we will walk the answers with your team.

For technical & security reviewers

How isolation and encryption work under the hood

Most CRE and finance users do not need this section. It is here for CISOs, IT leads, and vendors completing a security review.

  • Dedicated environment per firm

    Each customer runs in an isolated application with its own hardware-virtualized microVM, encrypted volume, and private network segment, not a shared multi-tenant agent process.

  • Private networking

    Agents have no public IP. Connectivity uses a private IPv6 address on an internal control network over a WireGuard-encrypted mesh, with per-tenant bearer credentials on every request, including health checks. Support access uses short-lived, loopback-bound tunnels rather than internet-exposed endpoints.

  • Secrets & key management

    CRM and model-provider credentials use envelope encryption (AES-256-GCM data keys wrapped by versioned master keys), bound to tenant ID and purpose. Secrets are injected at runtime through a sealed store, never baked into images, and master keys can rotate without downtime, consistent with NIST SP 800-57 guidance. Agent images are pinned by SHA-256 digest.

  • Model calls, minimized

    Inference is the only step that leaves the environment. Firms choose from 50+ models or bring their own provider credentials and commercial terms (including enterprise zero-data-retention options where available). Requests are task-scoped; persistent memory is optional and firm-controlled. This is not “never calls a model API”. It is “you control which API and what leaves your boundary.”

  • Oversight & evidence

    Consequential tool actions can require human approval; circuit breakers stop runaway loops. Continuous reconciliation flags infrastructure drift. Provisioning, credential, and admin events are written to an audit trail for questionnaires and internal review. Control themes map to SOC 2 CC6 access/encryption/boundary topics, ISO 27001 Annex A segregation and crypto controls, and NIST CSF Protect, plus NIST AI RMF / ISO 42001 themes for human oversight.

A practical next step

Protect your deals without slowing the desk.

Start a trial for your team, or book an AI audit and bring your security questionnaire. We will walk through how StratiqAI fits your NDAs and client requirements.