Trust Center
Compliance overview
Current status across frameworks and programs
Featured documents
Key security and compliance documentation
- Security & Compliance OverviewView
- SMS Compliance — Consent, Opt-Out & Quiet HoursView
- SOC 2 Type 2 Report
Compliance Program
The controls in place, with known limits stated plainly
In place· Implemented and verifiable in codePartial· Implemented with known limitsPlanned· Tracked in the gap register
- Supervised by default
- Independent draft reviewer that fails closed
- Higher autonomy is opt-in and admin-only
- Atomic approval
- Instant human takeover
- Revision loop re-holds drafts
- Escalate-to-human tool
- Per-turn audit trail
- Agents run inside Stryke's AWS boundary
- Partition-scoped agent data access
- Content guardrails beyond the reviewer
- Prompt-injection hardening
- Automated A2P 10DLC registration
- No unregistered sending
- Opt-out enforced in code, not by the AI
- Consent re-checked at the moment of send
- Keyword and natural-language opt-outs honored
- Ambiguity resolves against sending
- Quiet hours
- Carrier opt-outs reconciled back
- Consent history is immutable
- Inbound rate limiting and abuse controls