Trust & Security

Security

Steradian is built for sensitive leadership input. We follow industry-standard practices for infrastructure hardening, transport security, access control, and aggregate reporting. We do not hold SOC 2, ISO 27001, or other third-party compliance certifications at this time.

Infrastructure

Access & audit

Reporting & non-attribution

Data retention & deletion

Our stated retention policy (described on our Pricing page and not yet enforced automatically in the product): customer data retention follows the commercial terms agreed for the engagement; paid customers retain access for the duration of their subscription. Account and data deletion requests are fulfilled manually per our Privacy Policy — email privacy@steradianinsights.com (same mailto as Settings → Request account deletion); there is no automated self-serve deletion today. Module 2 sealed comment originals become purge-eligible 30 days after pulse close under current configuration; automated purge is not yet running.

Security questions

For security inquiries, vendor questionnaires, or responsible disclosure, contact security@steradianinsights.com. For general product questions, use Contact.

Last updated: July 21, 2026