Security & Trust
Straion enforces your engineering standards without ever touching your source code. Your rules. Your codebase. Your control.
Straion syncs rules, not code. The CLI runs locally, your repository is never cloned, and your codebase stays on your machine. There is no copy of your files on our side. Nothing to leak.
You own every org standard: every change is versioned, and you decide who can read or edit each rule. On Enterprise plans the rules live as plain Markdown on a branch in your own Git, so history and approvals run through your normal pull request flow.
Your rules, your task context, and your usage data are never used to train models. Not ours, not anyone else’s.
Three parts, one round trip. The agent describes the task, Straion sends back the rules that apply, and your files stay put.
On your machine
Claude Code, Cursor, or Copilot runs in your existing environment. The Straion CLI runs there too and asks for the rules that fit the task at hand.
✓ Your codebase never leaves this box
Straion (EU hosted)
Straion matches the task description against your rule collections and returns only the rules that apply. TLS in transit, encrypted at rest, EU-based models.
✓ Rule definitions only, no files
In your Git
Rules live as plain Markdown on a dedicated branch in your own repository. Changes go through pull requests, so CODEOWNERS and branch protection apply.
✓ Rule definitions only, and they stay yours
■ A real request, start to finish
That is the whole exchange. A task description goes out, a list of rule statements comes back. The files are named, never opened.
Every argument the CLI puts on the wire, and everything it leaves behind.
"Does the CLI send code snippets?"
It can, and we would rather say so plainly. Your agent writes the task description, so if it quotes a few lines in --body, those lines travel with the request. Straion never opens a file to add code itself, and full files are never transmitted. Run the CLI with verbose output to inspect every call before it leaves the machine.
■ The short list
Never reads, transmits, or stores your full code files
Never shares your rule definitions with other organizations
Never uses your data to train AI models
Never sells or monetizes usage data
We are working towards SOC 2 Type II certification. If that matters for your review, write to team@straion.com and we will share our current status and timeline.
Hosted SaaS, EU based
Straion runs on EU infrastructure. No setup on your side beyond the CLI.
EU-based data and models
The models Straion uses to select rules run in the EU, so task context stays in the same region as your data.
Roadmap: bring your own cloud
Self-hosted deployment options for larger enterprises are on the roadmap. Talk to us if you need one.
We answer security reviews, vendor questionnaires, and DPA requests directly. No sales gate.
Write to team@straion.com, or start free and see the data flow yourself.