Styr takes a security-by-design approach to protecting your data and continues to invest in security so you can use Styr with confidence.

Our security approach has two pillars: Security Infrastructure covers how Styr is built, and Product Security covers how your team uses it.

  • Security Infrastructure

    Styr's infrastructure is designed with layers of protection to help ensure your data is secure while transmitted, stored, or processed. Protections include encryption, network isolation, and secure software development practices.

  • Product Security

    Styr provides in-product data protection and admin controls for greater visibility and control over your data. Admins can apply least-privilege access, fine-tune permissions and guest access, and manage team organizations.

Security Infrastructure

Your Data Stays Yours.

What we do and do not do with your data.

  • No Sharing Between Customers

    Your farm's data is never shared with, or visible to, other Styr customers.

  • No Training on Your Data

    Your data is never used to train models that other customers use. Your data and the results generated from it remain private to your organization.

  • Encrypted at Rest and in Transit

    Customer data is encrypted at rest with AES-256 and encrypted in transit using TLS 1.2 or later.

  • NDA on Request

    We'll sign a non-disclosure agreement before you share anything with us. You can also request deletion of your data at any time.

Product Security

Right Access. Right Roles.

Protect sensitive data and actions with security controls.

  • Unique Logins

    Everyone gets their own login, creating a clear audit trail and allowing a compromised account to be locked down without disrupting anyone else.

  • Role-Based Access Control

    Assign roles to ensure that the right people have the right permissions to work on your projects.

  • Sensitive Data, Hidden by Role

    Hide sensitive fields and restrict permissions based on a user's role, so people only see what their job requires.

  • Manager Approval

    Certain actions can require a manager's approval before they go through.

  • Write-Only Audit Logs

    Sensitive features keep write-only audit logs of who changed what, and when.

  • Logged Approvals and Corrections

    Approvals and corrections are logged for a clear audit trail.

Product Security

Your Security Policies Stay in Place.

When Styr uses your existing systems to enter or export data, it follows the same VPN, two-factor authentication, and permission requirements as an employee.

  • API Integrations

    Connect an API with scoped credentials, so Styr can work within the permissions you choose.

  • Connect Through Your VPN

    Styr connects through your existing VPN the same way your employees do.

  • Remote Desktop

    If remote desktop is how your team accesses a system, Styr can connect the same way.

Security Infrastructure

Protected Cloud Infrastructure. On-Premises Available.

Public access through a secured entry point, with application services isolated in private subnets.

  • Isolated Cloud Infrastructure

    Styr's public app is exposed through a secured load balancer, while application services run in private subnets with tightly restricted network access.

  • Secure AI Use

    AI services receive only the data needed for a task. Our providers do not retain your data or use it for training.

  • On-Premises Deployments

    Styr can be deployed in your environment when your security or compliance requirements call for it. Contact us to scope the deployment.

FAQ

If someone gains access to Styr, can they reach payroll or employee data?

Not unless that person's role already allows it. Everyone signs in as themselves and sees only the records their job needs, so one stolen login doesn't open the whole farm. Pay and other sensitive fields can be hidden from a role entirely, and any change to them is recorded in a log that can't be edited afterwards.

If ransomware hits, can we keep operating?

Your records don't live only in Styr. It works on top of the systems you already have, so the same data is still sitting in your ERP and your spreadsheets, and your crew can keep working the way they always have. We also keep backups of everything in Styr, so a bad day means restoring data, not re-entering it.

What access does Styr need, and how many accounts are required?

One account, set up the way you'd set up a new hire. It gets only the systems and permissions the work actually needs, using credentials you issue and can revoke at any time. Inside your own software, Styr signs in exactly as a person does, through the same VPN and two-factor prompts your team goes through.

Can IT and legal review and approve access before Styr connects?

That's the normal order of things. Nothing gets connected until your IT and legal teams have signed off, and they're the ones who decide what Styr can reach and what it's allowed to do there. We'll sign an NDA first and work through whatever review process you already run vendors through.

Can our security team review Styr before we begin?

Bring them in as early as you like. We'll walk them through how Styr is built, where your data lives, and what protects it, and we'll take the hard questions. None of that requires committing to anything first.

See what every block is really costing you.