What we do with your data, in specifics.
AugmentMSP, Inc. operates Stratascout.AI. Connecting your PSA means handing a piece of software the records your business runs on, so this document says what happens to them in terms you can check rather than in adjectives.
Last updated August 24, 2026 · AugmentMSP, Inc.
01What this covers
This policy describes how we handle information when you use the Stratascout.AI application and this website. It covers two very different kinds of information, and the distinction matters throughout: the information we hold about YOU as a customer, and the information we read out of the business systems you connect, which is about your clients and belongs to you.
We call the second kind Customer Data. You are its controller. We process it on your instructions, for the purpose of operating the service, and for nothing else.
02Information we collect about you
Account information: your name, work email address, and the organization you belong to. This is handled by our authentication provider and is what identifies you when you sign in.
Connection credentials: the API credentials you issue in your own systems and enter into the service so it can read them. How these are stored is described below.
Usage information: which features are used, when, and whether a request succeeded or failed. We use this to operate the service and to find faults. Errors are reported to our monitoring provider, which may incidentally capture the contents of a failing request.
Communications: if you request a demo or email us, we keep that correspondence so we can reply to it and follow up.
03Customer Data: what the service reads
When you connect a system, the service reads the records it needs to do its work. Depending on which systems you connect, that includes tickets and time entries, agreements and their pricing, configurations and devices, invoices and payments, and the contact records attached to them.
It reads these records to reconcile them against each other and report where they disagree. It does not sell them, share them with other customers, or use them to build a product for anyone else.
Records from one organization are never used to answer a question for another. What the service learns about how your business works stays scoped to your organization.
04We do not train models on your data
We do not use Customer Data to train, fine-tune, or improve any machine learning model, our own or anyone else's.
The service sends the specific records needed to answer a request to a model provider so that it can produce the answer. Those providers are engaged under commercial API terms that do not permit training on submitted content. We do not opt into any programme that would change that, and we do not retain a training corpus of your records.
05How credentials are stored
Every vendor credential is encrypted with AES-256-GCM before it is written to the database. Each encrypted value is cryptographically bound to your organization, the vendor it belongs to, and the specific field it is, so a value copied out of the database and placed in another record fails to decrypt rather than opening in the wrong context.
Encryption keys are versioned and can be rotated without downtime; existing values re-encrypt themselves under the current key as they are read. If a decryption fails for any reason, the affected connection reports as not connected rather than falling back to an unprotected path.
You issued these credentials in your own systems and you can revoke them at any time, without asking us. If you do, the connection stops working immediately and the service reports it as not connected.
06What the service is permitted to do
Every tool call the service makes resolves to allowed, held for approval, or denied before it reaches the code that would execute it, and that decision is made outside the tool rather than inside it. Reads execute. Anything that would change a record in a system we do not own is staged as a draft for one of your people to approve. Nothing addressed to your clients is sent by the service.
Access is scoped per person within your organization. Each capability has an organization default which can be tightened for an individual, a person can make their own access more restrictive but never less, and an organization-level denial cannot be overridden by anyone.
07Service providers we use
We use the following sub-processors to operate the service. Each is engaged under terms that require them to process data only on our instructions and to maintain appropriate safeguards. We will update this list before adding a new one that processes Customer Data.
08Where your data is processed
The service is operated primarily from infrastructure located in the United States. If you are in Canada, this means your Customer Data is transferred to, stored in, and processed in the United States, and while it is there it is subject to lawful access requests under United States law. By using the service you consent to that transfer.
We transfer personal information across borders only to the sub-processors listed above and only for the purposes described in this policy.
09How long we keep things
Customer Data is retained for as long as your organization has an active account, and is deleted within 30 days of your account being closed unless you ask us to delete it sooner or the law requires us to keep it longer.
Credentials are deleted when you disconnect the integration or close your account. Operational logs and error reports are retained for a limited period for debugging and are not a durable store of your business records.
Correspondence with us, including demo requests, is kept for as long as it is useful for the business relationship.
10Your rights
If you are in Canada, PIPEDA gives you the right to access the personal information we hold about you, to ask that it be corrected if it is wrong, and to withdraw consent to its use, subject to legal and contractual limits. You may also complain to the Office of the Privacy Commissioner of Canada.
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to request its deletion or correction, to opt out of sale or sharing, and to be free from discrimination for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising.
Where the personal information in question is Customer Data belonging to one of our customers, we will refer your request to that customer, who is its controller, and assist them in responding.
To exercise any of these rights, or to ask what we hold, email us at the address at the end of this policy. We will respond within the time the applicable law allows.
11Security incidents
If we become aware of a breach of security that affects your Customer Data or personal information, we will notify you without undue delay, tell you what we know about what happened and what was affected, and tell you what we are doing about it. We will notify regulators where the law requires it.
12Changes to this policy
We will post any change here and update the date at the top. If a change materially reduces the protection of information we already hold, we will tell affected customers directly rather than relying on you to notice.
| Sub-processor | What it does | Where |
|---|---|---|
| Vercel | Application hosting, edge routing, and product analytics | United States |
| Neon | Primary application database | United States |
| Supabase | Stores demo requests and contact messages sent from this website | United States |
| Cloudflare | Agent runtime execution and object storage for generated artifacts | Global edge network |
| Clerk | Authentication and organization membership | United States |
| Anthropic | Large language model inference | United States |
| OpenRouter | Model routing for inference not served directly by Anthropic | United States |
| Sentry | Application error monitoring | United States |
| Langfuse | Tracing of model calls, for debugging and evaluation | European Union or United States, per deployment |
| Meta Platforms | WhatsApp Business messaging, where you enable that channel | United States |
| Slack Technologies | Slack messaging, where you enable that channel | United States |
Contact
Questions about this document, or a request under it, go to support@stratascout.ai. A person reads that inbox.