What are StratEngine AI data connections?
StratEngine AI connects to Google Drive, OneDrive, and Dropbox for two distinct purposes: importing proprietary documents so research can run alongside web sources, and exporting analysis results (strategy briefs and investment memos) directly to the user's own storage. This page explains how StratEngine handles, stores, and protects data at every step of the import and export workflow. Management consultants, corporate strategy teams, venture capitalists, PE firms, family offices, and commercial real estate investors use StratEngine data connections to keep originals inside their own storage while running AI-powered analysis on the working copy.
How does StratEngine AI keep connected data secure?
Does StratEngine AI permanently store uploaded files?
No. StratEngine never permanently stores original files from connected storage. When you connect Google Drive, OneDrive, or Dropbox for import, StratEngine pulls a temporary working copy into a staging bucket inside our private Google Cloud network. Your original stays in your drive, untouched. The staging copy is parsed (PDFs by Mistral’s OCR service, other formats on our own servers) and then deleted on ingestion — there is no 8-hour cache window, no overnight staging. What persists is the searchable layer: text excerpts and embeddings, each tagged to your organization and isolated at every query. The staging-copy infrastructure inherits SOC 2 and ISO 27001 from Google Cloud, with encryption in transit (TLS 1.2+) and at rest (AES-256).
What permissions does StratEngine AI request for connected storage?
StratEngine requests the minimum permissions needed for each use case. For document import, StratEngine requests read-only access to the files you choose to share. For export, StratEngine uses Google's drive.file scope (and the equivalent app-folder grant on OneDrive and Dropbox). That scope only lets StratEngine write the files StratEngine creates — we cannot open them again afterward, even if we wanted to. Import and export are separate connection flows; you can connect either or both, and revoke either independently from your storage provider's settings.
How do StratEngine AI import connections work?
What happens when users connect storage for document import?
Connecting storage for import is an OAuth 2.0 handshake with the storage provider — StratEngine never sees your storage password. Once connected, StratEngine pulls a temporary working copy of the files you've shared into a staging bucket inside our VPC (private network). The staging copy is parsed (PDFs by Mistral’s OCR service, other formats on our own servers), text is extracted, and that text is converted into search embeddings. The staging copy is deleted on ingestion. The original file in your storage is never touched. What remains in the StratEngine database is the searchable layer: text excerpts and embeddings tagged to your organization. When you run a research query, StratEngine searches that index and pulls relevant excerpts into the report.
What data does StratEngine AI store from imported documents?
StratEngine stores text excerpts, search embeddings (numerical vectors used for semantic search), and file names with metadata — all tagged to your organization. StratEngine does not store original files (they live in your storage, untouched), passwords (OAuth handles auth), or anything tied to another organization. This approach enables fast AI-powered search across proprietary documents while keeping the durable storage of sensitive originals on your side.
How does StratEngine AI isolate data between organizations?
Every database query is scoped to your organization, and your organization comes from your verified login, never from anything a request can change. Team members within an organization share access to that organization's connected data so the team can collaborate.
How do StratEngine AI export connections work?
How does StratEngine AI handle Investment mode exports?
Investment-mode analyses (investment memos and the underlying research reports) are one-shot artifacts. Once the memo is written, the deck's full text is deleted from the StratEngine database, and the uploaded deck file is deleted within 7 days. When you export, StratEngine creates the documents in your connected storage and deletes the analysis content from the StratEngine database, leaving only a link and a short preview for your dashboard. Deleting your account deletes all of it. This retention model gives investors control over where sensitive deal-vetting memos live after the analysis is complete.
How does StratEngine AI handle Strategy mode exports?
Strategy mode is iterative. Strategy briefs, inputs, and conversation history stay in the StratEngine database regardless of export settings because users refine inputs, have conversations, and evolve the brief over time. Strategy exports are one-way snapshots for sharing or archiving. Changes you make to an exported document do not sync back to StratEngine, and changes you make in StratEngine do not update previously exported documents. Management consultants and corporate strategy teams use this pattern to keep working versions in StratEngine while sharing point-in-time snapshots with clients or stakeholders.
Can users export existing analyses after connecting storage?
Yes. If you ran Investment analyses before connecting an export destination, you can export them afterward. Connect your export destination, click Export on any existing analysis, and StratEngine creates the documents in your connected storage and deletes the content from the StratEngine database, leaving only a link and a short preview for your dashboard. You can start on a free tier, then upgrade, connect export, and move sensitive content to your own storage at any time.
How does StratEngine AI organize exported files?
When you connect an export destination, StratEngine creates a clean folder structure in your storage. The top-level directory is named StratEngine, with subfolders for Investment Analysis and Strategy Analysis. Each analysis gets its own dated, named subfolder containing the generated files. For example, an Investment analysis for Company A on 2025-01-05 would live at StratEngine/Investment Analysis/2025-01-05 · Company A/ with the investment memo and the underlying research report. Predictable, greppable, easy to archive.
What security architecture protects StratEngine AI connections?
How does StratEngine AI handle authentication for connected storage?
StratEngine uses OAuth 2.0 for all storage connections. StratEngine never sees or stores storage passwords. You can revoke StratEngine's access at any time from your storage provider's connected-apps settings (Google Account security and third-party apps for Google Drive, Microsoft account permissions for OneDrive, Dropbox security settings for Dropbox). Revocation is immediate.
How does StratEngine AI secure its databases?
StratEngine databases use private IPs only and are not addressable from the public internet. All database traffic stays inside the private Google Cloud network through VPC isolation — no public IP, no externally reachable endpoint. Internal connections use TLS encryption. Every query is scoped to your organization from your verified login.
How does StratEngine AI secure the import pipeline?
The import pipeline pulls a temporary working copy of your files into a staging bucket inside our VPC. The staging copy is deleted on ingestion. All connections use TLS 1.2+ encryption — no data crosses the network unencrypted. Data at rest is encrypted with AES-256 on Google Cloud Platform. PDFs are read by Mistral's OCR service under its data-processing terms; other formats are parsed on our own servers. Embeddings are generated using business-tier AI models, and content is never used to train them.
Where does StratEngine AI store each type of data?
This is the procurement-grade view of the data pipeline. Every row below names a class of data, where it physically lives, and who can access it.
- Original files from connected storage. Stay in your Drive, OneDrive, or Dropbox. Untouched by StratEngine. Access governed by your storage provider.
- Staging copy (during import). Private staging bucket inside our VPC. Deleted on ingestion.
- Text excerpts and search embeddings. StratEngine database (Supabase Postgres) with encryption at rest, accessible only to your organization via per-tenant isolation.
- Investment analysis · with export connected. Lives in your storage. StratEngine keeps only a link and a short preview.
- Investment analysis · without export connected. StratEngine database with encryption at rest, viewable only in the application, accessible only to your organization.
- Strategy inputs and briefs. StratEngine database with encryption at rest, accessible only to your organization. Stay until you delete them.
- Strategy exports. One-way snapshots in your storage. Independent of the live brief in StratEngine.
- OAuth tokens. Stored in encrypted secret storage, accessible only to the StratEngine system, not to other users or organizations.
Frequently Asked Questions About StratEngine AI Data Connections
Can other organizations see my connected data in StratEngine AI?
No. Every database query is scoped to your organization, and your organization comes from your verified login, never from anything a request can change.
Can everyone in my organization see connected data?
Yes. Team members within an organization share access to that organization's connected storage and analysis results. Data connections and search results are scoped at the organization level. This enables collaboration among team members while keeping the boundary between organizations enforced at the database.
What happens when I disconnect my storage from StratEngine AI?
For import connections, the indexed search data for that connection (text excerpts and embeddings) is permanently deleted from the StratEngine database. Future searches will not include documents from the disconnected source. For export connections, the documents already created in your storage stay there — they belong to you. StratEngine simply removes the connection, and future analyses will not auto-export to that destination.
Can I use different providers for import and export in StratEngine AI?
Yes. You can import from multiple providers simultaneously (Google Drive plus Dropbox, for example) and export to a single destination. Import and export use separate connection flows and are configured independently.
Can I export analyses I ran before connecting export?
Yes. Run the analysis first, connect an export destination later, then click Export on any existing Investment analysis. StratEngine creates the documents in your storage and the content is deleted from our database, leaving only a link and a short preview for your dashboard.
How do I revoke StratEngine AI access to my storage?
Two paths. Inside StratEngine, disconnect from the settings page. Or revoke directly from your storage provider's connected-apps settings (Google Account security and third-party apps, Microsoft account permissions, or Dropbox security settings). Either path is immediate.
Is my data used to train AI models?
No. The AI models behind the analysis run on paid, business-tier API terms, and your inputs and the generated outputs are never used to train them.
How long does StratEngine AI keep files during import?
The staging copy is deleted on ingestion. There is no 8-hour cache, no overnight window. The original file in your storage is never touched. What persists in the StratEngine database is the searchable layer: text excerpts and embeddings.
What certifications does the StratEngine AI infrastructure inherit?
The compute layer (Google Cloud) is independently certified to ISO 27001:2022, SOC 2, PCI DSS, and FedRAMP. The database layer (Supabase) is SOC 2 Type II certified. StratEngine the application itself is CASA Tier 2 certified. See stratengineai.com/security for the full certification posture and how each one applies.
Is the StratEngine AI database accessible from the internet?
No. StratEngine databases use private IPs only. All access happens inside the private Google Cloud network through VPC isolation. There is no public endpoint, no externally reachable address.
What storage providers does StratEngine support?
Google Drive, OneDrive, and Dropbox today. The OAuth pattern (`drive.file` and equivalent app-folder grants) is consistent across providers: import uses read-only scopes, export uses write-only scopes limited to the files StratEngine creates.
How do I get in touch about data connections?
For questions about data connections, security configurations, or vendor due diligence, contact the StratEngine team at info@stratengineai.com. We respond to security and procurement questions from management consulting firms, corporate strategy teams, VCs, PE firms, family offices, and commercial real estate investors evaluating StratEngine for sensitive document workflows.