Security
Last Updated: June 25, 2026
Security is foundational to how we build and operate Starling AI. We implement commercially reasonable administrative, technical, and organizational measures designed to protect the data entrusted to us. This page summarizes our approach; it is a general description and not a warranty or guarantee. It supplements our Terms of Service and Privacy Policy.
Encryption
Data transmitted between you and Starling AI is encrypted in transit using industry-standard TLS. Our infrastructure and database providers encrypt data at rest within their managed environments.
Infrastructure
Starling AI runs on reputable cloud and platform providers that maintain robust physical, network, and operational security controls in their data centers. We rely on managed services for hosting, database, telephony/messaging, and related functionality, and we benefit from the security investments of those providers.
Access controls
We follow the principle of least privilege. Access to production systems and data is limited to personnel who require it, protected by authentication controls, and credentials are kept confidential. Access is reviewed and adjusted as roles change.
Vendor and subprocessor management
We engage third-party service providers (subprocessors) to deliver and support the platform. We select reputable vendors and rely on their security practices and contractual commitments. A description of how we use these providers is available in our Data Processing page.
Monitoring and maintenance
We monitor our services and apply updates and improvements on an ongoing basis to maintain the integrity and availability of the platform.
Shared responsibility
Security is a shared responsibility. Customers are responsible for safeguarding their account credentials, managing access for their own users, configuring the platform appropriately, and maintaining their own backups of important data.
Important limitations
No method of transmission over the internet or method of electronic storage is completely secure. While we work hard to protect data, we cannot guarantee absolute security, and we do not warrant that the services will be free from unauthorized access, loss, or other security incidents.
Reporting a vulnerability
If you believe you have found a security vulnerability, please report it to us responsibly at admin@starlingagent.com. We appreciate the work of the security community and will review reports promptly.