Data Security & Encryption
Sterling protects your client data using industry-standard security practices. This page explains how data is secured both during transmission and while stored in our systems.
Encryption in Transit
All data transmitted between your browser and Sterling's servers is encrypted using HTTPS with TLS (Transport Layer Security). This prevents anyone from intercepting or reading data as it travels over the internet.
- All web traffic uses HTTPS encryption
- Document uploads and downloads are encrypted
- AI requests are transmitted over secure channels
Encryption at Rest
Client data stored in Sterling is protected by enterprise cloud providers with built-in encryption:
- Database: MongoDB Atlas with encryption at rest enabled
- Documents: AWS S3 with server-side encryption
- Credentials: AWS Secrets Manager for secure key storage
Enterprise Infrastructure
Sterling runs on the same cloud infrastructure trusted by major financial institutions, healthcare organizations, and government agencies.
Authentication Security
Sterling uses Auth0, an enterprise identity platform, for user authentication. This provides:
- Secure password storage with industry-standard hashing
- Sessions expire after 12 hours, and after 1 hour of inactivity
- Protection against common attacks (brute force, credential stuffing)
No Local Data Storage
Sterling does not store sensitive client data on your local device. All data remains on secure cloud servers. When you close your browser, no client information is left behind on your computer.
Infrastructure Provider Certifications
The cloud platforms Sterling is built on hold independent security certifications. These are the providers' certifications, covering the infrastructure Sterling runs on:
- Amazon Web Services — SOC 2 Type II, ISO 27001, and GDPR commitments covering document storage, credential management, and AI processing
- MongoDB — SOC 2 Type II and ISO 27001 covering the database platform
- Auth0 (Okta) — SOC 2 Type II and ISO 27001 covering authentication
Certifications Are Not Transitive
A provider's certification covers that provider's controls, not Sterling's. For Sterling's own security posture and compliance status, contact your account team.
