Strac provides a data discovery and loss prevention platform that integrates with various applications to automatically identify and redact sensitive information such as PII, PCI, and PHI. By utilizing machine learning and tokenization, Strac enhances compliance with regulations like GDPR and HIPAA while minimizing the risk of data breaches across cloud and SaaS environments.
Funding
$4M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.



RCWVFounders
Product
Problem
Organizations struggle to maintain visibility and control over sensitive data, such as PII, PCI, and PHI, across diverse SaaS, cloud, and endpoint environments. This lack of oversight increases the risk of data breaches and makes it difficult to comply with regulations like GDPR, HIPAA, SOC 2, and ISO 27001.
Solution
Strac provides a data discovery and loss prevention (DLP) platform that automatically identifies, classifies, and remediates sensitive data across SaaS applications, cloud storage, generative AI platforms, and endpoints. The platform integrates with popular tools like Slack, Gmail, Zendesk, and Google Drive to scan for sensitive information within messages, documents, and files. Strac uses machine learning and optical character recognition (OCR) to accurately detect sensitive data in unstructured text and documents, including PDFs, images, and audio recordings. Remediation actions include redaction, masking, blocking, alerting, deletion, encryption, and labeling.
Target Audience
Strac targets businesses of all sizes that handle sensitive data and need to comply with data privacy regulations, including those in financial services, healthcare, and technology.
Features
- Automated scanning and classification of PII, PHI, PCI, source code, and intellectual property
- No-code integrations with SaaS applications like Zendesk, Slack, Gmail, Office 365, Intercom, Notion, Sharepoint, Jira, and Google Drive
- Data Security Posture Management (DSPM) capabilities to remediate sensitive data findings
- Tokenization and proxy APIs for secure data handling and compliance with PCI standards
- AI-powered DLP solution to protect against sensitive data sharing over ChatGPT, Google Gemini, and Anthropic Claude
- Historical scanning to identify sensitive data in past data sources
- Role-based access control