Skip to content
Security & trust

Built so the agent can never do the thing you fear.

Finance agents earn trust by what they cannot do. Stratum agents cannot move money, cannot file a return, cannot lock a period, and cannot act above your threshold without a person. Everything else is logged, encrypted, and yours to export.

Guarantees

Four things that are always true.

Not settings you can turn off. The shape of the system, on every workspace, from the first connection.

  • Guarantee 01 · Money

    No money moves without a human

    Agents prepare, schedule, apply, and reconcile. They never initiate a payment, transfer, or refund. Bank connections are read-only. Payment runs are released by you, inside your bank or payments platform.

  • Guarantee 02 · Record

    Every action has a trail

    Who approved, when, what the agent saw, what it proposed, and why. Recorded at the moment of the decision and never edited afterwards.

  • Guarantee 03 · Portability

    Your data and judgment are portable

    Rules, notes, learned patterns, logs, and documents can be exported in full at any time. Leaving Stratum never means leaving your knowledge behind.

  • Guarantee 04 · Access

    Least privilege, always

    Each agent gets the narrowest access its job requires. Read where reading is enough. Scoped write access only to the ledger objects it owns.

Boundaries

What an agent can do — and what it can never do.

The list on the right is not a policy. It is enforced in code. There is no instruction, prompt, or email that moves an agent across that line.

Within your limits

An agent can

  • Read ledger transactions, invoices, and bills through scoped APIs
  • Draft and send reminders in the tone and cadence you set
  • Code bills and match bank transactions above your confidence gate
  • Draft journal entries and hold them for review
  • Prepare payment runs and filings for a person to release
  • Log every action with its reasoning and the evidence it used
Enforced in code, not prompts

An agent can never

  • Initiate a payment, transfer, or refund
  • File a tax return or lock an accounting period
  • Act above your threshold without a person
  • Contact a customer, vendor, or account marked sensitive
  • Delete ledger data or edit the audit log
  • Change a vendor's bank details without human verification
  • Train shared models on your data
Controls

Four categories of control, switched on by default.

Access, data protection, agent guardrails, and operations. Nothing here is an add-on plan or an enterprise upsell.

Access & identity

  • Control 01

    Single sign-on and MFA

    Google and Microsoft sign-in with enforced multi-factor authentication for every user who can approve.

  • Control 02

    Role-based permissions

    Approver, reviewer, and reader roles per company. Budget owners see only their lines. Firms get strict per-client separation.

  • Control 03

    Scoped integration tokens

    OAuth tokens per integration with the minimum scopes. Revocable from your side at any time.

  • Control 04

    Session and device controls

    Short-lived sessions, forced re-authentication for approvals above a threshold, and a device log you can review.

Data protection

  • Control 01

    Encryption in transit and at rest

    TLS 1.2+ for every connection; AES-256 for stored data. Secrets held in a managed vault, never in application code.

  • Control 02

    Isolated workspaces

    Each company's data, judgment layer, and logs are logically isolated. No cross-tenant queries by design.

  • Control 03

    No training on your data

    Your ledger, documents, and judgment layer are never used to train models for anyone else.

  • Control 04

    Retention you control

    Delete your workspace and its data is removed from production within 30 days, with a written confirmation.

Agent guardrails

  • Control 01

    Hard limits, not prompts

    The actions an agent cannot take are enforced in code, not requested in a prompt. There is no path from an instruction to a payment.

  • Control 02

    Thresholds and approvals

    By amount, counterparty, account, or action type. Anything above a threshold is queued for a person and cannot proceed without them.

  • Control 03

    Confidence gating

    Low-confidence matches, codes, and classifications are queued with the agent's best guess. They are never assumed.

  • Control 04

    Sensitive-party holds

    Mark any customer, vendor, or account as sensitive and no agent will contact or act on it automatically.

Operational

  • Control 01

    Immutable audit log

    Append-only, timestamped, attributed. Exportable to your own storage on a schedule if you want a copy outside Stratum.

  • Control 02

    Change control

    Agent behaviour changes ship behind versioned releases with notes you can read before they apply to your workspace.

  • Control 03

    Monitoring and incident response

    Uptime and anomaly monitoring on every integration. A written incident process with customer notification within 72 hours.

  • Control 04

    Compliance roadmap

    Designed against SOC 2 Type II controls from day one. Formal audit and certification are on the roadmap; ask us for the current status.

Data handling

Where your data goes, and who can see it.

From your systems to a read-only connector, an isolated agent workspace, your approvals, and an audit log — never anywhere else.

  1. 01Your systemsLedger · bank feeds · mailbox · documents
  2. 02Read-only connectorsOAuth · minimum scopes · revocable
  3. 03Agent runtimeIsolated workspace · encrypted · no training
  4. 04ApprovalsYour thresholds · your people · MFA
  5. 05Audit logAppend-only · attributed · exportable

Money never enters this diagram. Payment runs are released by you, inside your bank or payments platform.

  • 01

    What we access

    Ledger transactions, invoices, bills, bank and card feed data, the mailbox folders you scope, and documents you connect. Nothing beyond what the agent's job needs.

  • 02

    What we store

    A working copy of the ledger data the agents act on, the judgment layer, and the audit log. Documents are stored only when they are evidence for a transaction.

  • 03

    Who can see it

    Your named users, by role. Stratum staff access is limited to support engineers, logged, and only with your consent for a specific issue.

  • 04

    Where it lives

    Cloud infrastructure in a region you choose at onboarding: India or the United States today, EU on the roadmap.

Questions

Before you connect a ledger.

Ask us the hard question first

Bring your security questionnaire.

We will walk through the architecture with your team, share our SOC 2 roadmap plainly, and sign a DPA before you connect a ledger.