Built so the agent can never do the thing you fear.
Finance agents earn trust by what they cannot do. Stratum agents cannot move money, cannot file a return, cannot lock a period, and cannot act above your threshold without a person. Everything else is logged, encrypted, and yours to export.
Four things that are always true.
Not settings you can turn off. The shape of the system, on every workspace, from the first connection.
- Guarantee 01 · Money
No money moves without a human
Agents prepare, schedule, apply, and reconcile. They never initiate a payment, transfer, or refund. Bank connections are read-only. Payment runs are released by you, inside your bank or payments platform.
- Guarantee 02 · Record
Every action has a trail
Who approved, when, what the agent saw, what it proposed, and why. Recorded at the moment of the decision and never edited afterwards.
- Guarantee 03 · Portability
Your data and judgment are portable
Rules, notes, learned patterns, logs, and documents can be exported in full at any time. Leaving Stratum never means leaving your knowledge behind.
- Guarantee 04 · Access
Least privilege, always
Each agent gets the narrowest access its job requires. Read where reading is enough. Scoped write access only to the ledger objects it owns.
What an agent can do — and what it can never do.
The list on the right is not a policy. It is enforced in code. There is no instruction, prompt, or email that moves an agent across that line.
An agent can
- Read ledger transactions, invoices, and bills through scoped APIs
- Draft and send reminders in the tone and cadence you set
- Code bills and match bank transactions above your confidence gate
- Draft journal entries and hold them for review
- Prepare payment runs and filings for a person to release
- Log every action with its reasoning and the evidence it used
An agent can never
- Initiate a payment, transfer, or refund
- File a tax return or lock an accounting period
- Act above your threshold without a person
- Contact a customer, vendor, or account marked sensitive
- Delete ledger data or edit the audit log
- Change a vendor's bank details without human verification
- Train shared models on your data
Four categories of control, switched on by default.
Access, data protection, agent guardrails, and operations. Nothing here is an add-on plan or an enterprise upsell.
- Control 01
Single sign-on and MFA
Google and Microsoft sign-in with enforced multi-factor authentication for every user who can approve.
- Control 02
Role-based permissions
Approver, reviewer, and reader roles per company. Budget owners see only their lines. Firms get strict per-client separation.
- Control 03
Scoped integration tokens
OAuth tokens per integration with the minimum scopes. Revocable from your side at any time.
- Control 04
Session and device controls
Short-lived sessions, forced re-authentication for approvals above a threshold, and a device log you can review.
Access & identity
- Control 01
Single sign-on and MFA
Google and Microsoft sign-in with enforced multi-factor authentication for every user who can approve.
- Control 02
Role-based permissions
Approver, reviewer, and reader roles per company. Budget owners see only their lines. Firms get strict per-client separation.
- Control 03
Scoped integration tokens
OAuth tokens per integration with the minimum scopes. Revocable from your side at any time.
- Control 04
Session and device controls
Short-lived sessions, forced re-authentication for approvals above a threshold, and a device log you can review.
Data protection
- Control 01
Encryption in transit and at rest
TLS 1.2+ for every connection; AES-256 for stored data. Secrets held in a managed vault, never in application code.
- Control 02
Isolated workspaces
Each company's data, judgment layer, and logs are logically isolated. No cross-tenant queries by design.
- Control 03
No training on your data
Your ledger, documents, and judgment layer are never used to train models for anyone else.
- Control 04
Retention you control
Delete your workspace and its data is removed from production within 30 days, with a written confirmation.
Agent guardrails
- Control 01
Hard limits, not prompts
The actions an agent cannot take are enforced in code, not requested in a prompt. There is no path from an instruction to a payment.
- Control 02
Thresholds and approvals
By amount, counterparty, account, or action type. Anything above a threshold is queued for a person and cannot proceed without them.
- Control 03
Confidence gating
Low-confidence matches, codes, and classifications are queued with the agent's best guess. They are never assumed.
- Control 04
Sensitive-party holds
Mark any customer, vendor, or account as sensitive and no agent will contact or act on it automatically.
Operational
- Control 01
Immutable audit log
Append-only, timestamped, attributed. Exportable to your own storage on a schedule if you want a copy outside Stratum.
- Control 02
Change control
Agent behaviour changes ship behind versioned releases with notes you can read before they apply to your workspace.
- Control 03
Monitoring and incident response
Uptime and anomaly monitoring on every integration. A written incident process with customer notification within 72 hours.
- Control 04
Compliance roadmap
Designed against SOC 2 Type II controls from day one. Formal audit and certification are on the roadmap; ask us for the current status.
Where your data goes, and who can see it.
From your systems to a read-only connector, an isolated agent workspace, your approvals, and an audit log — never anywhere else.
- 01Your systemsLedger · bank feeds · mailbox · documents
- 02Read-only connectorsOAuth · minimum scopes · revocable
- 03Agent runtimeIsolated workspace · encrypted · no training
- 04ApprovalsYour thresholds · your people · MFA
- 05Audit logAppend-only · attributed · exportable
Money never enters this diagram. Payment runs are released by you, inside your bank or payments platform.
- 01
What we access
Ledger transactions, invoices, bills, bank and card feed data, the mailbox folders you scope, and documents you connect. Nothing beyond what the agent's job needs.
- 02
What we store
A working copy of the ledger data the agents act on, the judgment layer, and the audit log. Documents are stored only when they are evidence for a transaction.
- 03
Who can see it
Your named users, by role. Stratum staff access is limited to support engineers, logged, and only with your consent for a specific issue.
- 04
Where it lives
Cloud infrastructure in a region you choose at onboarding: India or the United States today, EU on the roadmap.
Before you connect a ledger.
Ask us the hard question first
Bring your security questionnaire.
We will walk through the architecture with your team, share our SOC 2 roadmap plainly, and sign a DPA before you connect a ledger.