Search documentation

Search documentation

Security & data

How API keys, organization isolation, and your data are handled.

This page summarises how Stratta protects your access and your norms. For account-level controls, see Manage API keys.

API keys

  • Keys look like sk_strt_… and are created on Intégrations › Clés d’API (API keys).
  • The full key is shown once; only a prefix is stored for display. On the server the key is kept as a salted hash, never in plaintext.
  • A key grants read and write access to your workspace (including ingest and delete), so it's a secret. Treat it like a password.
  • Revocation is immediate. Limits: 50 active keys and 20 new keys per 24 hours, per user.

Never commit a key, place it in a shared/project MCP config, or post it in logs. Prefer the STRATTA_API_KEY environment variable or the user-scoped ~/.stratta/config.json (stored owner-only, mode 0600). If a key leaks, revoke it at Intégrations › Clés d’API (API keys).

Your account

  • Two-factor authentication, optional, in Settings › Profile › Security: an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password…) gives a six-digit code asked at every password sign-in, and ten backup codes each work once without the phone. Signing in through your company's account follows its directory's rules.
  • Connected devices: the browsers where your account is open; close a session you do not recognise, or all the others at once. Changing your password closes the other sessions too.
  • Phone and backup codes lost: write to hello@stratta.ch. After checking by another channel, Stratta removes two-factor authentication and closes all your sessions.
  • Exposed passwords: at sign-up and on a password change, Stratta refuses a password that appears in a known public breach. The check goes through Have I Been Pwned without ever sending the password: only the first five characters of its SHA-1 hash leave the server.
  • Invitation links: Stratta keeps only the hash of a link, never the link itself. A copy of the database does not let anyone into a space.

Organization isolation

Norms are scoped to your organization and isolation is enforced server-side:

  • Every MCP request is authenticated by your key.
  • The server resolves the key to an organization and filters all reads and writes by it.
  • The organization id is never a client-supplied parameter. It's derived from the key, so a client can't request another organization's data.

See Multi-tenant norms.

Signing in through your directory (Enterprise)

On an Enterprise contract, your people sign in with the Microsoft 365 or Google account they already have, instead of one more password.

What protects your domain:

  • A DNS proof. You publish a TXT record at _stratta-sso.<your-domain>. Without it nothing switches on: claiming a domain you do not control would be helping yourself to the accounts of everyone who writes from it.
  • The right directory, and only that one. We accept a token only if it comes from the Microsoft directory that actually owns your domain. We resolve that with Microsoft, which only admits a domain after its own DNS proof. A work address proves nothing by itself: inside a directory, an administrator writes whatever address they like.
  • Passwords refused, on request. Sign-in, sign-up and password reset all become impossible except through your directory.

There is no directory synchronisation (SCIM). Removing someone from the organization in Stratta cuts their access to the corpus on the very next call, including for an agent that is already connected.

What leaves your machine

  • During queries, the MCP connector sends your API key and your tool arguments (e.g. a norm code and section path) to the Stratta backend, and receives the section content back.
  • During ingestion by your agent, the PDF stays on your machine: the connector only uploads the norm content you extract (text, formulas, tables, figures) to your workspace. Only ingest documents you hold the rights to.
  • When you add a norm from the app (Norms page, "Ajouter une norme"), the PDF itself is uploaded. It is processed on Stratta's own server in Germany (EU): optical character recognition if it is scanned, structure and summaries, formulas and tables transcribed by a language model, then checked against the image of their page by a second model, before a person at Stratta reviews it. The models are reached through OpenRouter: every call requires a zero-retention provider (zdr) that does not collect the data (data_collection: deny), and DeepSeek's own endpoint is excluded. The PDF is deleted as soon as the norm is delivered, refused or withdrawn; the text stays in your organization's corpus, readable by that organization only.
  • When a borehole profile is read (the "Read the PDF profile" button of the site sheet, or "Read a borehole in this document" on a dossier attachment), the PDF page leaves, as an image, for OpenRouter, where a vision model reads it, under the same zero-retention and no-collection requirements. Nothing else from the dossier goes with it.
  • With a remote connector (https://stratta.ch/mcp), there is no API key: the agent's host holds an OAuth token instead. If it asks for the email permission, which ChatGPT does by default, that host can read the address of your account and whether it is verified. This is what lets an enterprise workspace tie the connector to its own domain. The authorization screen says so before you approve, and tool replies never carry the address.

What your organisation deposits, and who sees it

The Word reports you deposit on the Methods page to learn a plan from, the methods you write, the deliverables and their sections, the logged readings and the replies received through a read link follow the same regime as a dossier's attachments: they carry your organisation's identifier and are readable by its members only. A signed, often confidential report does not leave your workspace; the file serves two purposes only, learning the plan and laying out your Word exports, and it goes when you delete the plan.

One piece of data is shared between organisations: the reading of public Geneva borehole profiles (boreholeProfiles). The profile is open cantonal data, reading it with a model costs every office the same, and it says nothing about you: it is pooled. An archive borehole read from an attachment of your own dossier stays with your organisation.

Data residency

The Stratta backend (Convex) and the web platform (Vercel) run on infrastructure located in the United States, and transactional email is sent via Resend. Details and your rights are described in the Privacy policy.

Transport

  • Remote connector: your agent speaks HTTPS to stratta.ch/mcp, with an OAuth 2.1 access token valid for one hour and renewed on its own. The exchange follows PKCE S256 and the authorization code is single-use. You can see and withdraw authorised agents from Connected agents in your workspace.
  • Local server: the connector talks to your client over stdio, and to the backend over HTTPS to *.convex.cloud. Outbound HTTPS must be allowed by your firewall or VPN (see Troubleshooting). Its API key lives until you revoke it.
  • Either way, organisation membership is re-read on every call: removing someone from the organisation cuts their agent off on its very next call, with no token or key to revoke by hand.