Your systems stay yours.

Strata reads the systems you already own — your database, your Microsoft tenant, your Atlassian site — live, at the moment you ask. Apart from the SharePoint content you deliberately add to the Knowledge Base, it does not copy them into a store of its own, and inference runs in your own Azure AI Foundry. The conversation history and audit trail Strata does keep are encrypted, exportable, and yours to delete.

Your data stays where it lives.

Strata never copies your databases, and never sends your prompts to a model Kronisys controls. Files you upload and files Strata generates are held in encrypted Azure storage inside your deployment’s region — exportable, and deletable on your schedule.

The platform is an orchestrator. It asks questions of the systems you already own — on your behalf, with your credentials, against the Foundry running in your tenant.

Your team
Prompts Strata in plain English
TLS 1.2+
Strata
Orchestration & audit
OAuth 2.0
Your Azure tenant
Your Foundry
Your capacity · your billing · your region

OneDrive, Outlook and Teams calls happen with the signed-in user's own delegated Microsoft permissions; database access uses the stored credentials of the connection an admin or the user configured. Jira and Confluence work the same way when your admin chooses per-person sign-in — each member connects their own Atlassian account, and their own Atlassian permissions bound every result. An admin can instead configure one organization account, in which case Atlassian calls run as that account for everyone; that is an explicit choice made in Admin > Organization settings, where the one Atlassian site Strata may reach is also pinned and re-checked on every request.

Defense in depth.

Eight controls protecting your data — each one shown in action below.

Your data
USER STRATA JWT SESSION GRANTED
Entra ID SSO
access_token sql.read SCOPED files.read SCOPED mail.send SCOPED
OAuth 2.0
alice@acmeACTIVE
bob@acmeACTIVE
carol@acmeDEPROV.
dave@acmeSYNCED
SCIM 2.0
YOUR AZURE TENANT strata foundry model all traffic stays inside
In-tenant inference
PLAINTEXT CIPHERTEXT
passworda4b3f1c9
alice@7e8f9a1b
SELECTf3c4b5a6
AES-256-GCM
Encryption
foundry prompt response TRAINING BLOCKED
No training
12:34:01aliceGRANT
12:35:22carolEXPORT
12:36:18adminCREATE
12:37:45systemROTATE
12:38:09bobQUERY
Audit log
ACME GLOBEX INITECH + n no cross-tenant queries
Tenant isolation

Built on Azure.
Owned by us.

Every item below is a control Strata actually implements — how we authenticate, encrypt, isolate, and log. We're not going to list Azure's certifications as if they were ours.

Strata runs on Microsoft Azure, so the underlying infrastructure carries Microsoft's own compliance posture. That's theirs to certify — not ours to claim.

Microsoft SSO Entra ID enforced
AES-256-GCM at rest
TLS 1.2+ in transit
Per-tenant isolation row + connection level
Audit log actor · target · IP
Delegated access delegated by default

Your prompts and responses are never used to train AI models.

Not by Kronisys, not by the model providers reached through Foundry, not by anyone. This is contractual, enforced by Microsoft Azure AI Foundry's enterprise data processing terms — the same terms that govern every Foundry deployment, including yours.

For the full data handling breakdown, see the Privacy Policy or the data architecture guide in the docs.