Strata keeps none of your data.

It runs against the systems you already own — your database, your Microsoft tenant, your Azure AI Foundry. We orchestrate; you keep everything.

Architecture

Your data stays where it lives.

Strata never copies your databases, never stores your files, and never sends your prompts to a model Kronisys controls.

The platform is an orchestrator. It asks questions of the systems you already own — on your behalf, with your credentials, against the Foundry running in your tenant.

Your team
Prompts Strata in plain English
TLS 1.2+
Strata
Orchestration & audit
OAuth 2.0
Your Azure tenant
Your Foundry
Your tokens · your billing · your region

Database queries, OneDrive (SharePoint), Outlook, and Teams calls happen with the signed-in user's own delegated permissions. Strata never holds long-lived integration credentials.

Controls

Defense in depth.

Eight controls protecting your data — each one shown in action below.

Your data
USER STRATA JWT SESSION GRANTED
Entra ID SSO
access_token sql.read SCOPED files.read SCOPED mail.send SCOPED
OAuth 2.0
alice@acmeACTIVE
bob@acmeACTIVE
carol@acmeDEPROV.
dave@acmeSYNCED
SCIM 2.0
YOUR AZURE TENANT strata foundry model all traffic stays inside
In-tenant inference
PLAINTEXT CIPHERTEXT
passworda4b3f1c9
alice@7e8f9a1b
SELECTf3c4b5a6
AES-256-GCM
Encryption
foundry prompt response TRAINING BLOCKED
No training
12:34:01aliceGRANT
12:35:22carolEXPORT
12:36:18adminCREATE
12:37:45systemROTATE
12:38:09bobQUERY
Audit log
ACME GLOBEX INITECH + n no cross-tenant queries
Tenant isolation
Compliance

Built on Azure.
Owned by us.

Every item below is a control Strata actually implements — how we authenticate, encrypt, isolate, and log. We're not going to list Azure's certifications as if they were ours.

Strata runs on Microsoft Azure, so the underlying infrastructure carries Microsoft's own compliance posture. That's theirs to certify — not ours to claim.

Microsoft SSO Entra ID enforced
AES-256-GCM at rest
TLS 1.2+ in transit
Per-tenant isolation row + connection level
Audit log actor · target · IP
Delegated access no shared service account
Data use

Your prompts and responses are never used to train AI models.

Not by Kronisys, not by the model providers reached through Foundry, not by anyone. This is contractual, enforced by Microsoft Azure AI Foundry's enterprise data processing terms — the same terms that govern every Foundry deployment, including yours.

For the full data handling breakdown, see the Privacy Policy or the data architecture guide in the docs.

Need a security review?

Walk our team through your questionnaire on a call. Faster than a PDF, more useful than a brochure.