Security, governance and deployment

Enterprise security, built into the platform.

Choose where OptiFI runs, integrate Microsoft Entra identity, keep data and AI inside the agreed boundary, and maintain a reviewable record of material activity.

Enterprise identity Least-privilege workspaces Encrypted credentials Private AI options Audit & recovery

Built for complex and regulated environments. One control boundary across source data, modelling, reporting, automation and OptiAgent.

Enterprise security controls

Control follows the work.

Identity, permissions and audit should apply to the full decision lifecycle—not disappear after the user signs in.

Access and control

Enterprise identity, precise workspace access.

Connect OptiFI to Microsoft Entra single sign-on and align workspace roles with how people administer, build, approve and consume analytical content.

  • Microsoft Entra SSO for enterprise authentication
  • Workspace roles for administration, design and consumption
  • Role-aware data and report visibility
  • Provisioning automation can be scoped for enterprise deployment
Workspace accessEntra connected
AN
Analytics ownerModels · Reports · Workflows
Owner
FP
FP&A teamPlan · Analyse · Publish
Builder
EX
Executive leadershipPublished reports · Scenarios
Viewer
IA
Internal auditActivity · Evidence · Exports
Reviewer
LP Least privilege

People see what their role requires.

Workspace permissions govern access to sources, datasets, models, reports and workflows. Role-aware report filters keep sensitive organisational rows aligned to the right audience.

CR Protected credentials

Secrets stay out of analytical and agent paths.

Connector credentials are encrypted and handled separately from user-facing analysis. Source access remains bounded to approved connections, queries and actions.

Deployment and data boundary

Choose where your data and compute live.

Match the OptiFI operating pattern to your residency, network and control requirements. Use managed cloud, a private customer environment, on-premises infrastructure or a defined hybrid pattern.

  • Managed cloud for rapid adoption and simplified operations
  • Private environment for customer-controlled boundaries
  • On-premises deployment for isolated or regulated estates
  • Desktop and portable workspace patterns for specialised use
MC
Managed cloudOperated service · scalable capacity
Available
PE
Private environmentCustomer boundary · private AI option
Selected
OP
On-premisesLocal infrastructure · controlled connectivity
Available
HY
HybridDefined source, compute and trust boundaries
Scoped
WI Workspace isolation

Analytical assets remain workspace-scoped.

Sources, imported data, models, reports, workflows and agent context are organised within explicit workspace boundaries with permissioned membership.

SQ Bounded source access

Connectivity does not mean unrestricted reach.

Source queries are designed for controlled, read-oriented access with bounded scope and timing. Workspace administrators decide which connections are available.

Audit and operational visibility

Material activity stays reviewable.

OptiFI records user and system activity across refresh, calculation, publication, workflow and agent execution. The resulting trail supports governance review, operating support and accountability.

  • User-attributed design, publication and administrative activity
  • Task history for refreshes, models and automated workflows
  • OptiAgent prompts, tool runs and affected objects
  • Exception status for operational follow-up
Decision cycle · close packAll controls passed
08:42:11Dataset refreshComplete
08:44:03Model calculateComplete
08:45:18Report publishApproved
08:46:09OptiAgent analysisLogged
08:47:22Executive notifyDelivered
BK Backup and recovery

Protect the workspace, not only the server.

Scheduled backups, workspace export and portable packages support recovery at the level the business understands. Task status makes failures visible.

SE Security engineering

Controls are treated as an operating discipline.

Stratic Analytics reviews its own environment and builds against security practices mapped to recognised SOC and ISO control domains.

OptiAgent security

Private AI, governed like the rest of the platform.

OptiAgent inherits the authenticated user, approved workspace context and allowed tools. The model does not become an unrestricted route around enterprise controls.

Environment-bound intelligence

Keep the model close to the approved data boundary.

OptiAgent can use secure model patterns deployed within the customer environment where data policy, residency or operating risk requires it.

  • Customer-environment model options
  • Approved workspace data and document context
  • Training or adaptation only when customer-approved and scoped
  • Clear separation between model, context and available tools
OptiAgent Identity Tools Audit Context
CX Approved context

The agent sees the work the user is allowed to see.

Governed datasets, reports, model outputs, definitions and approved documentation provide context within the user and workspace permission boundary.

AP Tools and approval

Capability is scoped to the use case.

Available tools are restricted by role and task. Sensitive or material actions can remain draft, require human approval and stay visible in the audit trail.

Framework-aligned assurance

Evidence for the enterprise review.

OptiFI’s current assurance language is precise: controls are designed and operated in line with SOC- and ISO-aligned security practices. Formal certification is not claimed unless supporting certificates are available.

SOC Control mapping Security practices mapped to relevant trust-service control themes.
ISO Aligned practices Governance, access, operations and resilience aligned to recognised domains.
AUD Internal review Stratic Analytics audits its own operating environment continuously.
EV Enterprise evidence Architecture, data-flow and control discussions available during review.

No formal SOC 2 or ISO certification is asserted on this page. Control scope and supporting evidence should be confirmed during the customer security review.

Frequently asked questions

Answers for security, risk and technology teams.

Storage depends on the deployment selected. OptiFI can operate in a managed cloud, private customer environment, on-premises infrastructure or an agreed hybrid pattern. The proposed architecture defines data location and movement before implementation.
Trust is part of the architecture

Review OptiFI against your control environment.

Bring your identity, network, data-residency, AI-governance, audit and recovery requirements. We will map them to the platform and define the right deployment boundary.