Choose where OptiFI runs, integrate Microsoft Entra identity, keep data and AI inside the agreed boundary, and maintain a reviewable record of material activity.
Enterprise identityLeast-privilege workspacesEncrypted credentialsPrivate AI optionsAudit & recovery
Built for complex and regulated environments. One control boundary across source data, modelling, reporting, automation and OptiAgent.
Enterprise security controls
Control follows the work.
Identity, permissions and audit should apply to the full decision lifecycle—not disappear after the user signs in.
Access and control
Enterprise identity, precise workspace access.
Connect OptiFI to Microsoft Entra single sign-on and align workspace roles with how people administer, build, approve and consume analytical content.
Microsoft Entra SSO for enterprise authentication
Workspace roles for administration, design and consumption
Role-aware data and report visibility
Provisioning automation can be scoped for enterprise deployment
Workspace accessEntra connected
AN
Analytics ownerModels · Reports · Workflows
Owner
FP
FP&A teamPlan · Analyse · Publish
Builder
EX
Executive leadershipPublished reports · Scenarios
Viewer
IA
Internal auditActivity · Evidence · Exports
Reviewer
LP
Least privilege
People see what their role requires.
Workspace permissions govern access to sources, datasets, models, reports and workflows. Role-aware report filters keep sensitive organisational rows aligned to the right audience.
CR
Protected credentials
Secrets stay out of analytical and agent paths.
Connector credentials are encrypted and handled separately from user-facing analysis. Source access remains bounded to approved connections, queries and actions.
Deployment and data boundary
Choose where your data and compute live.
Match the OptiFI operating pattern to your residency, network and control requirements. Use managed cloud, a private customer environment, on-premises infrastructure or a defined hybrid pattern.
Managed cloud for rapid adoption and simplified operations
Private environment for customer-controlled boundaries
On-premises deployment for isolated or regulated estates
Desktop and portable workspace patterns for specialised use
MC
Managed cloudOperated service · scalable capacity
Available
PE
Private environmentCustomer boundary · private AI option
HybridDefined source, compute and trust boundaries
Scoped
WI
Workspace isolation
Analytical assets remain workspace-scoped.
Sources, imported data, models, reports, workflows and agent context are organised within explicit workspace boundaries with permissioned membership.
SQ
Bounded source access
Connectivity does not mean unrestricted reach.
Source queries are designed for controlled, read-oriented access with bounded scope and timing. Workspace administrators decide which connections are available.
Audit and operational visibility
Material activity stays reviewable.
OptiFI records user and system activity across refresh, calculation, publication, workflow and agent execution. The resulting trail supports governance review, operating support and accountability.
User-attributed design, publication and administrative activity
Task history for refreshes, models and automated workflows
OptiAgent prompts, tool runs and affected objects
Exception status for operational follow-up
Decision cycle · close packAll controls passed
08:42:11Dataset refreshComplete
08:44:03Model calculateComplete
08:45:18Report publishApproved
08:46:09OptiAgent analysisLogged
08:47:22Executive notifyDelivered
BK
Backup and recovery
Protect the workspace, not only the server.
Scheduled backups, workspace export and portable packages support recovery at the level the business understands. Task status makes failures visible.
SE
Security engineering
Controls are treated as an operating discipline.
Stratic Analytics reviews its own environment and builds against security practices mapped to recognised SOC and ISO control domains.
OptiAgent security
Private AI, governed like the rest of the platform.
OptiAgent inherits the authenticated user, approved workspace context and allowed tools. The model does not become an unrestricted route around enterprise controls.
Environment-bound intelligence
Keep the model close to the approved data boundary.
OptiAgent can use secure model patterns deployed within the customer environment where data policy, residency or operating risk requires it.
Customer-environment model options
Approved workspace data and document context
Training or adaptation only when customer-approved and scoped
Clear separation between model, context and available tools
OptiAgentIdentityToolsAuditContext
CX
Approved context
The agent sees the work the user is allowed to see.
Governed datasets, reports, model outputs, definitions and approved documentation provide context within the user and workspace permission boundary.
AP
Tools and approval
Capability is scoped to the use case.
Available tools are restricted by role and task. Sensitive or material actions can remain draft, require human approval and stay visible in the audit trail.
Framework-aligned assurance
Evidence for the enterprise review.
OptiFI’s current assurance language is precise: controls are designed and operated in line with SOC- and ISO-aligned security practices. Formal certification is not claimed unless supporting certificates are available.
SOCControl mappingSecurity practices mapped to relevant trust-service control themes.ISOAligned practicesGovernance, access, operations and resilience aligned to recognised domains.AUDInternal reviewStratic Analytics audits its own operating environment continuously.EVEnterprise evidenceArchitecture, data-flow and control discussions available during review.
No formal SOC 2 or ISO certification is asserted on this page. Control scope and supporting evidence should be confirmed during the customer security review.
Frequently asked questions
Answers for security, risk and technology teams.
Storage depends on the deployment selected. OptiFI can operate in a managed cloud, private customer environment, on-premises infrastructure or an agreed hybrid pattern. The proposed architecture defines data location and movement before implementation.
Customer information is used for model training or adaptation only when explicitly approved and scoped as part of the agreed OptiAgent design. Customer-environment model options are available where the model and data must remain inside the customer boundary.
Data sources, imported analytical data, models, reports, workflows and agent context are organised within explicit workspace boundaries. Authenticated membership and roles determine which workspace objects a user may access.
OptiFI combines enterprise authentication with workspace roles and role-aware data visibility. Access can distinguish administration, design, approval and consumption responsibilities, with sensitive report rows aligned to organisational roles.
Connector credentials are encrypted and separated from user-facing analytical and agent context. Connections and queries are scoped to the sources and actions approved for the workspace.
OptiAgent prompts, tool executions, affected workspace objects and task outcomes can be recorded alongside wider user and workflow activity. Exact retention and export requirements are agreed for the deployment.
Yes. The workspace model is designed to grant people only the visibility and capabilities required for their responsibilities. OptiAgent also inherits the user’s permitted context and the tools approved for the task.
OptiFI supports scheduled backup and export workflows, workspace portability and operating-task status. The production recovery design depends on deployment topology, retention policy and the customer’s continuity requirements.
OptiFI is designed and operated in line with SOC- and ISO-aligned security practices, and Stratic Analytics reviews its own environment. This page does not claim formal SOC 2 or ISO certification. Current evidence and scope are discussed during the enterprise security review.
Trust is part of the architecture
Review OptiFI against your control environment.
Bring your identity, network, data-residency, AI-governance, audit and recovery requirements. We will map them to the platform and define the right deployment boundary.