Explainer
How we protect your data
STRIA checks authorisation on every request, so you reach only your own organisation's data. Passwords are never stored in plain text. Credentials for your systems are stored encrypted, never shown again and handed out only as short-lived leases to work within the access you approved. Changes to members, passwords and access are logged.
Only your organisation reaches your data
On every read and change, STRIA checks that the record belongs to an organisation you are a member of and that your role allows the action. The check runs in STRIA's core, not only in the interface. Each piece of work also gets its own separate workspace, so one engagement cannot read another engagement's or another customer's code.
Accounts and passwords
Passwords are never stored in plain text, only as a hash computed with Argon2id. A password needs at least 12 characters. Repeated failed sign-ins are blocked for a while. The session is kept in a cookie that the page's scripts cannot read. Changing your password signs out your other sessions. Two-factor authentication is handled via STRIA support in this version.
Credentials for your systems
A credential connected under a mandate is stored encrypted in STRIA's vault. It is never shown again, not to you and not to STRIA's team. Work that needs it receives only a short-lived lease, and the lease ends when the work stops, when access is revoked or when it expires. Credentials are masked in what is logged during the work. The mandate itself never contains secrets.
What is logged?
Changes that affect authority are kept in an audit log that cannot be altered afterwards, for example invitations, ended memberships, password changes, approved or revoked access and file downloads. Refused attempts are logged too. At sign-in, details such as IP address and browser are processed. The reason you give when changing or revoking access appears in the mandate's version history.
What you are responsible for
Use a unique password and never share your sign-in. End the membership of anyone who should no longer have access. If you suspect unauthorised access, change your password and tell STRIA without delay.