Trust Center
When your work goes out for client approval, you are creating a commercial record. Stria is built so that record is trustworthy by design — tamper-evident, verifiable, and yours to keep.
The sign-off model
- Email-verified: a one-time code confirms it was really your client who approved — not an anonymous click.
- Tamper-evident and append-only: each sign-off stores a SHA-256 hash of exactly what was approved, with a server-captured timestamp and IP — no edits, no deletes.
- Isolated at the database: row-level security separates every workspace at the data layer, not just in the interface.
The whole picture
Read the detail: Security & sign-off, Privacy, DPA, and Subprocessors.
What is true today
Row-level security isolates every workspace at the database, not just in the interface. Optional AI drafts feedback summaries and scope classifications; a person reviews and decides. Your workspace exports on request. Stria is not SOC 2 certified and does not claim a completed examination; SOC 2 readiness is in progress, and the full control set and timeline — including what is a target rather than a commitment — are published on our trust roadmap.