Keep tenant data separated
Every file node is scoped to the caller's tenant, with bucket naming and metadata designed around tenant boundaries.
Sovereign file storage for teams that need control beyond shared drives.
Stratis gives regulated teams a tenant-aware file workspace for folders, versions, shares, recovery, storage statistics, and AI-assisted discovery, backed by Keycloak identity, PostgreSQL metadata, and S3-compatible Ceph object storage.
Teams need to store large files, operational archives, media, and project documents, but generic drives often blur tenant boundaries, make share governance difficult, hide version history, and leave recovery, provenance, and AI workflows fragmented across separate tools.
Stratis combines a modern web interface with a Fastify API, Keycloak tenant identity, PostgreSQL file metadata, and Ceph RGW object storage. Users work with folders, files, versions, favorites, shares, trash, and assistant workflows while the platform keeps storage access mediated through authenticated APIs.
Stratis is built for teams that need the usability of a shared drive and the control model of tenant-aware infrastructure.
Every file node is scoped to the caller's tenant, with bucket naming and metadata designed around tenant boundaries.
Give teams a single workspace for folders, project files, shared-with-me views, favorites, versions, and recoverable trash.
Share with users, teams, or controlled links using clear permissions such as view, edit, and manage.
Version history and trash workflows help teams restore prior content and undo accidental removals before permanent deletion.
Assistant workflows use the tenant's routed AI path instead of giving a separate tool unmanaged file access.
Photo analysis can record C2PA, SynthID, and vision-stage results so teams can track evidence rather than rely on guesswork.
Users sign in through Keycloak. Stratis validates JWTs, tenant claims, and required groups before file APIs return data.
Teams create folders, upload files, assign ownership context, track versions, and store objects in tenant-specific S3-compatible buckets.
Users manage shares, favorites, storage statistics, trash restore, photo analysis, and Ask Files conversations through controlled application routes.
Create folder hierarchies, rename and move nodes, upload files, and keep operational archives organized by user, team, or project ownership.
Uploads and downloads are proxied through authenticated API routes, keeping direct Ceph RGW access out of the browser path.
Store file versions with version numbers, object keys, file sizes, checksums, creator metadata, and timestamps.
Share files with users, teams, or links, apply view, edit, or manage permissions, and support expiry-aware link workflows.
Help users find the files they rely on by separating incoming shares from personally marked important content.
Soft-delete files, restore content when mistakes happen, and permanently delete records when retention policy allows it.
Expose storage usage so teams can monitor capacity, growth, and archive behavior across managed workspaces.
Route file assistance through gscBicameral and the files assistant agent, keeping AI access aligned with tenant context.
Run staged provenance checks for supported images, including C2PA, SynthID, and vision analysis states with explicit results.
Stratis separates the user interface, API, metadata, identity, and object storage layers so file access can be governed without exposing raw infrastructure endpoints.
Give departments a controlled place for operational files, project documents, and long-lived folders.
Organize records by ownership context and preserve versions for work that needs traceability over time.
Share documents with internal users, teams, or link recipients without losing the governance model around access.
Let teams ask questions about files through a routed assistant path that respects tenant boundaries.
Record image analysis stages and outcomes when teams need evidence about whether media appears original, edited, or AI-generated.
Expose Ceph RGW-backed durability through a business-friendly file interface instead of raw bucket operations.
Stratis fits into the existing identity, storage, assistant, runtime, and deployment services used across the GoSec Cloud environment.
Keeps access tied to organization accounts, roles, and sign-in policy.
Shows how this service fits into the wider Vianordis environment instead of standing alone.
Shows how this service fits into the wider Vianordis environment instead of standing alone.
Stores structured service records in a controlled tenant-aware backend.
Provides the governed place where service data and files are stored.
Provides the governed place where service data and files are stored.
Shows how this service fits into the wider Vianordis environment instead of standing alone.
Shows how this service fits into the wider Vianordis environment instead of standing alone.
Shows how this service fits into the wider Vianordis environment instead of standing alone.
Shows how this service fits into the wider Vianordis environment instead of standing alone.
Shows how this service fits into the wider Vianordis environment instead of standing alone.
Stratis uses identity checks, tenant scoping, API-mediated storage access, and explicit lifecycle metadata to keep file operations governable.
Tenant claims are required before file APIs expose tenant data.
Required groups gate normal user access, with a separate admin role mapping.
Object access is mediated through the backend instead of public browser-facing bucket endpoints.
File records include ownership, size, object key, version, checksum, and lifecycle timestamps.
Share records support permission level, recipient type, link token, password field, expiry, and audit metadata.
Trash and restore flows help teams recover from deletion before permanent removal.
Stratis pod egress is narrowed to the intended object-storage service path.
Photo analysis records unavailable or inconclusive stages explicitly instead of inventing certainty.
Stratis is sold as part of the GoSec Cloud application suite. For enterprise deployments, the right plan depends on storage volume, tenant count, sharing rules, media-analysis requirements, migration scope, and whether Ask Files should be enabled.
Stratis is for teams that need managed file storage with tenant-aware identity, object-backed durability, sharing, recovery, and optional assistant workflows.
It combines business-friendly file operations with tenant-scoped metadata, Keycloak access controls, version records, recoverable trash, object storage, and API-mediated file access.
No. Browser upload and download flows are routed through authenticated Stratis API endpoints instead of exposing raw Ceph RGW access to end users.
Yes. File nodes can be modeled around user, team, or project ownership so storage can match the way work is organized.
Stratis supports user, team, and link shares with permission levels such as view, edit, and manage, plus expiry-oriented link metadata.
Yes. File versions are tracked with version numbers, object keys, sizes, checksums, creator details, and timestamps.
Ask Files conversations route through gscBicameral to the files assistant agent, keeping the AI path aligned with the caller's tenant context.
Yes. Supported photo analysis records staged checks such as C2PA, SynthID, and vision analysis with explicit verdict and status fields.
See how Stratis can give your teams a controlled file workspace backed by enterprise identity, object storage, recovery workflows, and AI-assisted discovery.