Vianordis
--:--:-- UTCVianordis / ED. 02 / 2026
§ 07 — App support

Stratis

Sovereign file storage for teams that need control beyond shared drives.

Stratis gives regulated teams a tenant-aware file workspace for folders, versions, shares, recovery, storage statistics, and AI-assisted discovery, backed by Keycloak identity, PostgreSQL metadata, and S3-compatible Ceph object storage.

01Problem

Shared drives and raw object buckets do not give enterprises enough operational control.

Teams need to store large files, operational archives, media, and project documents, but generic drives often blur tenant boundaries, make share governance difficult, hide version history, and leave recovery, provenance, and AI workflows fragmented across separate tools.

  • Files spread across personal drives, team folders, object buckets, and ad hoc links.
  • Limited visibility into who owns a file, who can access it, and which version is current.
  • Manual recovery processes after accidental deletion or uncontrolled folder changes.
  • Object storage that is powerful for infrastructure but too raw for business users.
  • AI assistants and media analysis bolted on without tenant-aware access boundaries.
  • Security teams lacking a clean model for tenant isolation, identity gates, and controlled download paths.
02Solution

Stratis turns object storage into a governed file workspace.

Stratis combines a modern web interface with a Fastify API, Keycloak tenant identity, PostgreSQL file metadata, and Ceph RGW object storage. Users work with folders, files, versions, favorites, shares, trash, and assistant workflows while the platform keeps storage access mediated through authenticated APIs.

  • Built for organizations that need managed file storage with tenant isolation and enterprise identity.
  • Maps files and folders to user, team, or project ownership instead of unmanaged personal silos.
  • Streams upload and download through the application API so browsers do not need direct object-store access.
  • Routes the Ask Files assistant through gscBicameral so AI interactions stay inside the tenant-aware GoSec Cloud pattern.
03Benefits

Business file storage without giving up governance.

Stratis is built for teams that need the usability of a shared drive and the control model of tenant-aware infrastructure.

Keep tenant data separated

Every file node is scoped to the caller's tenant, with bucket naming and metadata designed around tenant boundaries.

Reduce file sprawl

Give teams a single workspace for folders, project files, shared-with-me views, favorites, versions, and recoverable trash.

Control collaboration

Share with users, teams, or controlled links using clear permissions such as view, edit, and manage.

Recover from mistakes

Version history and trash workflows help teams restore prior content and undo accidental removals before permanent deletion.

Use AI without bypassing storage governance

Assistant workflows use the tenant's routed AI path instead of giving a separate tool unmanaged file access.

Support media provenance checks

Photo analysis can record C2PA, SynthID, and vision-stage results so teams can track evidence rather than rely on guesswork.

04How it works

How Stratis works

  1. 01

    Authenticate and resolve the tenant

    Users sign in through Keycloak. Stratis validates JWTs, tenant claims, and required groups before file APIs return data.

  2. 02

    Organize files into governed workspaces

    Teams create folders, upload files, assign ownership context, track versions, and store objects in tenant-specific S3-compatible buckets.

  3. 03

    Share, recover, analyze, and assist

    Users manage shares, favorites, storage statistics, trash restore, photo analysis, and Ask Files conversations through controlled application routes.

05Features

What teams can actually do in Stratis.

File and folder workspace

Create folder hierarchies, rename and move nodes, upload files, and keep operational archives organized by user, team, or project ownership.

API-mediated upload and download

Uploads and downloads are proxied through authenticated API routes, keeping direct Ceph RGW access out of the browser path.

Version history

Store file versions with version numbers, object keys, file sizes, checksums, creator metadata, and timestamps.

Share management

Share files with users, teams, or links, apply view, edit, or manage permissions, and support expiry-aware link workflows.

Shared-with-me and favorites

Help users find the files they rely on by separating incoming shares from personally marked important content.

Trash and recovery

Soft-delete files, restore content when mistakes happen, and permanently delete records when retention policy allows it.

Storage statistics

Expose storage usage so teams can monitor capacity, growth, and archive behavior across managed workspaces.

Ask Files assistant

Route file assistance through gscBicameral and the files assistant agent, keeping AI access aligned with tenant context.

Photo analysis

Run staged provenance checks for supported images, including C2PA, SynthID, and vision analysis states with explicit results.

06Architecture

Architecture and security model.

Stratis separates the user interface, API, metadata, identity, and object storage layers so file access can be governed without exposing raw infrastructure endpoints.

  • Next.js frontend using the GoSec Cloud continuum design system and @gsc/auth.
  • Fastify API with PostgreSQL metadata in the files schema.
  • Keycloak tenant mode with required user group gates and admin role mapping.
  • Ceph RGW object storage with bucket-per-tenant naming and S3-compatible access.
  • Frontend rewrites API calls to the in-cluster backend; the API is not directly public.
  • Upload and download streams pass through authenticated backend routes.
  • Assistant traffic is routed through gscBicameral instead of direct provider calls.
  • Kubernetes deployment with network policy restricting object-storage egress paths.
07Use cases

Where Stratis fits.

Regulated team file storage

Give departments a controlled place for operational files, project documents, and long-lived folders.

Project and team archives

Organize records by ownership context and preserve versions for work that needs traceability over time.

Controlled collaboration

Share documents with internal users, teams, or link recipients without losing the governance model around access.

AI-assisted file discovery

Let teams ask questions about files through a routed assistant path that respects tenant boundaries.

Media intake and provenance review

Record image analysis stages and outcomes when teams need evidence about whether media appears original, edited, or AI-generated.

Object-backed business workspaces

Expose Ceph RGW-backed durability through a business-friendly file interface instead of raw bucket operations.

08Integrations

Integrates with the Vianordis platform stack.

Stratis fits into the existing identity, storage, assistant, runtime, and deployment services used across the GoSec Cloud environment.

Keycloak

Keeps access tied to organization accounts, roles, and sign-in policy.

@gsc/auth

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Auth.js

Shows how this service fits into the wider Vianordis environment instead of standing alone.

PostgreSQL

Stores structured service records in a controlled tenant-aware backend.

Ceph RGW

Provides the governed place where service data and files are stored.

S3-compatible object storage

Provides the governed place where service data and files are stored.

gscBicameral

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Fastify

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Next.js

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Kubernetes

Shows how this service fits into the wider Vianordis environment instead of standing alone.

@gsc/continuum

Shows how this service fits into the wider Vianordis environment instead of standing alone.

09Trust

Designed for controlled enterprise storage

Stratis uses identity checks, tenant scoping, API-mediated storage access, and explicit lifecycle metadata to keep file operations governable.

Tenant gate

Tenant claims are required before file APIs expose tenant data.

Identity groups

Required groups gate normal user access, with a separate admin role mapping.

Storage boundary

Object access is mediated through the backend instead of public browser-facing bucket endpoints.

Metadata

File records include ownership, size, object key, version, checksum, and lifecycle timestamps.

Shares

Share records support permission level, recipient type, link token, password field, expiry, and audit metadata.

Recovery

Trash and restore flows help teams recover from deletion before permanent removal.

Network policy

Stratis pod egress is narrowed to the intended object-storage service path.

Analysis integrity

Photo analysis records unavailable or inconclusive stages explicitly instead of inventing certainty.

10 — Pricing

Pricing based on tenant storage, governance scope, and assistant usage.

Stratis is sold as part of the GoSec Cloud application suite. For enterprise deployments, the right plan depends on storage volume, tenant count, sharing rules, media-analysis requirements, migration scope, and whether Ask Files should be enabled.

11FAQ

Questions technical buyers usually ask.

Who is Stratis for?

Stratis is for teams that need managed file storage with tenant-aware identity, object-backed durability, sharing, recovery, and optional assistant workflows.

How is Stratis different from a normal shared drive?

It combines business-friendly file operations with tenant-scoped metadata, Keycloak access controls, version records, recoverable trash, object storage, and API-mediated file access.

Can users access the object store directly?

No. Browser upload and download flows are routed through authenticated Stratis API endpoints instead of exposing raw Ceph RGW access to end users.

Does Stratis support team and project ownership?

Yes. File nodes can be modeled around user, team, or project ownership so storage can match the way work is organized.

What share controls are available?

Stratis supports user, team, and link shares with permission levels such as view, edit, and manage, plus expiry-oriented link metadata.

Does Stratis keep file versions?

Yes. File versions are tracked with version numbers, object keys, sizes, checksums, creator details, and timestamps.

How does the assistant work?

Ask Files conversations route through gscBicameral to the files assistant agent, keeping the AI path aligned with the caller's tenant context.

Can Stratis analyze images for provenance?

Yes. Supported photo analysis records staged checks such as C2PA, SynthID, and vision analysis with explicit verdict and status fields.

12 — Next step

Replace unmanaged file sprawl with governed, tenant-aware storage.

See how Stratis can give your teams a controlled file workspace backed by enterprise identity, object storage, recovery workflows, and AI-assisted discovery.