STRATAM io
Australian government demo spine

Security and privacy (AU)

Local-first memory fabric with honest boundaries. Not a foreign multi-tenant memory SaaS.

Principles

  1. Local-first data plane Memory stays in your process / your host volume — not a shadow cloud tenancy.
  2. Lab vs product Lab defaults are not protective. Product path refuses repository-known keys.
  3. Forget honesty channels_run / channels_skipped; backups remain operator-owned.
  4. Sister gates STRATAM mechanisms → MLSB security/utility → VOROR ops.
  5. No foreign agent mint Agents bootstrap with local keys for government demos.

Security angle (what assessors should see)

Full table: Security model.

Assessor quick answers

QuestionAnswer
Where is data stored?In-process fabric; durable path is host-configured.
Who has keys?Host KMS inject via product_fabric / STRATAM_KMS_*.
Can we forget?Logical + product crypto path; replicas out-of-band (documented).
Independent security measure?Pinned MLSB evaluation bags (UNIT). Same-lab unless G8-signed independent review; depth probes are exploratory (citable: false).
Certifications?None claimed for STRATAM itself. Host/deployer SOC2/HIPAA (or equivalent) are separate and not inherited from the library.

10-minute demo script

  1. Cold open — positioning: local fabric, not foreign memory SaaS.
  2. Security model: storage-time controls — authorization, provenance, isolation, poison quarantine.
  3. Privacy AU: residency, custody, and the honesty table above.
  4. Live: product_fabric remember/recall, verify_integrity() (including a tamper flip caught live), then forget — with channels_run / channels_skipped shown, not summarised.
  5. python examples/depth_extensions_demo.py — GM + PM.
  6. Close: you own keys, residency, and evaluation pins.
Quickstart Report a vulnerability

Contact: security@stratam.io

Lab defaults are not protective. Product path refuses repo-known keys. Home · Demo console (non-PHI, outside clinical path)