FAQ
Questions we get asked.
For information governance and operations
Does this replace our officer?
No. It does the finding, marking, checking and recording. Your officer still decides what is disclosed, what is withheld and why, and the DPO still signs off. Nothing leaves without a person saying yes.
Do we have to change how we work?
Requests still arrive the way they arrive. Your team still owns the decisions. What changes is that the register, the search, the review and the evidence pack happen in one place instead of across a spreadsheet, a shared mailbox and a redaction tool.
Can it tell a STAIRs request from a subject access request?
Yes. Requests are typed on arrival and each runs under its own clock, exemptions and appeal route. A request that is really both is split into linked cases.
What happens if our officer is off sick or leaves?
Every case holds its own history: what was asked, searched, found, decided and by whom. Anyone with the right role can pick it up where it was left. The evidence pack is built as you go, not reconstructed afterwards.
How do you handle third-party data?
Every document is shown with the requester's data marked and everyone else's flagged by type: staff, contractor, neighbour, third party, child. Your officer decides on each. Redactions are burned in, and every outgoing file is re-read independently before release.
What if the request comes from a solicitor?
Authority is checked and recorded on the case. The register shows you patterns, such as the same template arriving from the same firm. The response is built to the same evidence standard as any other, so it stands up when the claim is issued.
How long does it take to set up?
Typically six to eight weeks from signed order to live, including deployment, connectors, register migration, training and a parallel run on real requests before go-live.
Can we try it before we buy?
Yes. Pick one request. Run it through your current process and ours, compare the hours, the records found and the redactions caught, then decide.
What does it cost?
An annual licence by volume: £20,000 for up to 50 requests a year, £30,000 for 51 to 100, £50,000 for unlimited. All request types count towards the one band. Setup from £10,000 depending on the connectors you need. All prices plus VAT.
For IT and information security
Is this SaaS or self-hosted?
Self-hosted by default. The service runs inside your own Microsoft Azure environment, so documents, extracted data, results, backups and logs stay within your perimeter. A fully managed SaaS option hosted by Strata on Azure in the UK is also available.
What infrastructure do we have to provide?
An Azure subscription or resource group and approval of the deployment. We deploy with pre-built infrastructure-as-code onto standard Azure services and give you sizing guidance before we start.
Do you charge for compute and storage?
No. Azure consumption is billed to your own subscription by Microsoft. We give you cost estimates before deployment. AI processing is metered and logged per document.
Where is the data held?
You choose the Azure region, typically UK South. All stored data stays in your subscription, tenancy and chosen region.
Does any data leave our environment?
No document content and no personal data. The service runs as an agent inside your perimeter: documents, extracted data, search results, redaction decisions, backups and logs stay in your Azure tenancy, and the AI reading step runs against a model resource inside that tenancy, so documents are never sent to a shared service and are never used to train models. The only data that reaches Strata is operational metadata: counts, hashes, version and licence checks, and error reports with no content in them. We will walk your information security lead through exactly what crosses the boundary.
How do we sign in?
The service is registered as an application in your own Entra ID. Staff use their existing account. Your MFA and conditional access policies apply automatically. No cross-tenant consent is needed.
Is there role-based access control?
Yes. Roles govern who can open a case, search, decide, review and release. Permissions are enforced on the server for every action.
How do the connectors authenticate?
With your own managed identity inside your tenancy. No stored secrets. Credentials and keys are held in your Azure Key Vault. Connectors are read-only, scoped to the records a case needs, and logged on every call.
What encryption is used?
TLS 1.2 or higher for all traffic: browser to platform, service to service, and to the AI service. AES-256 at rest through Azure Storage and Azure Cosmos DB encryption.
What about availability, redundancy and disaster recovery?
Containerised services that Azure restarts and scales automatically, with health monitoring, alerting and self-retrying queues set up at deployment. Database and storage replication configured at deployment. The whole environment is scripted, so it can be rebuilt quickly. A DR runbook is provided and can be aligned with your own arrangements.
Backups, RPO and RTO?
Continuous point-in-time database backup plus replicated document storage, inside your own subscription. Target RPO in minutes, target RTO under four hours. You can align the settings with your own policies.
Data retention?
Configurable and under your control. Individual cases and documents can be deleted on demand, and everything stays in your subscription at contract end.
Does Strata have access to our data?
No standing access. Deployment and support use time-limited, audited access that you grant, or you run the deployment with our guidance. Updates arrive as tested releases for you to approve.
Is there an incident response plan?
Yes, a joint model. Strata's tested plan covers the software and the release process; your own security operations cover the environment. Runbooks are provided at deployment.
Accessibility?
Designed to meet WCAG 2.2 AA in line with the GDS Service Standard, with accessible component patterns and keyboard and screen-reader testing. An accessibility statement is maintained and a formal audit is planned.
How is the AI kept honest?
It never decides. It finds, marks, suggests and checks. Every extracted field carries a confidence score; low-confidence reads are re-checked with a stronger model, and anything still uncertain is flagged for a person rather than guessed. Every outgoing file is re-read independently before release. Every AI call is logged with its cost.
Which housing associations use it?
References available on request.