The implementation process is designed for speed and flexibility, primarily by employing a no-code approach known as Identity Orchestration, which removes the need for modifying legacy application code.
No-Code Orchestration Layer: Strata's Maverics platform is deployed as a layer between applications and identity providers (IDPs), eliminating the need for application code changes: This significantly reduces the typical effort and duration associated with identity projects.
Use of Recipes and Cookbooks: The platform utilizes pre-built configuration templates called Recipes and Cookbooks: These accelerate deployment for common use cases like unifying single sign-on (SSO) or migrating apps to a new IDP.
Foundation and Planning Phase: For complex enterprise deployments, the initial phase focuses on foundation setting, planning, and design: This process can typically span from 1 to 6 months depending on the complexity of the current infrastructure.
Automated Identity Fabric: Deployment includes automating the creation of an Identity Fabric: This establishes a flexible, automated foundation for future identity use cases and infrastructure modernization.
Multi-Cloud Agility: The implementation is vendor-agnostic and designed to deploy across multi-cloud, hybrid, or on-premises environments: This ensures the deployment timeline is not bottlenecked by vendor-specific integration complexities.
Customisation
Strata’s core value is its vendor-agnostic nature, offering extensive customization by allowing organizations to orchestrate and manage policies across multiple disparate identity systems from a single control plane.
Vendor-Agnostic Neutrality: The platform is built to connect any existing IDP (Okta, Entra ID, legacy systems) and any application: This allows businesses to choose the best identity solutions without being locked into a single vendor's ecosystem.
Identity Orchestration Policies: Customers can define granular access and security policies centrally in the Strata layer: These policies are then uniformly enforced across all integrated applications, regardless of the underlying identity system.
No-Code Policy Enforcement: Flexible access control mechanisms can be implemented or modified without writing custom development code: This enables rapid and agile adaptation to evolving business or regulatory requirements.
App Fabric Control Plane: The App Fabric unifies governance and access control for all applications across the enterprise: This provides a single point of customization for the entire application portfolio.
Support for AI Agents: Customization extends to securing emerging technologies, enabling organizations to define and enforce identity policies specifically for AI agents: This ensures secure, traceable actions for autonomous systems.
Additional Costs
Strata operates on a subscription-based model, with costs determined by the scope of orchestration, specifically tied to the quantity of applications and identity providers managed.
Subscription-Based Pricing: The primary cost is a recurring subscription fee based on the duration and terms of the executed contract: This entitles the customer to a specified quantity of usage over the contract period.
Usage-Based Dimensions: Pricing is structured around key usage dimensions: The number of Identity Providers integrated and the number of Applications orchestrated are typical billing metrics.
Contract Term Options: Customers can select from various contract lengths: Available terms often include 1-month, 24-month, and 36-month options, allowing for financial flexibility.
Setup/Implementation Costs: Initial setup costs may apply, often involving professional services from Strata or a certified partner: These services cover planning, deployment, and configuration of the platform.
Potential Cloud Infrastructure Costs: The customer is responsible for any separate, underlying cloud infrastructure costs (e.g., AWS, Azure) required to host or run components of the Identity Orchestrator: These must be estimated separately.
Training
Strata provides support through comprehensive documentation, a large library of technical resources, and a robust partner ecosystem for implementation and ongoing managed services.
Extensive Documentation: The company offers detailed online Docs covering installation, configuration, and API references: This allows technical teams to implement and manage the platform independently.
Resource Center and Blog: A comprehensive Resource Center provides whitepapers, guides, reports, and a blog: These resources educate customers on identity orchestration concepts and best practices.
Partner Network Support: Strata works with a wide network of technology and service partners: These partners offer specialized services, including application maintenance, DevOps, and managed security support.
Demo and Sandbox Access: Customers and prospects can access a Sandbox environment or request a demo: This facilitates hands-on training and testing of the platform's capabilities prior to deployment.
Direct Vendor Support: Standard support is provided under the terms of the service agreement: Higher-tier support may be available for mission-critical applications and 24/7 coverage, often through the customer success team.
Security Measures
The platform enhances security by enabling centralized, zero-trust access policies, strong authentication methods, and ensuring security certifications are maintained for the platform itself.
Zero Trust Integration: The platform facilitates a Zero Trust security posture: It enables runtime enforcement and delegated authorization, ensuring no user or AI agent is trusted by default.
Advanced Multi-Factor Authentication (MFA): Strata supports a diverse range of modern MFA methods: These include passwordless access, biometrics, passkeys, and real-time reporting capabilities.
Role-Based Access Control (RBAC): It enables the implementation of fine-grained, least-privileged access controls: This ensures users and applications only have the minimum permissions necessary for their tasks.
Security Portal and Certifications: Strata maintains a dedicated Security Portal and references security certification logos: This implies adherence to formalized standards like SOC 2 or ISO 27001 for its own operations and platform.
Identity Continuity for Resilience: The Identity Continuity product provides high availability and resilience: This protects data and access against potential security outages or failures of the primary identity provider.
Updates
As an enterprise software platform, Strata delivers frequent updates and new features, particularly around emerging technologies like AI identity, with management often handled centrally through the orchestration layer.
Continuous Feature Development: Updates are frequent, reflecting a commitment to adapting to the rapidly evolving IAM landscape: Recent development focuses on integrating and securing new architectures, such as AI Agent identity.
Automated Updates for Platform: Core cloud-based components of the orchestration platform are typically updated automatically by Strata: This ensures customers always have access to the latest security features and protocol support.
Non-Disruptive Deployment: New policies and platform upgrades are designed to be deployed without requiring changes to application code: This minimizes disruption during the update cycle for integrated applications.
Patching and Vulnerability Management: Strata manages security updates and patches for its core orchestration layer: This offloads the responsibility of infrastructure patching from the customer's identity team.
Management via Central Control Plane: Updates to security policies or IDP connections are managed centrally through the Maverics platform interface: This simplifies the management of changes across a distributed application environment.
Data Ownership and Portability
Data ownership remains with the customer, and the platform is specifically designed to maximize data and configuration portability, thereby eliminating identity vendor lock-in.
Customer Retains Data Ownership: Strata acts as an orchestration layer, meaning the primary identity data storage resides within the customer's existing IDPs: This ensures the customer retains full ownership and control of their user data.
No-Code Migration Functionality: The core functionality supports application identity migration between identity platforms: This provides high portability for identity configurations and prevents architectural lock-in.
Use of Standard Protocols: The platform relies on industry-standard authentication protocols like SAML, OIDC, and OAuth: This avoids proprietary data formats and facilitates the easy export and import of application authentication data.
Anti-Vendor Lock-In Design: The architecture is fundamentally built to reduce reliance on any single identity vendor: This ensures the freedom to move or rationalize identity systems without being penalized by data exit costs.
Contractual Data Privacy: Commercial contracts and legal counseling define clear terms on data privacy and security: This legally solidifies the customer's ownership rights and limits Strata's role to data processing and orchestration.
Scaling Up / Down
The platform is inherently scalable, and scaling terms are directly integrated into the subscription model, allowing organizations to adjust usage based on business growth or contraction.
Usage-Based Scaling: The subscription model allows scaling up by simply increasing the licensed quantity of Applications or Identity Providers managed: This ensures the solution can immediately accommodate business growth (e.g., following a merger or acquisition).
Reducing Operational Costs: The platform helps enterprises rationalize redundant IDPs and cut back on maintenance: This results in lower infrastructure and operational costs, facilitating efficient scaling without proportionate spending increases.
Architected for Enterprise Growth: The platform is designed to handle the complexity of large, distributed enterprise environments (e.g., Fortune 500 customers): This confirms its ability to scale to millions of users and thousands of applications.
Flexibility for Contraction: Scaling down involves reducing the contracted number of orchestrated entities upon renewal or contract adjustment: This offers flexibility during periods of application retirement or corporate restructuring.
IDP Rationalization Support: The orchestration layer makes it simple to add new IDPs or retire old ones: This allows the business to scale its identity architecture rapidly in response to organic or inorganic growth.
The terms & conditions for contract renewal and cancellation
Contract terms for renewal and cancellation are clearly defined, typically tied to the chosen subscription period, with a commitment to addressing customer dissatisfaction through mutual agreement.
Defined Contract Cycles: Contracts are issued for specific durations (e.g., 1-month, 24-month, 36-month): These terms dictate the exact cycle for renewal discussions.
Expiration of Entitlements: If a customer chooses not to renew or replace a contract, the entitlements (access to orchestration services) will automatically expire at the end of the term: This mandates proactive renewal management.
Vendor Remedy/Refund Policy: Strata commits to working towards a mutually agreed remedy in a timely manner if a customer is unsatisfied with the service: This demonstrates a good-faith approach to addressing service disputes.
Governed by Commercial Agreements: Renewal and cancellation clauses are explicitly detailed within the Master Service Agreements (MSA) and Statement of Work (SOW): These documents outline notice periods and specific conditions.
Legal Expertise: Strata utilizes corporate legal counsel for negotiating operational and commercial contracts: This ensures that renewal and cancellation terms are legally sound and transparent for complex transactions.
Compliance
Strata's platform significantly aids customers in meeting various compliance standards by enforcing uniform security policies and providing evidence of consistent access controls across their multi-cloud environment.
Aids Compliance Enforcement: The platform's ability to define and apply security settings once across all platforms greatly simplifies compliance reporting and auditing: This ensures consistency needed for frameworks like HIPAA or NIST.
Security Portal Access: Customers can access Strata's Security Portal to review information on the platform's internal compliance and security posture: This transparency supports customer due diligence and internal audits.
Facilitates Data Protection Mandates: The implemented security controls—like MFA, RBAC, and encryption—directly address mandates found in regulations designed to protect sensitive data: This includes PII and financial records.
References Recognized Frameworks: Strata publishes content and solutions addressing major security and compliance frameworks: This indicates alignment with industry standards such as NIST 800-53 and CMMC.
Audit Trail and Observability: Identity Orchestration inherently centralizes access logging and policy enforcement: This provides a consolidated, reliable audit trail necessary to demonstrate compliance during regulatory reviews.