Stratos CLI

Architecture review · 28 Sep 2026 · design at 736afdb · rendered by arch-lens · the right-hand side is designed and approved, not yet built

Stratos Technologies helps organisations, families and individuals work with AI through the command line, inside the AI tool they already use. Until now that has been done by hand, in four sessions per team. It works and people love it, but trust has rested on good behaviour. Stratos CLI makes the same experience safe by construction: keys locked away, every action named and recorded, every risky step waiting for a person's yes, and the person responsible (IT, a parent, or the user) able to see everything and switch it off.

works today partly there absent a risk designed, not built

Today

CURRENTworks by hand, trusted by habit
① People today
Founder runs every enablementNonprofit teams · ~80 peopleFamilies · individualsPartner, not yet an enabler
▼
② The engine, used directly
Claude CodeShared loginsWhoever-is-logged-in connectorsCodex
▼
Rules written as text
Every “ask before sending” and “never read another team’s brain” lives in an editable instruction file. Nothing enforces it.
③ Where the work lives
~25 team brain reposOne personal account owns themTwo public sitesNo branch protection
▼
④ Keys and access
Secrets in historyPasswords in a sheetVendor admin everywhereNo audit trail
▼
⑤ The design desk
Operating sheetDated decisionsSession ledgerApproved planCompany accounts
The break: the method works and people love it, but trust rests on good behaviour. Logins are shared, keys sit where agents can read them, and every rule is a sentence someone can delete.

Designed

PROPOSEDsame work, safe by construction
① Who it serves
Families · parents + teensSolopreneursNonprofits · company pilotsEnablers · partners
▼
② The person’s laptop
Claude CodeCodexstratos CLIModel, called directlyManaged settings
▼
③ Stratos gateway — the locked room
Key vault · one lock per tenantAgent identityUntrusted content markedKill switch
▼
Role check · just-in-time yes · secret scan
Every call checked against the person’s role. Sending, publishing, sharing or deleting waits for the person’s yes — a parent’s yes for a teen. No commit lands carrying a secret.
④ Places the customer owns
Google · Microsoft 365Their GitHub organisationTheir security log
▼
⑤ The record and the off switch
Write-once audit logAlertsRegistry · packagesDecision-maker console
The join: the same work, but every key is locked, every action carries a name, every risky step waits for a human yes, and the person responsible can see it all and switch it off.

The build, slice by slice

plan approved 23 Sep 2026 · weeks counted from the day Google releases the company domain

Each slice ends with something a real person can use and react to, and security is in the first slice, not bolted on later. The founder uses it first, then families and individuals, then a nonprofit department, then an IT team, then a partner who runs the call without Stratos in the room. Codex now comes before Microsoft, because it is the engine that lets 13–17-year-olds take part with a parent's permission; that re-order is decided and is being written into the next version of the plan.

Weeks from the domain release
W1–2
W3–4
W5–6
W7–8
W9–10
W11–12
W13–14
W15–16
W17–18
W19–20
W21–22
W23–24
W25–26
Who tries it first
founder, then families
first department
first IT team
first enabler
teens on Codex
Product slices
0 · Foundations accounts, verification, GitHub App
waiting
1 · One person, 30 minutes login, connect, first live page; security built in
2 · A department capture, publish, undo, Friday summary
3 · IT can say yes deploy pack, request-and-unlock, gateway in their cloud
4 · Enablers branded CLI, enabler admin, handbook
5a · Codex teens 13–17 with a parent’s permission
moved earlier
5b · Microsoft 365 mail, calendar, files, Entra login
Alongside
Independent security review before any customer reaches slice 3
T · Existing brains move across into customer-owned organisations
continuous

What is true at the end of slice 1

1One person, thirty minutes.Install, sign in with the account they already have, connect mail and calendar, and see a live page of their own with a private link.Product
2No key on any laptop.Every login token sits in the gateway vault, one lock per customer.Security
3Every action has a name.Each AI session carries its own identity, tied to its human, in a record nobody can edit.Audit
4Nothing risky without a yes.Sending, publishing, sharing and deleting wait for the person at the moment it happens.Control
5An off switch that works.One person, one family or everyone, stopped in minutes.Safety

What we can honestly say today

The design is written, reviewed and approved. No product code exists yet; the first step is company accounts and app verification with Google and Microsoft.

We say "designed to", not "certified". Certifications are a path: data-protection alignment before launch, child-safety rules before any child uses it, SOC 2 and ISO after.

Bars are solid where the work is understood and pale where it depends on the re-order still being written into the plan. Estimates, re-planned after slice 1: a shape to argue with, not a promise.

The detail

Stratos CLI · architecture review · 28 Sep 2026 · labels: EXISTS verified · DECIDED confirmed by Stratos · RECOMMENDED proposed, not yet agreed

The five promises

  1. Your work stays yours. Company brains live in a GitHub organisation the customer owns; Stratos's app is a guest they installed and can remove in one click. Stratos staff hold no personal access. DECIDED
  2. Nobody holds your keys but the locked room. Login keys live only in the gateway's vault, one lock per customer, never on laptops and never in files the AI can read. DECIDED
  3. Every action has a name on it, and the record cannot be edited. Person, their agent, what, when, in a write-once log the customer can copy into their own security system. DECIDED
  4. Risky things need a "yes" at the moment they happen. Sending outside, publishing, deleting, sharing, bulk reading. For a teen, the yes is the parent's. DECIDED
  5. Someone responsible can always pull the plug. IT for a company, a parent for a family, the person for themselves, from the decision-maker console, in minutes. The console shows and switches; nobody chats or works there. DECIDED

We never see the conversation between a person and the AI. The model is called by the person's own tool on the person's own plan; Stratos only sees actions on mail, files and code. That is a privacy promise, not a gap.

Who it serves, and who is the guardian

Parent + teens 13–17A family space owned by the parent. Teens use Codex with the parent's permission (Anthropic's consumer terms are 18+; OpenAI allows 13–17 with a guardian's permission). No outside send, share or publish without the parent's yes; private only; weekly summary to the parent. DECIDED
Adults, solopreneursTheir own private space; they are their own guardian. Claude Code or Codex. DECIDED
Under 13Not served in the first version. DECIDED
Nonprofits, companiesTheir own organisation, directly with Stratos or through an enabler partner; the IT admin is the guardian. Claude Code first, Codex next. DECIDED
Enabler partnersTheir own branded build of the same CLI; they may run their own gateway and may leave with their customers' data, which was never Stratos's. No lock-in. DECIDED

What is enforced, and what is only advice

Enforced everywhereEverything at the gateway: login, keys, role checks, the just-in-time yes, the secret scan, the audit log, the kill switch. It holds whatever happens on the laptop.
Enforced with device managementLaptop settings (which tools the AI may run, which sites it may reach) are locked only where IT manages the machine. Without that they are advice, and the setup pack says so.
Advice onlyInstructions written for the AI. Useful, never relied on for safety.

How it scales, and what it costs to run

Pilot · up to 50 users

~$410 / month

One shared gateway and control plane, EU-hosted.

Growth · ~1,000 users

~$4k / month

More copies of the same gateway; same design.

Scale · ~20,000 users

~$8.5k / month

Twenty times the users of growth, about twice the cost.

Plus about $26k of one-off costs. Estimates for infrastructure only, excluding salaries; the AI model itself is on each customer's own plan. RECOMMENDED estimates, not quotes.

The compliance path

Now · designPrivacy by design; data map; data-processing agreement template; list of subprocessors.
First company pilotSecurity pack: one-pager, architecture, setup pack, questionnaire answers. Independent security review before any customer reaches the IT stage.
Before public launchUAE data-protection law, GDPR (EU hosting), California privacy law, EU AI Act transparency ("you are working with AI"), Google's security assessment for Gmail access.
Before any child userUAE Child Digital Safety law (compliance window to about January 2027), COPPA, GDPR for children, UK Children's Code; age assurance and recorded parental consent.
GrowthSOC 2 Type I, then Type II; then ISO 27001 and ISO/IEC 42001 for AI management.

Legal points are summarised from public sources and are to be re-verified with counsel.

What was found, today

The methodFour hand-run sessions per team; strong adoption across three nonprofits and many families and individuals. It needs a Stratos person in every room, so it cannot reach thousands of organisations.
IdentityShared AI logins and shared mailboxes are common; the record often cannot say who did what.
RulesAround 180 written rules across the team brains; none enforced by software.
KeysTwo live keys sit in repository history; they are retired as teams move onto the new system rather than by hand beforehand, a risk accepted knowingly.
OwnershipMost team brains sit under one personal account; they move into organisations the customers own as part of the transition.
The buildDesign documents, decisions and plan are in place; no product code yet. The first step is waiting to release the company domain.