Stratos Technologies helps organisations, families and individuals work with AI through the command line, inside the AI tool they already use. Until now that has been done by hand, in four sessions per team. It works and people love it, but trust has rested on good behaviour. Stratos CLI makes the same experience safe by construction: keys locked away, every action named and recorded, every risky step waiting for a person's yes, and the person responsible (IT, a parent, or the user) able to see everything and switch it off.
Each slice ends with something a real person can use and react to, and security is in the first slice, not bolted on later. The founder uses it first, then families and individuals, then a nonprofit department, then an IT team, then a partner who runs the call without Stratos in the room. Codex now comes before Microsoft, because it is the engine that lets 13–17-year-olds take part with a parent's permission; that re-order is decided and is being written into the next version of the plan.
| 1 | One person, thirty minutes.Install, sign in with the account they already have, connect mail and calendar, and see a live page of their own with a private link. | Product |
| 2 | No key on any laptop.Every login token sits in the gateway vault, one lock per customer. | Security |
| 3 | Every action has a name.Each AI session carries its own identity, tied to its human, in a record nobody can edit. | Audit |
| 4 | Nothing risky without a yes.Sending, publishing, sharing and deleting wait for the person at the moment it happens. | Control |
| 5 | An off switch that works.One person, one family or everyone, stopped in minutes. | Safety |
The design is written, reviewed and approved. No product code exists yet; the first step is company accounts and app verification with Google and Microsoft.
We say "designed to", not "certified". Certifications are a path: data-protection alignment before launch, child-safety rules before any child uses it, SOC 2 and ISO after.
We never see the conversation between a person and the AI. The model is called by the person's own tool on the person's own plan; Stratos only sees actions on mail, files and code. That is a privacy promise, not a gap.
| Parent + teens 13–17 | A family space owned by the parent. Teens use Codex with the parent's permission (Anthropic's consumer terms are 18+; OpenAI allows 13–17 with a guardian's permission). No outside send, share or publish without the parent's yes; private only; weekly summary to the parent. DECIDED |
| Adults, solopreneurs | Their own private space; they are their own guardian. Claude Code or Codex. DECIDED |
| Under 13 | Not served in the first version. DECIDED |
| Nonprofits, companies | Their own organisation, directly with Stratos or through an enabler partner; the IT admin is the guardian. Claude Code first, Codex next. DECIDED |
| Enabler partners | Their own branded build of the same CLI; they may run their own gateway and may leave with their customers' data, which was never Stratos's. No lock-in. DECIDED |
| Enforced everywhere | Everything at the gateway: login, keys, role checks, the just-in-time yes, the secret scan, the audit log, the kill switch. It holds whatever happens on the laptop. |
| Enforced with device management | Laptop settings (which tools the AI may run, which sites it may reach) are locked only where IT manages the machine. Without that they are advice, and the setup pack says so. |
| Advice only | Instructions written for the AI. Useful, never relied on for safety. |
One shared gateway and control plane, EU-hosted.
More copies of the same gateway; same design.
Twenty times the users of growth, about twice the cost.
Plus about $26k of one-off costs. Estimates for infrastructure only, excluding salaries; the AI model itself is on each customer's own plan. RECOMMENDED estimates, not quotes.
| Now · design | Privacy by design; data map; data-processing agreement template; list of subprocessors. |
| First company pilot | Security pack: one-pager, architecture, setup pack, questionnaire answers. Independent security review before any customer reaches the IT stage. |
| Before public launch | UAE data-protection law, GDPR (EU hosting), California privacy law, EU AI Act transparency ("you are working with AI"), Google's security assessment for Gmail access. |
| Before any child user | UAE Child Digital Safety law (compliance window to about January 2027), COPPA, GDPR for children, UK Children's Code; age assurance and recorded parental consent. |
| Growth | SOC 2 Type I, then Type II; then ISO 27001 and ISO/IEC 42001 for AI management. |
Legal points are summarised from public sources and are to be re-verified with counsel.
| The method | Four hand-run sessions per team; strong adoption across three nonprofits and many families and individuals. It needs a Stratos person in every room, so it cannot reach thousands of organisations. |
| Identity | Shared AI logins and shared mailboxes are common; the record often cannot say who did what. |
| Rules | Around 180 written rules across the team brains; none enforced by software. |
| Keys | Two live keys sit in repository history; they are retired as teams move onto the new system rather than by hand beforehand, a risk accepted knowingly. |
| Ownership | Most team brains sit under one personal account; they move into organisations the customers own as part of the transition. |
| The build | Design documents, decisions and plan are in place; no product code yet. The first step is waiting to release the company domain. |