TRUST & EVALUATION

Clarity is part of the evaluation.

Understand the controls described, the evidence to request and the assurance that has not been published. Make an informed institutional decision.

Functional illustration

EVIDENCE POSITION

Descriptions and assurance
are not the same thing.

Based on the supplied feature inventory dated 10 September 2026. Reconfirm the position during procurement.

Documented in inventory

Institutional controls

Role-based access, tenant isolation, scoped credentials, approval and operational evidence are described.

Not available in supplied evidence

SOC 2 report

The inventory explicitly says that Stretus currently has no SOC 2 report.

Not available in supplied evidence

ISO 27001 certification

The inventory explicitly says that Stretus is not currently ISO 27001 certified.

No publishable summary

Third-party penetration test

A publishable third-party penetration-test summary is not available in the supplied evidence.

Not published in supplied evidence

Named team profiles

The operating company is identified. Named team profiles remain a content and diligence gap.

Requires technical discovery

Deployment assurance

Verify residency, isolation, recovery, access and support against the proposed deployment.

MAKE DILIGENCE ACTIONABLE

Request the artefact.
Review the boundary.

Not every artefact is currently available. Request confirmation of availability rather than assuming a data room exists.

Start an evaluation enquiry
  1. Architecture and data flow for the proposed deployment.
  2. Permission, credential and tenant-boundary demonstrations.
  3. A representative strategy approval and order-evidence record.
  4. Incident, change, backup and recovery responsibilities.
  5. Executed contractual terms and relevant security evidence.

START WITH YOUR REQUIREMENTS

Start with your diligence requirements.

Share the evidence and operating constraints your institution needs to evaluate.