Stratify
Legal and compliance

ISMS Scope & Context

docs/compliance/isms/governance/GOV-01-scope-and-context.md

Source updated 03. Aug. 2026

ISMS Scope & Context

Satisfies ISO/IEC 27001:2022 clauses 4.1 (understanding the organization and its context), 4.2 (understanding the needs and expectations of interested parties), and 4.3 (determining the scope of the ISMS). All factual claims below are grounded in `register/facts.md`; this document does not re-derive them, only frames them for the ISMS.

1. Purpose

This document defines what the stratify ISMS covers, who it answers to, and what it deliberately excludes. It exists so that every later governance, policy, and procedure document (and, if ever engaged, an external auditor or a B2B partner's security reviewer) can point to a single, unambiguous boundary rather than an implicit or shifting one.

2. External context

  • Stage and posture. Stratify is a pre-seed, Zürich-based copy-investing product currently

operating in a pre-license, research-publication posture (docs/compliance/signalgeber- classification.md) — it publishes curated rebalancing signals across a fixed set of strategy mandates rather than offering personalized investment advice. This positioning is deliberate and operationally maintained (no per-recipient personalization, no order routing, no custody); see regulatory-roadmap-ch-eea.md for the regulatory ladder this sits at the bottom of.

  • Regulatory trajectory. The product is designed to escalate through a known ladder — Swiss

Beraterregister, then FINIG, and in parallel a Liechtenstein FMA VVG license for EEA MiFID passporting (Phase C) — meaning today's ISMS scope will need to widen (KYC, Stripe Connect payouts, MiFID-II suitability) once that license lands. This document describes the scope as it is today, not the target-state scope.

  • Data-subject base. Subscribers are drawn from the EEA and Switzerland; the product's primary

privacy exposure is therefore dual-track GDPR and revDSG, not a single-jurisdiction regime.

  • Interested external parties who will read this ISMS or ask questions it should answer:

neobroker/B2B partners integrating against the REST/webhook/MCP surface, pilot strategy authors, prospective institutional investors during fundraising diligence, and — once relevant — the FMA Liechtenstein, EDÖB (Switzerland), and EEA member-state DPAs.

3. Internal context

  • No separate Stratify legal entity is incorporated yet. wait, what. Advisory is the

controller of record today (register/facts.md, "Entity"), matching the placeholder already used in docs/compliance/dsgvo-data-flow.md:10. This is a known, temporary state — see §6.

  • Production is real and live, not a pre-launch target architecture: self-hosted on a single

Hetzner host (Docker + Traefik + self-hosted Supabase EU), cut over from Vercel on 2026-06-03 (docs/runbooks/hetzner-cutover.md, docs/runbooks/production-cutover.md). The ISMS is retrofitting governance around a running system with real subscriber and signal data.

  • Team. Engineering is effectively single-person (Toby; confirmed via git log, one human

identity across all commits). Antonios (co-founder, Product & Compliance) owns the FMA license and DSGVO workstream but does not touch code. Philipp (co-founder, Structuring & Sales) owns pilot acquisition and the structured-wrapper architecture and likewise does not touch code. This shapes the ISMS role assignment in GOV-03 and is the direct cause of the segregation-of-duties gap tracked as RISK-002.

  • Documentation drift. Several existing compliance documents (dsgvo-data-flow.md,

pentest-rfp.md, infra/hetzner/README.md, docs/secrets.md, the top-level README.md) still describe the pre-cutover Vercel/Resend architecture. This is a real, tracked gap (RISK-001), not something this ISMS assumes away — the Hetzner runbooks, not those documents, are the source of truth for current hosting.

4. Interested parties and their requirements

PartyInterestWhat they need from the ISMS
Subscribers (B2C)Their personal data and financial-signal history are handled lawfully and securelyGDPR/revDSG-compliant processing, a working data-subject-rights path, breach notification if it matters to them
B2B / neobroker partnersThe audit-log and API integrity claims made to them hold upEvidence behind the chain-hashed audit log, a security posture they can reference in their own due diligence, DPA coverage
Pilot strategy authorsTheir drafts and identity data are protected; approval process is auditableRBAC correctness, 4-eyes approval trail in audit_log
wait, what. Advisory (controller of record)Not exposed to liability from a product it doesn't fully own operationallyA scope boundary that clearly separates Stratify's data processing from the rest of the Advisory practice
Prospective investorsSecurity/compliance maturity is honestly represented, not oversold, ahead of a funding roundAn accurate, gap-aware documentation set rather than a certification-shaped fiction
Future FMA Liechtenstein regulator (Phase C)MiFID-II-equivalent conduct and security obligations will be met once licensedA documented trajectory from today's posture to license-ready controls
EDÖB / EEA member-state DPAsGDPR/revDSG obligations are met for EEA and Swiss data subjectsRoPA-equivalent documentation (dsgvo-data-flow.md, formalised in PRIV-01/02), lawful transfer basis for third-country processors

5. ISMS scope statement

The ISMS covers the stratify product — web, mobile, and the B2B API — and the Hetzner-hosted infrastructure it runs on.

5.1 In scope

  • apps/web (Next.js 15, subscriber, pilot, admin, and partner-facing surfaces)
  • apps/mobile (Expo SDK 52, iOS + Android)
  • The B2B REST/webhook/MCP API surface (openapi/stratify-api.yaml)
  • The Hetzner production host: Docker + Traefik + self-hosted Supabase EU (Postgres, Auth/GoTrue,

Realtime, Storage), the pull-based systemd deploy timer, and the nightly backup mechanism

  • The CI/CD pipeline that gates changes to the above (dos-ci.yml)
  • Personal and financial-signal data processed through any of the above, regardless of which

legal entity technically holds the controller role today

5.2 Explicitly out of scope

  • The wait, what. Advisory entity's other ventures and mandates. Stratify is a distinct

product and data boundary even though it currently shares a controller entity with Advisory pre-incorporation — Advisory's other client work, other portfolio companies, and unrelated infrastructure are not covered by this ISMS.

  • wait, what. marketing and other web properties, if any exist outside the stratify product

surface listed in §5.1 (e.g. the general wait-what.co site) — these are not part of Stratify's data-processing boundary and are not assessed here.

  • The Phase C structured-wrapper / FMA-licensed architecture insofar as it doesn't yet exist

in running code (KYC, Stripe Connect payouts, MiFID-II suitability engine). Once that code goes live, this scope statement needs to be revisited, not silently assumed to already cover it.

  • Physical premises and facilities — Stratify has no Stratify-controlled office or datacenter; the

only physical infrastructure in scope is the rented Hetzner server, whose physical security is Hetzner's control (see the Annex A 7.x controls in register/controls.yaml, scored not_applicable for this reason).

6. Controller of record — a known open item

wait, what. Advisory is the controller of record today because no separate Stratify legal entity is incorporated. This is confirmed and current as of this document's version, but it is exactly the kind of fact that goes stale quietly: this statement, and every document that cites it (notably PRIV-01/02 and any DPA Stratify signs as controller), must be re-verified once Stratify AG/GmbH incorporates, and the ISMS scope statement in §5 updated to name the new entity rather than wait, what. Advisory. Until then, this document is the canonical statement of that fact for ISMS purposes — see register/facts.md for the underlying citation trail.

7. Review triggers

This scope statement should be reviewed on the annual cadence set in GOV-02, and additionally whenever any of the following occur: Stratify AG/GmbH incorporation, a material infrastructure change (the Vercel → Hetzner cutover of 2026-06-03 is the standing example of a change that should have triggered this kind of review and didn't — see GOV-13), the FMA Liechtenstein license grant (Phase C), or the addition of a materially new product surface (e.g. Stripe Connect payouts going live).