Jump to handbook document Browse handbook… Design system (visual) Start here · Readme Product and features · Critical Path Product and features · Onboarding Antonios Product and features · Prd Stratify V2 Product and features · Product Design Product and features · V2.1 Roadmap Strategy mandates · Partners Group Directors’ Dealings Tracker (PGHN vs SMI) Strategy mandates · Pelosi Trade Tracker (PTR Backtest) Strategy mandates · Trump Trade Tracker ($TRUMP / DJT / Tariff) Strategy mandates · AI Arms Race Strategy mandates · Europe Defense Strategy mandates · Insider DACH Strategy mandates · Inverse Cramer Strategy mandates · Obesity Strategy mandates · Pelosi Tracker Strategy mandates · Super-Investors Mobile app · Mobile Screenshots (Light / Dark) Mobile app · Mobile Release Design system · Stratify Design System V1 Legal and compliance · Acceptable Use & Asset Management Policy Legal and compliance · Access Control & Identity Management Policy Legal and compliance · Asset & Information Classification Procedure Legal and compliance · Audit Trail Export Format Legal and compliance · B2B Partner Onboarding & Key Provisioning Procedure Legal and compliance · Backup & Restore Procedure Legal and compliance · Bearbeitungsreglement (VDSG Art. 5) Legal and compliance · Breach Notification — Regulatory Procedure Legal and compliance · Business Continuity & Disaster Recovery Test Procedure Legal and compliance · Business Continuity & ICT Resilience Policy Legal and compliance · Change & Release Management Procedure Legal and compliance · Closed Beta Sign Off Checklist Legal and compliance · Competence, Awareness & Training Plan Legal and compliance · Control of Documented Information Legal and compliance · Cryptography & Data Protection Policy Legal and compliance · Data Processing Agreement — Template Legal and compliance · Data Subject Access & Erasure Request Procedure Legal and compliance · Data Subject Rights — Regulatory Procedure Legal and compliance · DPIA / DSFA Screening — Core Product Legal and compliance · Dsgvo Data Flow Legal and compliance · Facts Legal and compliance · Fma Passporting Gate Legal and compliance · HR Security Policy Legal and compliance · Incident Management Policy Legal and compliance · Incident Response Procedure — Dual-Clock Decision Tree Legal and compliance · Information Security Framework Policy Legal and compliance · Information Security Policy Legal and compliance · Internal Audit Programme & Procedure Legal and compliance · ISMS Scope & Context Legal and compliance · Joiner / Mover / Leaver Procedure Legal and compliance · Logging & Monitoring Policy Legal and compliance · Logging, Monitoring & Alerting Procedure Legal and compliance · Management Review — Procedure & Record Template Legal and compliance · Nonconformity & Corrective Action Log Legal and compliance · Operations & Change Management Policy Legal and compliance · Penetration Test & Remediation Procedure Legal and compliance · Pentest Rfp Legal and compliance · Physical & Remote-Working Policy Legal and compliance · PLAN Legal and compliance · Privacy Notices — Inventory & Consistency Check Legal and compliance · Quarterly Access Review Procedure Legal and compliance · Records of Processing Activities — Controller Role Legal and compliance · Records of Processing Activities — Processor Role Legal and compliance · Regulatory Roadmap CH → EEA (Tippgeber → lizenzierter Vermögensverwalter) Legal and compliance · Retention & Deletion Schedule Legal and compliance · Risk Assessment & Treatment Methodology Legal and compliance · Risk Treatment Plan Legal and compliance · Roles, Responsibilities & Authorities (RACI) Legal and compliance · Schema Legal and compliance · Secrets & Key Management Procedure Legal and compliance · Secure Development Policy Legal and compliance · Secure SDLC & Code-Review Gate Procedure Legal and compliance · Security Awareness Training Delivery Procedure Legal and compliance · Security Objectives & Metrics Legal and compliance · Signalgeber Classification Legal and compliance · Statement of Applicability Legal and compliance · Sub-processor List Legal and compliance · Suitability Responsibility Matrix Legal and compliance · Supplier / Sub-Processor Onboarding & Review Procedure Legal and compliance · Supplier & Cloud Security Policy Legal and compliance · Technical and Organisational Measures (TOMs) Legal and compliance · Transfer Impact Assessment — Third-Country Transfers Legal and compliance · Vulnerability & Patch Management Procedure Engineering · Architecture Engineering · Cloudflare Access Engineering · Db Recovery Engineering · Deploy Engineering · Git Signing Engineering · Hetzner Cutover Engineering · Hetzner Power Schedule Engineering · Jenkins Engineering · Partner Order Mapping Engineering · Phase C Endpoints Engineering · Pre Launch Quality Engineering · Production Cutover Engineering · Production Env Engineering · Quickstart Internal ops · B2b Rate Limits Internal ops · Partner Runbook Internal ops · Postman And Screenshots Internal ops · Project Kickoff 2026 05 08 Investor narrative · Stratify Pitch Deck V1 More · 0000 Adr Template More · 0000 Plan Template More · 0001 Adopt Development Operating Standard More · 0002 Email Code Auth Instead Of Links More · Graphify Findings Cleanup
Handbook · Legal and compliance Suitability — responsibility matrix (MiFID II Art. 25(2)) Status (2026-05-19): PARKED — Phase A pre-license. Stratify Signals does not run MiFID-II suitability today. The matrix below describes the post-license state that re-enters when the FMA VVG license is granted (Phase C). Until then the engine in lib/suitability/ does not exist and partners do not delegate suitability to Stratify.Closed-beta / v2.1 baseline. Legal review owns final wording; engineering owns implementation traceability.
Roles Topic Stratify Partner (neobroker) Suitability assessment Performs scoring & pass/fail using Stratify engine on answers submitted via B2B-APICollects answers in partner UX; must not apply own pass/fail for copy-trading eligibilityDisclosure to retail user Provides outcome categories / mandated copy via API errors & B2C surfaces where applicable Presents Stratify-approved disclosures only; no reinterpretation Record retention Stores full answer snapshot + engine output + version hash (audit) Stores correlation ids / partner user refs per DPA KYC / AML Sumsub (or contracted vendor) on Stratify-led B2C flow Partner KYC for their relationship; Stratify KYC for Stratify-regulated activity per flow design Loss-bearing capacity Engine enforces quantitative caps Supplies accurate numeric inputs; does not coerce answers
Evidence bundle (per suitability decision) Minimum fields persisted by Stratify (see lib/suitability/ + audit payloads):
Questionnaire version / schema id Normalised answers (machine-readable) Per-dimension scores, total score, hard-fail codes (if any) Timestamp and actor (partner_api_key id or system) Change control Any change to weights, thresholds, or hard-fail rules requires:
Compliance sign-off Version bump in engine + migration note Regression tests (lib/suitability/engine.test.ts + fixtures) Stratify · wait, what. · Zürich Pre-license phase — research publication, not investment advice.