Jump to handbook document Browse handbook… Design system (visual) Start here · Readme Product and features · Critical Path Product and features · Onboarding Antonios Product and features · Prd Stratify V2 Product and features · Product Design Product and features · V2.1 Roadmap Strategy mandates · Partners Group Directors’ Dealings Tracker (PGHN vs SMI) Strategy mandates · Pelosi Trade Tracker (PTR Backtest) Strategy mandates · Trump Trade Tracker ($TRUMP / DJT / Tariff) Strategy mandates · AI Arms Race Strategy mandates · Europe Defense Strategy mandates · Insider DACH Strategy mandates · Inverse Cramer Strategy mandates · Obesity Strategy mandates · Pelosi Tracker Strategy mandates · Super-Investors Mobile app · Mobile Screenshots (Light / Dark) Mobile app · Mobile Release Design system · Stratify Design System V1 Legal and compliance · Acceptable Use & Asset Management Policy Legal and compliance · Access Control & Identity Management Policy Legal and compliance · Asset & Information Classification Procedure Legal and compliance · Audit Trail Export Format Legal and compliance · B2B Partner Onboarding & Key Provisioning Procedure Legal and compliance · Backup & Restore Procedure Legal and compliance · Bearbeitungsreglement (VDSG Art. 5) Legal and compliance · Breach Notification — Regulatory Procedure Legal and compliance · Business Continuity & Disaster Recovery Test Procedure Legal and compliance · Business Continuity & ICT Resilience Policy Legal and compliance · Change & Release Management Procedure Legal and compliance · Closed Beta Sign Off Checklist Legal and compliance · Competence, Awareness & Training Plan Legal and compliance · Control of Documented Information Legal and compliance · Cryptography & Data Protection Policy Legal and compliance · Data Processing Agreement — Template Legal and compliance · Data Subject Access & Erasure Request Procedure Legal and compliance · Data Subject Rights — Regulatory Procedure Legal and compliance · DPIA / DSFA Screening — Core Product Legal and compliance · Dsgvo Data Flow Legal and compliance · Facts Legal and compliance · Fma Passporting Gate Legal and compliance · HR Security Policy Legal and compliance · Incident Management Policy Legal and compliance · Incident Response Procedure — Dual-Clock Decision Tree Legal and compliance · Information Security Framework Policy Legal and compliance · Information Security Policy Legal and compliance · Internal Audit Programme & Procedure Legal and compliance · ISMS Scope & Context Legal and compliance · Joiner / Mover / Leaver Procedure Legal and compliance · Logging & Monitoring Policy Legal and compliance · Logging, Monitoring & Alerting Procedure Legal and compliance · Management Review — Procedure & Record Template Legal and compliance · Nonconformity & Corrective Action Log Legal and compliance · Operations & Change Management Policy Legal and compliance · Penetration Test & Remediation Procedure Legal and compliance · Pentest Rfp Legal and compliance · Physical & Remote-Working Policy Legal and compliance · PLAN Legal and compliance · Privacy Notices — Inventory & Consistency Check Legal and compliance · Quarterly Access Review Procedure Legal and compliance · Records of Processing Activities — Controller Role Legal and compliance · Records of Processing Activities — Processor Role Legal and compliance · Regulatory Roadmap CH → EEA (Tippgeber → lizenzierter Vermögensverwalter) Legal and compliance · Retention & Deletion Schedule Legal and compliance · Risk Assessment & Treatment Methodology Legal and compliance · Risk Treatment Plan Legal and compliance · Roles, Responsibilities & Authorities (RACI) Legal and compliance · Schema Legal and compliance · Secrets & Key Management Procedure Legal and compliance · Secure Development Policy Legal and compliance · Secure SDLC & Code-Review Gate Procedure Legal and compliance · Security Awareness Training Delivery Procedure Legal and compliance · Security Objectives & Metrics Legal and compliance · Signalgeber Classification Legal and compliance · Statement of Applicability Legal and compliance · Sub-processor List Legal and compliance · Suitability Responsibility Matrix Legal and compliance · Supplier / Sub-Processor Onboarding & Review Procedure Legal and compliance · Supplier & Cloud Security Policy Legal and compliance · Technical and Organisational Measures (TOMs) Legal and compliance · Transfer Impact Assessment — Third-Country Transfers Legal and compliance · Vulnerability & Patch Management Procedure Engineering · Architecture Engineering · Cloudflare Access Engineering · Db Recovery Engineering · Deploy Engineering · Git Signing Engineering · Hetzner Cutover Engineering · Hetzner Power Schedule Engineering · Jenkins Engineering · Partner Order Mapping Engineering · Phase C Endpoints Engineering · Pre Launch Quality Engineering · Production Cutover Engineering · Production Env Engineering · Quickstart Internal ops · B2b Rate Limits Internal ops · Partner Runbook Internal ops · Postman And Screenshots Internal ops · Project Kickoff 2026 05 08 Investor narrative · Stratify Pitch Deck V1 More · 0000 Adr Template More · 0000 Plan Template More · 0001 Adopt Development Operating Standard More · 0002 Email Code Auth Instead Of Links More · Graphify Findings Cleanup
Handbook · Engineering Pre-launch — quality & security bar (v2.1) Status (2026-05-19): Targets still binding. v2.1 surfaces to cover with Lighthouse: /, /walkthrough/*, /feed, /sign-in.Lighthouse / Core Web Vitals Target: Lighthouse ≥ 90 on B2C onboarding URL (mobile), manual monthly. Command (local): Chrome DevTools → Lighthouse → export HTML report to artifacts/lighthouse/. Track LCP / CLS via PostHog + manual Lighthouse runs (Hetzner host, no Vercel Speed Insights). External penetration test Scope: production-like staging + B2B API + admin surfaces. Exit: 0 critical , 0 high unresolved at launch; mediums documented with timeline. Audit replay UI Admin route: /admin/audit — tail of audit_log + global chain verification status. Ongoing CI gate: GitHub Actions (.github/workflows/dos-ci.yml) runs typecheck/lint/test/build + secret scan on every PR; deploy.yml is *intended* to auto-deploy to prod on merge to main but deploy.yml has never successfully run — it dies at the Tailscale step unless TS_OAUTH_CLIENT_ID/TS_OAUTH_SECRET are set as repo secrets. Until they are, every prod deploy is manual (./infra/hetzner/deploy-web-hetzner.sh). Verify with gh run list --workflow=deploy.yml before assuming a merge deployed anything. Local Jenkins (docs/jenkins.md) may still run in parallel — not reconfirmed. Dependabot weekly merges with CI green Review Cloudflare (Access + WAF) rules quarterly Stratify · wait, what. · Zürich Pre-license phase — research publication, not investment advice.