Skip to main content
Stokka

Platform · Security

Enterprise security, without the enterprise rollout.

Workforce SSO over SAML and OIDC with break-glass protection, passkeys and TOTP two-factor, an exportable security audit log, and GDPR requests handled inside the product. Hosted on EU servers and built to GDPR principles.

Sign-in

Done properly, from the first login.

Every account gets modern sign-in. Organisations that run an identity provider can enforce it, without ever being able to lock themselves out.

Break-glass

SSO

SAML and OIDC, with a way back in

Workforce SSO with named setup templates for eight identity providers, DNS domain verification, and enforcement mode. Break-glass protection guarantees an IdP outage can never lock out every owner.

Passkeys

Passkeys and TOTP 2FA

Phishing-resistant passkeys, plus TOTP two-factor that also fires on social sign-in, not just passwords.

Passwords

Breach-checked by default

Email and password sign-in checks credentials against known breach corpora. Google sign-in links to existing accounts safely.

Roles

Server-side, everywhere

Owner, admin and member roles enforced server-side across roughly fifty resource types, mirrored in the interface, with email invitations.

Multi-org

One login, isolated companies

Run several fully isolated organisations under one login, each with its own currency, timezone, members and billing.

Alerts

Owners hear about it first

Account-takeover-shaped events, credential changes, new members, trigger automatic owner email alerts.

Audit trail

When the auditor asks, export the answer.

Sign-ins, credential changes, member changes and billing events land in a security audit log you can export. The operational side is covered too: every stock movement in Stokka is an immutable ledger entry where corrections post as reversals.

The security log answers who signed in, from where, and what changed about accounts and access. The stock ledger answers what happened to inventory, with who, when, cost and running balance on every movement, and no way to rewrite history.

Together they make the audit conversation short: export the trail, hand it over, move on with your week.

Security logLast 24 hours
exportable
09:41SSO enforcement enabled · maria@ (owner)
09:12New member invited · dara@ (admin)
08:55Passkey registered · maria@
07:30Failed sign-in · unknown device · owner alerted
ExportCSV · full history

GDPR

Compliance tooling inside the product.

Data subject requests are submitted and tracked from inside the app. Terms and the data processing agreement are versioned, with consent logged. Account deletion is self-serve.

Hosting

EU servers

Built to GDPR principles. You own your data.

Requests

Submit & track

Data subject requests handled in-product.

Consent

Versioned

Terms and DPA versions with consent logging.

Deletion

Self-serve

Account deletion handled in-product.

The interface

Trust is a detail-level habit.

Light and dark themes with test-enforced WCAG AA contrast, 44px touch targets for warehouse tablets, keyboard shortcuts on every list, and honest offline and update-pending states. Security you can see is the same discipline as security you can't.

Stokka · shipping soon

The operating system you've been waiting for.

Inventory, BOMs and orders on one screen. From €299/month with unlimited users; solo founders lock in at €199 for 12 months. Xero, QuickBooks and Shopify sync at launch, with batch traceability and production planning in the box; shop-floor tablet mode follows on the roadmap.