> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# What is Lerian STA?

> Lerian STA is your client-owned integration to BACEN's STA file-exchange hub — two-way regulatory file transport with SHA-256 integrity and terminal events.

**Lerian STA** is the client-owned messaging integration between a financial institution and **BACEN's STA (Sistema de Transferência de Arquivos)**, the Banco Central file-exchange hub. It moves regulatory and operational files in both directions. The institution submits files to BACEN (outbound), and BACEN makes files available for the institution to download (inbound).

Lerian STA authenticates every exchange with a stored BACEN operator credential for the institution. It validates BACEN's TLS certificate against the tenant's trust store. It drives each transfer through BACEN's protocol state machine and verifies file integrity by **SHA-256**. It stores inbound artefacts durably and can publish terminal-state facts through separate audit and business outboxes for consumers. It supports a multi-tenant mode with physical database-per-tenant isolation, as well as single-tenant operation, and is API- and event-first.

## What Lerian STA does — and does not — do

***

* It is the **transport and integrity boundary** between the institution and BACEN's file hub. It moves the bytes, authenticates the exchange, verifies the SHA-256, and records the outcome — it does not interpret the file's business content.
* It **does not post to a ledger**. On a completed inbound download, Lerian STA publishes a terminal-state event that carries a claim-check. The consuming domain product (for example, [Lerian SISBAJUD](/en/rails/native/sisbajud/what-is-lerian-sisbajud)) fetches the artefact and reconciles it into **the client's ledger**. The ledger posting belongs to the consumer, not to Lerian STA.
* It supports a **multi-tenant mode** with physical database-per-tenant isolation. In **single-tenant mode**, it uses the default database/pool with no tenant context.

## Who it serves

***

Lerian STA serves financial institutions that operate on BACEN rails and need a governed, auditable path for file exchange with the Banco Central. It can run in single-tenant mode or, when multi-tenancy is enabled, serve multiple institutions in one deployment with isolated databases.

Downstream, it serves the Lerian products that consume the files it delivers. Lerian STA routes each inbound file to a **source product** — the downstream product that owns the file's business meaning. That product subscribes to its own events and takes it from there.

## Glossary

***

| Term                             | Meaning                                                                                                                                                                                            |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Lerian STA**                   | Lerian's client-owned integration to BACEN's file-exchange hub (Sistema de Transferência de Arquivos).                                                                                             |
| **Transfer**                     | One inbound or outbound exchange of a single file between the institution and BACEN, tracked through its lifecycle.                                                                                |
| **Outbound transfer**            | A file the institution submits to BACEN.                                                                                                                                                           |
| **Inbound transfer**             | A file BACEN makes available for the institution to download.                                                                                                                                      |
| **Protocol number**              | The BACEN-assigned identifier for a transfer; the reconciliation and idempotency key.                                                                                                              |
| **Inbound source configuration** | A per-tenant policy binding a BACEN system code to a source product, with polling cadence, credential, retention, and maximum file size.                                                           |
| **Trust store**                  | The tenant's uploaded X.509 root certificates that validate BACEN's TLS certificate.                                                                                                               |
| **Credential**                   | An encrypted BACEN operator password, identified by institution code and operator ID.                                                                                                              |
| **Password rotation**            | The three-phase change of a BACEN password — stage, change at BACEN, promote locally.                                                                                                              |
| **Claim-check**                  | The `object_key`, `sha256`, `size_bytes`, and `file_name` carried on an inbound-success event so a consumer can fetch and re-verify the artefact; `document_type` is included only when non-empty. |
| **Source product**               | The downstream product a discovered inbound file is routed to (for example, Lerian SISBAJUD).                                                                                                      |
| **Lerian SISBAJUD**              | The judicial asset-order product that consumes Lerian STA inbound-file events.                                                                                                                     |

For how Lerian STA sits alongside the other native rails and the partner interfaces, see [Native messaging and partner interfaces](/en/rails/native/native-messaging).
