StackWeaver is a compliance-engineering company. Security is not a department here — it is the product. Below is what we operate, what we align to, and who we rely on.
Request the security pack →Row-level security enforced in the data layer; access scoped per engagement.
TLS 1.2+ in transit; encrypted storage and integrity-checked artifacts.
Every access, change, and approval is recorded and attributable.
AI proposes; a named reviewer approves. No automated compliance opinion is issued.
Documented detection, containment, notification, and remediation process.
Security posture is evidenced continuously, not captured at audit time.
Our platform and operations are built to these control sets. We are not yet independently certified; the controls are in place and evidenced continuously. Request current audit status from security@.
We use a small set of third-party providers. A current list, including international-transfer mechanisms under NDPA and GDPR, is available on request.
Found a vulnerability? Report it responsibly to security@stackweaver.cloud. We acknowledge, investigate, and remediate, and we credit validated disclosures.
Report a finding →Our operations and the platform are built to SOC 2, ISO 27001, NDPA, and GDPR control sets. We are not yet independently certified; the controls are in place and evidenced continuously. Ask security@stackweaver.cloud for current audit status.
Every customer is isolated at the tenant level with row-level security policies enforced in the data layer. One tenant cannot read another tenant’s evidence, controls, or artifacts.
Least-privilege, role-based access with full audit logging. Engagement team members are bound by confidentiality and non-disclosure agreements. Access is reviewed on a fixed cadence.
Yes — authentication, database, email, and error monitoring are provided by third parties. A current sub-processor list, including international-transfer mechanisms, is available on request.
We operate a responsible-disclosure process at security@stackweaver.cloud. Validate findings responsibly and we will respond and remediate.
Data is encrypted in transit (TLS 1.2+) and at rest. Evidence artifacts are integrity-checked and versioned.