The same controls we build for clients, applied to ourselves.

StackWeaver is a compliance-engineering company. Security is not a department here — it is the product. Below is what we operate, what we align to, and who we rely on.

Request the security pack →

Controls we operate

Tenant isolation & least privilege

Row-level security enforced in the data layer; access scoped per engagement.

Encryption in transit and at rest

TLS 1.2+ in transit; encrypted storage and integrity-checked artifacts.

Full audit logging

Every access, change, and approval is recorded and attributable.

Human-in-the-loop decisions

AI proposes; a named reviewer approves. No automated compliance opinion is issued.

Incident response

Documented detection, containment, notification, and remediation process.

Continuous evidence

Security posture is evidenced continuously, not captured at audit time.

Frameworks we align to

Our platform and operations are built to these control sets. We are not yet independently certified; the controls are in place and evidenced continuously. Request current audit status from security@.

SOC 2
ISO 27001
NDPA
GDPR
PCI-DSS
OWASP

Sub-processors

We use a small set of third-party providers. A current list, including international-transfer mechanisms under NDPA and GDPR, is available on request.

Responsible disclosure

Found a vulnerability? Report it responsibly to security@stackweaver.cloud. We acknowledge, investigate, and remediate, and we credit validated disclosures.

Report a finding →

Common questions

What security standards does StackWeaver align to?

Our operations and the platform are built to SOC 2, ISO 27001, NDPA, and GDPR control sets. We are not yet independently certified; the controls are in place and evidenced continuously. Ask security@stackweaver.cloud for current audit status.

How is client data isolated?

Every customer is isolated at the tenant level with row-level security policies enforced in the data layer. One tenant cannot read another tenant’s evidence, controls, or artifacts.

Who can access my data?

Least-privilege, role-based access with full audit logging. Engagement team members are bound by confidentiality and non-disclosure agreements. Access is reviewed on a fixed cadence.

Do you use sub-processors?

Yes — authentication, database, email, and error monitoring are provided by third parties. A current sub-processor list, including international-transfer mechanisms, is available on request.

How are vulnerabilities reported?

We operate a responsible-disclosure process at security@stackweaver.cloud. Validate findings responsibly and we will respond and remediate.

Do you encrypt data?

Data is encrypted in transit (TLS 1.2+) and at rest. Evidence artifacts are integrity-checked and versioned.