We hold ourselves to the
same standard we sell.

Our security, privacy, and compliance posture — published, current, and accountable.

Last updated: April 2026 · Reviewed quarterly

SOC 2 Type II
In Progress
Q3 2026 attestation target
ISO 27001:2022
Internal Programme
ISMS implemented; certification roadmap active
CBN AML Framework
Production-Ready
Internal controls aligned with BSD/DIR/PUB/LAB/019/002
GDPR / NDPR
Production-Ready
DPA available on request
Encryption in transit
TLS 1.3 across all surfaces
Encryption at rest
AES-256 (database, storage, backups)
Access control
SSO + MFA enforced; least-privilege RBAC
Penetration testing
Annual third-party + continuous internal
Vulnerability scanning
Continuous (dependency + container)
Backup cadence
Daily encrypted, 30-day retention
Incident response
24-hour acknowledgement, 72-hour disclosure
Audit logging
Immutable, 12-month retention minimum
ProviderPurposeRegion
Supabase
Application database & auth
EU / US
Cloudflare
CDN, DNS, WAF
Global
n8n (self-hosted)
Workflow automation
EU
Resend
Transactional email
US

We provide 30 days written notice before adding or changing sub-processors.

Responsible disclosure

Found a vulnerability? Please report it confidentially. We acknowledge within 24 hours and will work with you on a coordinated disclosure timeline.

security@stackweaver.cloud →
Documentation requests

For DPA, security questionnaires, or framework attestations, contact our compliance team.

compliance@stackweaver.cloud →

We build trust pages
for our clients, too.

Begin →