Skip to main content

Trust Center

Security, privacy, and operational trust—documented

Review how Stack-Ops protects customer data, uses Microsoft Azure, develops and operates the service, responds to incidents, and reports compliance status.

Hosted on Microsoft AzureEncryption in transit and at restCustomer data remains customer-ownedNo unverified certification claims

Trust at a glance

Clear controls. Clear ownership. Clear claims.

This page summarizes the protections, responsibilities, and trust resources that matter to customers in clear, practical language.

Last reviewed August 28, 2026

Secure cloud hosting

Securely hosted and managed on Microsoft Azure

Stack-Ops uses Microsoft Azure services to provide a secure, reliable, and professionally managed cloud environment for the application and customer data.

Trust area 01

Security

Layered controls protect access to Stack-Ops, customer workspaces, operational records, and connected systems.

Encryption in transit

HTTPS and TLS help protect data moving between customers, Stack-Ops services, and connected systems.

Platform + application control

Encryption at rest

Customer data and service backups are encrypted at rest using managed Azure data-protection capabilities.

Azure-backed control

Secrets and credentials

Sensitive configuration and integration credentials are protected using secure Azure and application-level controls.

Layered control

Role-based access control

Built-in and eligible custom roles limit what users can view, change, approve, and administer through permission-gated actions.

Application control

Two-factor authentication

Account-level MFA/2FA is supported, with plan-based enforcement controls for organizations that require it.

Identity control

Single sign-on

Microsoft and Google sign-in paths are supported. Advanced SSO and directory-backed options are available on eligible plans.

Plan dependent

Audit logs

Significant platform activity records actor and timestamp context, with audit-log retention determined by the customer plan.

Application control

Tenant isolation

Tenant-scoped records, query filters, and authorization middleware keep customer workspace access within the correct organization context.

Application control

Trust area 02

Infrastructure

Stack-Ops is securely hosted and managed using Microsoft Azure services for a reliable, protected cloud environment.

Secure Azure hosting

Stack-Ops is securely hosted and managed using Microsoft Azure services.

Microsoft Azure

Managed cloud platform

Azure provides a trusted cloud foundation with built-in security, platform maintenance, and resilience.

Azure managed services

Protected environments

Production environments are protected through controlled configuration and restricted administrative access.

Operational control

Monitoring

Service health and operational monitoring support reliability and timely response.

Managed operations

Backups

Managed backup processes help protect customer data and support restoration when needed.

Data protection

Business continuity

Recovery and continuity practices support ongoing service availability.

Operational readiness

Trust area 03

Privacy & Data

Customer ownership, defined processing purposes, documented retention, and clear request channels guide how data is handled.

Customer data ownership

Customers retain ownership of the data and content they upload or create. Stack-Ops receives only the limited rights needed to provide and improve the service.

Defined in Terms

Data use

Customer workspace data is processed to provide, secure, support, and improve the Stack-Ops service, as described in the public Privacy Policy and Data Processing overview.

Documented purpose

Retention

Personal information is retained while an account is active or as needed to provide the service. The Privacy Policy documents deletion or anonymization within 90 days after account deletion, subject to legal exceptions.

Published policy

Deletion and portability

Access, correction, deletion, and portability requests can be sent to privacy@stack-ops.io and are handled subject to applicable legal obligations.

Request process

Data location and transfers

Stack-Ops is hosted on Microsoft Azure. Data handling and international-transfer safeguards are explained in the Privacy Policy.

Published policy

Subprocessors

Stack-Ops uses service providers for functions such as cloud hosting, payments, email, and analytics. Customers can request the current subprocessor information from the privacy team.

Available on request

Data Processing Agreement

Customers can request a DPA or submit privacy due-diligence questions to privacy@stack-ops.io.

Available on request

Trust area 04

Secure Development

Security continues through source control, release validation, dependency maintenance, and restricted production administration.

Code and change review

Application changes are source-controlled and reviewed before release, with build validation used before production deployment.

Development practice

Dependency and security updates

Application dependencies and supported runtimes are reviewed for security updates, while Azure managed services maintain the underlying cloud platform.

Shared responsibility

Vulnerability management

Reported or identified issues are triaged based on severity and potential customer impact. Security reports can be sent to security@stack-ops.io.

Operational process

Secrets management

Production configuration is kept separate from development settings, unsafe static cloud credentials are rejected by default, and supported protected-configuration or workload-identity patterns are preferred.

Production safeguard

Production access controls

Administrative functions require authenticated, authorized roles. Sensitive production operations are limited through role and permission checks.

Restricted access

Trust area 05

Incident Management

A defined response path supports triage, containment, recovery, customer communication, and follow-up when security events occur.

Response process

Potential incidents are assessed for scope and impact, then handled through containment, investigation, remediation, recovery, and post-incident review as appropriate.

Response lifecycle

Customer notification

Affected customers are notified based on confirmed impact, applicable law, and contractual commitments. Timing and detail depend on the facts established during investigation.

Impact based

Security contact

Suspected vulnerabilities, unauthorized access, and security questions can be reported directly to security@stack-ops.io.

Direct reporting channel

Trust area 06

Compliance

Stack-Ops distinguishes its own program status from Microsoft Azure provider certifications and avoids publishing unverified attestations.

GDPR readiness

Published privacy information covers data-subject access, correction, deletion, portability, international transfers, and DPA requests. This is a readiness statement, not a certification or legal guarantee.

Operational readiness

Microsoft Azure compliance

Microsoft Azure maintains its own broad compliance portfolio, including ISO and SOC reports for in-scope Azure services. Those provider attestations support the platform but do not certify Stack-Ops itself.

Provider scope only

Stack-Ops attestations

This Trust Center does not claim Stack-Ops ISO 27001 certification, SOC 2 attestation, or completed penetration testing unless a current, applicable report is available for customer review.

No unverified claims

Need a security or privacy review?

Send a questionnaire, request a DPA or subprocessor list, or ask our team for additional security and privacy information.