Encryption in transit
HTTPS and TLS help protect data moving between customers, Stack-Ops services, and connected systems.
Trust Center
Review how Stack-Ops protects customer data, uses Microsoft Azure, develops and operates the service, responds to incidents, and reports compliance status.
Trust at a glance
This page summarizes the protections, responsibilities, and trust resources that matter to customers in clear, practical language.
Last reviewed August 28, 2026
Secure cloud hosting
Stack-Ops uses Microsoft Azure services to provide a secure, reliable, and professionally managed cloud environment for the application and customer data.
Trust area 01
Layered controls protect access to Stack-Ops, customer workspaces, operational records, and connected systems.
HTTPS and TLS help protect data moving between customers, Stack-Ops services, and connected systems.
Customer data and service backups are encrypted at rest using managed Azure data-protection capabilities.
Sensitive configuration and integration credentials are protected using secure Azure and application-level controls.
Built-in and eligible custom roles limit what users can view, change, approve, and administer through permission-gated actions.
Account-level MFA/2FA is supported, with plan-based enforcement controls for organizations that require it.
Microsoft and Google sign-in paths are supported. Advanced SSO and directory-backed options are available on eligible plans.
Significant platform activity records actor and timestamp context, with audit-log retention determined by the customer plan.
Tenant-scoped records, query filters, and authorization middleware keep customer workspace access within the correct organization context.
Trust area 02
Stack-Ops is securely hosted and managed using Microsoft Azure services for a reliable, protected cloud environment.
Stack-Ops is securely hosted and managed using Microsoft Azure services.
Azure provides a trusted cloud foundation with built-in security, platform maintenance, and resilience.
Production environments are protected through controlled configuration and restricted administrative access.
Service health and operational monitoring support reliability and timely response.
Managed backup processes help protect customer data and support restoration when needed.
Recovery and continuity practices support ongoing service availability.
Trust area 03
Customer ownership, defined processing purposes, documented retention, and clear request channels guide how data is handled.
Customers retain ownership of the data and content they upload or create. Stack-Ops receives only the limited rights needed to provide and improve the service.
Customer workspace data is processed to provide, secure, support, and improve the Stack-Ops service, as described in the public Privacy Policy and Data Processing overview.
Personal information is retained while an account is active or as needed to provide the service. The Privacy Policy documents deletion or anonymization within 90 days after account deletion, subject to legal exceptions.
Access, correction, deletion, and portability requests can be sent to privacy@stack-ops.io and are handled subject to applicable legal obligations.
Stack-Ops is hosted on Microsoft Azure. Data handling and international-transfer safeguards are explained in the Privacy Policy.
Stack-Ops uses service providers for functions such as cloud hosting, payments, email, and analytics. Customers can request the current subprocessor information from the privacy team.
Customers can request a DPA or submit privacy due-diligence questions to privacy@stack-ops.io.
Trust area 04
Security continues through source control, release validation, dependency maintenance, and restricted production administration.
Application changes are source-controlled and reviewed before release, with build validation used before production deployment.
Application dependencies and supported runtimes are reviewed for security updates, while Azure managed services maintain the underlying cloud platform.
Reported or identified issues are triaged based on severity and potential customer impact. Security reports can be sent to security@stack-ops.io.
Production configuration is kept separate from development settings, unsafe static cloud credentials are rejected by default, and supported protected-configuration or workload-identity patterns are preferred.
Administrative functions require authenticated, authorized roles. Sensitive production operations are limited through role and permission checks.
Trust area 05
A defined response path supports triage, containment, recovery, customer communication, and follow-up when security events occur.
Potential incidents are assessed for scope and impact, then handled through containment, investigation, remediation, recovery, and post-incident review as appropriate.
Affected customers are notified based on confirmed impact, applicable law, and contractual commitments. Timing and detail depend on the facts established during investigation.
Suspected vulnerabilities, unauthorized access, and security questions can be reported directly to security@stack-ops.io.
Trust area 06
Stack-Ops distinguishes its own program status from Microsoft Azure provider certifications and avoids publishing unverified attestations.
Published privacy information covers data-subject access, correction, deletion, portability, international transfers, and DPA requests. This is a readiness statement, not a certification or legal guarantee.
Microsoft Azure maintains its own broad compliance portfolio, including ISO and SOC reports for in-scope Azure services. Those provider attestations support the platform but do not certify Stack-Ops itself.
This Trust Center does not claim Stack-Ops ISO 27001 certification, SOC 2 attestation, or completed penetration testing unless a current, applicable report is available for customer review.
Trust area 07
Start with public trust documents, then request organization-specific agreements or review materials from the appropriate team.
Application security, identity, access, auditability, and data protection controls.
View documentPersonal-data collection, use, sharing, retention, rights, and transfer information.
View documentCustomer content ownership, service responsibilities, account terms, and legal conditions.
View documentData categories, processing purposes, application controls, and request channels.
View documentRequest a DPA for your organization or begin a privacy and legal review.
Request documentRequest current information about service providers used to deliver Stack-Ops.
Request documentRequest the current overview of backup, recovery, and continuity practices.
Request documentSend a questionnaire, request a DPA or subprocessor list, or ask our team for additional security and privacy information.