Security & Compliance
A security posture your review team can approve.
StackswiseSoft is built for teams that handle customer data, sales pipelines, and internal knowledge. Here is what we do to keep it safe.
Data encryption
TLS 1.2+ in transit and AES-256 at rest for all customer data. Keys managed by our cloud provider's KMS with regular rotation.
Access controls
Role-based access, per-resource permissions, session management, and support for SSO (SAML) and SCIM on Business and Enterprise plans.
Payment handling
Payments are processed by Stripe and PayPal. Card numbers never touch our servers. Stripe is PCI-DSS Level 1 certified.
Data residency
Customer data is stored in either our US or EU region. You choose during workspace creation; the choice is fixed after that.
Privacy compliance
We support GDPR and CCPA data subject requests: access, export, correction, and deletion. Data Processing Addendum available on request.
Incident response
Documented incident response process with defined severity levels. Affected customers notified without undue delay per applicable law.
Hosting
StackswiseSoft runs on Tier 1 cloud infrastructure with independently audited physical, network, and platform security. Production systems are isolated from development environments and access is logged.
Data we collect and why
- Account data (name, email, workspace) — required to create and access your account.
- Customer content (records you create) — stored on your behalf; you retain ownership.
- Usage telemetry — used to improve reliability and diagnose issues.
- Billing data — collected by Stripe or PayPal; we store only invoice metadata.
Vulnerability disclosure
Report security issues to security@stackswisesoft.com. We acknowledge reports within two business days and coordinate a fix before public disclosure.
Compliance statement
StackswiseSoft complies with applicable data protection regulations and industry best practices to ensure secure and lawful operation. A signed Data Processing Addendum is available on request. Additional certifications (SOC 2, ISO 27001) are on our roadmap; contact us for our current attestation status.