Third Party Index

Snapshot 49172

Document
Security page
URL
https://www.stacksync.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
188608 bytes
SHA-256 (raw)
d4cdd545d9b5cc596d0d2e738b2317121b5c4e0815dfdfec2ff6c3484653636d
SHA-256 (normalized text)
323b0a5167787eadae3231c2f3e389836a2a73f32404fffc5f3d53ecaa233916

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Stacksync × Supabase Miami: AI-Native OperationsOct 13Reserve your spot
SECURITY
Security &
Trust.
Stacksync shares its SOC 2 Type II report under NDA through its Trust Center, and your security team can request it as soon as your evaluation starts. Two-way sync moves records between your systems without keeping a copy of them; logs and undelivered events persist only as this page sets out.
Book a demo
Stacksync holds SOC 2 Type II and ISO 27001, offers a Business Associate Agreement for HIPAA workloads, and covers GDPR, CCPA and DPF transfers. It encrypts data with TLS 1.2+ in transit and AES-256 at rest. MFA, SSO and SCIM, IP allowlisting, audit logs and region choice depend on your plan.
Short answers for a vendor security review. Plan availability matches the compare table on /pricing.
Question	Answer	Details
Frameworks	SOC 2 Type II, ISO 27001, HIPAA, GDPR, CCPA and DPF US-EU, UK, CH. HIPAA workloads run under a Business Associate Agreement.	Compliance
SOC 2 Type II report	Available under NDA from the Trust Center. Request it when your evaluation starts and check its audit period.	Trust Center
Does Stacksync store our records?	The two-way sync path keeps no copy. Five things do persist for a time: undelivered payloads and events, logs for your plan's retention period, encrypted connection credentials, sync state (record IDs and change-detection fingerprints) and any database or event queue you choose to host on Stacksync.	Data handling
Encryption	TLS 1.2+ in transit, AES-256 at rest.	Data handling
Compliance by plan	SOC 2 Type II, ISO 27001, HIPAA and DPF US-EU-UK-CH on Pro and up; GDPR and CCPA on every plan.	Pricing
MFA, SSO and SCIM	MFA on Pro and up. SSO & SCIM on Enterprise only.	Plan controls
Processing region	You select it. The choice widens by plan, up to custom regions on Enterprise.	Plan controls
FedRAMP and on-premise	FedRAMP is not in the framework list above, so raise it before a POC. On-premise deployment is on Enterprise only.	Deployment
SECURITY
Security teams trust Stacksync
As a data company, we understand the importance of keeping your data secure. Stacksync is built with security best practices to keep your data safe at every layer, and is DPF-certified for US, EU, UK and CH data transfers.
Learn more about security
SOC 2 Type II
ISO 27001
HIPAA BAA
GDPR
CCPA
DPF US-EU-UK-CH
→ SECURITY WITH BENEFITS
SSO & SCIM
Let your users access Stacksync from your centralized user management systems. Works with Okta, Azure, Google SSO and more.
Alerts
Immediately get alerted about record syncing issues over email, Slack, PagerDuty and WhatsApp. Resolve issues from a centralized dashboard with retry and revert options.
Secure connection options
Securely connects to your systems with:
OAuth 2SSH TunnellingSSL certificatesIP WhitelistingVPN gatewayVPC peeringand more
01
Records in the sync path
Stacksync reads a change from one system and writes it to the other. It keeps no copy of your records once the write lands. /pricing lists a “No data retention” policy on every plan, and that policy covers this path.
02
Undelivered payloads and events
When a destination is down or rate-limits a write, Stacksync holds the sync payload or workflow event only as long as it needs to deliver it. You inspect failed records in the Issues dashboard and retry or revert them.
Issues dashboard docs
03
Logs
Stacksync keeps sync and workflow logs for the retention period your plan sets (see the plan table below). Storing logs in your own storage is available on Enterprise only.
04
Connection credentials
Stacksync stores OAuth tokens, API keys and database passwords encrypted. You can revoke or rotate them in the source system at any time.
05
Sync state
Stacksync keeps the record IDs and change-detection fingerprints a sync needs to match records between the two systems and to detect changes.
06
Data you choose to host
A database or event queue you run on Stacksync stores data by design. Those products sit outside the sync path, and you opt into them.
Database hosting Event queues
AES-256 encryption
Stacksync encrypts data in transit with TLS 1.2+ and at rest with AES-256. It stores connection credentials encrypted, and you can revoke or rotate them at any time.
No copy in the sync path
Stacksync processes records in flight and keeps no copy once the write lands. Sync payloads and workflow events stay only as long as delivery takes; logs follow your plan's retention period.
Advanced connection security
OAuth 2, SSH tunneling, SSL certificates, IP allowlisting, VPN gateway and VPC peering. Pick the model your security team already approved; the plan table shows where each one starts.
Control	Starter	Pro	Managed Pro	Enterprise
Access
Passwordless and social logins	Included	Included	Included	Included
MFA	Not included	Included	Included	Included
SSO & SCIM	Not included	Not included	Not included	Included
RBAC (Role Based Access Control)	Included	Included	Included	Included
Network
IP whitelisting	Not included	Included	Included	Included
SSH tunneling	Included	Included	Included	Included
SSL certificates	Not included	Included	Included	Included
VPC peering	Not included	Not included	Not included	Included
VPN gateway	Not included	Not included	Not included	Included
Private networking (PrivateLink, Azure Private Link, Google PSC)	Not included	Not included	Not included	Included
Data, logs and deployment
“No data retention” policy	Included	Included	Included	Included
Select processing region	Basic	Extended	Extended	All (incl. Custom)
Select cloud provider (GCP, AWS, or Azure)	Not included	Not included	Not included	Included
Log retention policy	1 day	7 days	7 days	30 days
Store logs in your own storage	Not included	Not included	Not included	Included
Audit logs	Not included	Not included	Not included	Included
Environments (Dev, Staging, Production)	1	1	1	3
On-premise deployment	Not included	Not included	Not included	Included
Compliance
SOC 2 Type II	Not included	Included	Included	Included
GDPR	Included	Included	Included	Included
CCPA	Included	Included	Included	Included
ISO 27001	Not included	Included	Included	Included
HIPAA	Not included	Included	Included	Included
DPF US-EU-UK-CH	Not included	Included	Included	Included
Private networking
SSH tunnels through a bastion host, VPC peering, AWS PrivateLink, Azure Private Link, Google PSC and VPN gateways keep traffic off the public internet. Private networking is on Enterprise only.
Regional processing
You choose where Stacksync processes your data. Region choice by plan: Starter Basic, Pro Extended, Managed Pro Extended, Enterprise All (incl. Custom). Ask for the current region list and the egress IPs to allowlist during your review.
MFA & SSO enforcement
MFA on Pro and up; SSO & SCIM on Enterprise only. SCIM provisioning keeps your directory and Stacksync users in step.
On-premise deployment
On-premise deployment is on Enterprise only, for data that must stay in your own data center.
Step 1
Request the documents
The Trust Center holds the SOC 2 Type II report (under NDA), the security whitepaper, the subprocessor list and audit reports. The DPA, privacy notice and terms sit in the Stacksync docs. Check the SOC 2 audit period against what your own auditors need.
Trust Center DPA
Step 2
Create a scoped integration user
Give Stacksync a dedicated user or OAuth app in Salesforce, NetSuite, HubSpot or your database, limited to the objects the sync reads and writes. Keep personal admin logins out of it. You own that user, so revoking or rotating it cuts Stacksync off.
Step 3
Settle vendor-staff access
Ask your account team for Stacksync's staff-access terms and write them into your DPA or contract. Inside your workspace, RBAC (on every plan) sets what each of your own users can change.
Step 4
Choose region, network and plan
Pick the processing region and the connection model: SSH tunnel, IP allowlist or private networking. Then read the plan table for MFA, SSO & SCIM, audit logs and log retention.
Plan controls
Step 5
Bring your questionnaire to a call
Book a demo and send your security questionnaire ahead of it, so the review runs next to the technical evaluation.
Book a demo
RECOMMENDED RESOURCES
Security at a glance
The documents your security review team will ask for. Request the SOC 2 report from the Trust Center below.
01 Policy Privacy policy How we protect and manage your personal data.
02 Legal Terms of service Rules and guidelines for using our platform.
03 Legal Data Processing Addendum GDPR-compliant data processing framework.
04 Guide AI agent governance Approvals, access, logs and AI scope for Copilot and Genies.
TRUST CENTER
Live status for all things compliance
The SOC 2 Type II report under NDA, security whitepapers, subprocessors, audit reports and one-click access to our policies.
Visit Trust Center
How do we get Stacksync's SOC 2 Type II report?
Request it under NDA through the Stacksync Trust Center at security.stacksync.com, which also holds the security whitepaper, the subprocessor list and audit reports. Ask for it when your evaluation starts, and check the audit period against what your own auditors need.
Does Stacksync store my Salesforce data or just pass it through?
The two-way sync path passes records through: Stacksync reads a change, writes it to the other system and keeps no copy. Five things do persist for a time: undelivered payloads and events, logs for your plan's retention period, encrypted connection credentials, sync state (record IDs and change-detection fingerprints) and any database or event queue you choose to host on Stacksync. Stacksync encrypts data with TLS 1.2+ in transit and AES-256 at rest.
Which Stacksync plans include SOC 2, ISO 27001 and HIPAA coverage?
The compare table on /pricing lists SOC 2 Type II, ISO 27001, HIPAA and DPF US-EU-UK-CH on Pro and up; GDPR and CCPA on every plan. HIPAA workloads run under a Business Associate Agreement. If your review needs a framework on a specific plan, confirm it in your order form before you sign.
Are SSO, SCIM and MFA available on every Stacksync plan?
No. Per the /pricing compare table, MFA is on Pro and up, SSO and SCIM on Enterprise only, and IP allowlisting on Pro and up. Passwordless and social logins and role-based access control are on every plan.
Can Stacksync keep processing in the EU for GDPR?
Yes, Stacksync offers EU processing regions. You select the region for your workspace, and the choice widens by plan, up to every region including custom locations on Enterprise. Stacksync signs a Data Processing Addendum as a GDPR processor and is DPF-certified for US, EU, UK and Swiss transfers. If your policy requires EU-only processing with no US transit, ask for the current region list, the control-plane location and the egress IPs during your review, and write the requirement into the DPA.
How does Stacksync govern its AI features?
Stacksync governs its AI features with the same platform controls as the rest of the product: role-based access, approval steps that hold a write until a person signs off, and the log explorer for each run. Stacksync AI Copilot builds integrations and workflows from a prompt, and Genies are AI agents that act across your connected systems. You can build two-way sync and workflows by hand when a policy keeps AI out of scope. The AI agent governance page at /security/ai-agents covers approvals, audit and the questions to raise in a security review.
Does the processing region cover AI inference?
Not as published: the processing region you select covers sync processing, and the site does not yet state where AI inference for Stacksync AI Copilot and Genies runs. Ask for the inference region, model providers and retention terms in writing during your security review and check them against the Data Processing Addendum and the sub-processor list in the Trust Center. /security/ai-agents lists these questions.
How does Stacksync access our systems?
Through the integration user or OAuth app you create, scoped to the objects the sync needs. Stacksync stores its credentials encrypted, and revoking or rotating that user in the source system stops access. For the terms that govern Stacksync staff access, ask your account team and put them in your DPA or contract.
What should government contractors check about FedRAMP and GovCloud?
Raise FedRAMP and GovCloud requirements with Stacksync before a POC and get the answer in writing, because FedRAMP is not among the frameworks this page lists. For data that must stay in your own data center, on-premise deployment is on Enterprise only.
What security documents should we request before giving an integration vendor sandbox access?
Ask for the SOC 2 Type II report with its audit period, the ISO 27001 certificate, the security whitepaper, the Data Processing Addendum and the subprocessor list. Then confirm three answers in writing: what the vendor stores, where it processes data, and which plan includes the controls you need. For Stacksync, the Trust Center holds the SOC 2 report, whitepaper and subprocessor list, and the DPA sits in the Stacksync docs.