Legal

Security & Trust Center

Stack4Sec's security program, practices and trust commitments.

Última atualização: June 25, 2026 · Stack4Sec, LLCWyoming, USA

Language

This document is provided in English, which is the authoritative version; any translation is for convenience only and the English version prevails.

Overview

This document applies to all cybersecurity software-as-a-service solutions, websites, applications, platforms, APIs, software, modules, features, documentation, support, and related services made available by Stack4Sec, LLC, a Wyoming limited liability company.

For purposes of this document, "Stack4Sec," "Company," "we," "us," and "our" mean Stack4Sec, LLC. "Customer," "you," and "your" mean the person or entity accessing or using the Services.

This document is incorporated into and forms part of the Stack4Sec Terms of Service. Product-specific terms may supplement this document for particular products, modules, services, or features.

This Security Policy / Trust Center describes Stack4Sec's security commitments, shared responsibility model, and general safeguards for the Services. It is provided for transparency and does not create warranties, service levels, or guarantees unless expressly stated in a signed agreement.

Security Philosophy

Stack4Sec provides Cybersecurity SaaS solutions and recognizes that Customer Content may include sensitive security, compliance, governance, risk, operational, and business information. Stack4Sec uses commercially reasonable administrative, technical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of the Services.

No system is perfectly secure. Customer remains responsible for its own systems, users, configurations, content, devices, networks, access decisions, and cybersecurity program.

Shared Responsibility Model

Stack4Sec is responsible for securing the infrastructure, application, personnel processes, and service operations under its control.

Customer is responsible for:

  • configuring the Services appropriately;
  • managing users, roles, permissions, and authentication;
  • protecting credentials, devices, networks, and endpoints;
  • ensuring Customer Content is lawful, accurate, and appropriately classified;
  • reviewing exports, integrations, and external sharing;
  • maintaining backups and records outside the Services where required;
  • implementing Customer's own cybersecurity controls.

Access Control

Stack4Sec applies least privilege principles to personnel access where feasible. Access to production systems and Customer Content is limited to authorized personnel with a business need, subject to confidentiality obligations and access controls.

Customer should enable strong authentication, limit administrative access, review users regularly, and promptly revoke access for users who no longer require it.

Encryption

Stack4Sec uses encryption in transit for supported connections. Stack4Sec may use encryption at rest or equivalent safeguards for stored data depending on architecture, provider capabilities, and service configuration.

Customer is responsible for protecting files before upload where additional encryption, redaction, or classification is required by Customer policy or law.

Hosting and Infrastructure

The Services may be hosted using reputable cloud infrastructure, hosting, database, storage, monitoring, communications, AI, and security providers. Stack4Sec may add, replace, or remove providers as needed to operate, secure, and improve the Services.

Logging and Monitoring

Stack4Sec may collect logs, telemetry, alerts, and diagnostic information to operate the Services, troubleshoot issues, detect abuse, investigate incidents, monitor performance, and improve security.

Customer should monitor its own Account activity, user access, exports, integrations, and internal use of Service outputs.

Vulnerability Management

Stack4Sec uses commercially reasonable processes to identify, evaluate, prioritize, and remediate vulnerabilities in systems under its control. Remediation timelines depend on severity, exploitability, impact, compensating controls, and operational risk.

Customers and researchers may report suspected vulnerabilities to contact@stack4sec.com.

Secure Development

Stack4Sec aims to use secure development practices appropriate for SaaS services, which may include code review, access control, dependency management, testing, environment separation, change management, and security review of material changes.

Backup and Recovery

Stack4Sec may maintain backups or recovery mechanisms designed to support service continuity and data recovery. Backup frequency, retention, and restoration capabilities may vary by service, plan, architecture, and provider.

Customer remains responsible for exporting and retaining copies of Customer Content where required for audit, compliance, legal hold, business continuity, or records management.

Incident Response

Stack4Sec maintains incident response processes designed to identify, assess, contain, investigate, mitigate, and communicate security incidents. If Stack4Sec confirms a Security Incident affecting Customer Personal Data, Stack4Sec will notify Customer in accordance with the Data Processing Addendum and applicable law.

Personnel Security

Stack4Sec personnel with access to systems or Customer Content are expected to follow confidentiality, acceptable use, access control, and security requirements. Access may be reviewed and revoked when no longer needed.

Vendor and Subprocessor Security

Stack4Sec may use vendors and Subprocessors to provide the Services. Stack4Sec evaluates vendors based on the nature of services provided and may impose contractual, confidentiality, security, and data protection obligations where appropriate.

Customer Security Recommendations

Stack4Sec recommends that Customers:

  • enable multi-factor authentication where available;
  • use unique user accounts and prohibit shared credentials;
  • apply least privilege access;
  • review access rights periodically;
  • classify and minimize sensitive evidence and data;
  • redact secrets, credentials, and unnecessary personal data before upload;
  • monitor exports and external sharing;
  • train users on safe handling of security information;
  • maintain independent backups and records where required.

No Security Guarantee

Stack4Sec does not guarantee that the Services will be error-free, uninterrupted, immune from attack, free of vulnerabilities, or able to prevent all unauthorized access, data loss, misuse, cyber incidents, or third-party compromise.

Contact

Legal notices and inquiries may be sent to:

Stack4Sec, LLC 30 N Gould St, STE R Sheridan, WY 82801 United States Email: legal@stack4sec.com

Stack4Sec, LLC · Wyoming, USA · contact@stack4sec.com