STACK places a runtime boundary between an agent and the systems it uses. The linked concept and API articles define each control in detail.
STACK's production applications run in Stockholm. The primary database region is Frankfurt. Production encryption uses AWS KMS in eu-north-1. Some configured providers can process data in other regions. Review the Privacy page and your selected provider before you send regulated data.
The operator remains responsible for its lawful basis, configuration, upstream providers, and use of agent output.
See Encryption and CMEK and Credentials API.
Human clients should use OAuth, which preserves the operator or member identity and applies the member's role and service restrictions. A headless service can use the long-lived operator API key when it cannot complete OAuth, but that key carries operator-wide access. A Passport or agent JWT creates an agent-bearing request, which STACK denies on human governance routes including scope expansion, encryption changes and Intent decisions.
See STACK Authentication, Agent Keys, and Intents and Governance.
STACK checks live revocation on each STACK-verified call. Offline signature verification proves signature and expiry but cannot see a later revocation. Use the online verification endpoint when current revocation status matters. See Revocation.
Hash chaining makes later row changes detectable. Anchor the chain head outside STACK if you need evidence against a full chain rewrite. See Audit Log and Evidence API.
Email security@getstack.run with reproduction steps. Do not publish the details before STACK confirms a fix.