STACK
MENU

Security at STACK

STACK keeps access decisions, credentials and revocation outside the agent’s runtime and gives customers independent ways to verify those controls, even if the agent itself is compromised.

Security model

If an attacker takes control of an agent, they inherit only the access already granted to it. Those limits remain outside the agent’s runtime and are checked again on every request. Our attack tests begin from that compromised state, and customers can verify the controls using their own records and infrastructure.

Access is agreed before the agent starts

The Passport records the approved job, who authorised it, the systems the agent may use, and the limits on credentials, data and time. STACK checks those terms on every request, along with any approval, runtime check or revocation that applies.

Compromised agent

The attacker controls its runtime and holds its valid Passport.

Every new request must match every limit
  1. Job, authority and identity
  2. Systems and actions
  3. Credential access
  4. Request limits
  5. Approvals, runtime checks and revocation
  6. Permitted data flows×
Data flow not permittedRequest refused

Due diligence

A security review covers the product and the company operating it. For STACK, that includes protection of customer data, operational controls, standards used at each trust boundary, and material available for independent review.

Customer data and cryptography

STACK handles account data, signed requests, selected payloads, credentials and audit records. The controls differ by data type; “encrypted” is not treated as one blanket property.

DataProtectionImportant detail
Upstream credentialsAES-256-GCM envelope encryption with AWS KMS. In proxy-only mode, the credential is added only inside the boundary.The agent receives the upstream response, not the raw credential.
Identity evidenceThe Passport carries opaque claim references. The underlying identity assertion is encrypted separately.A receiving party can request the evidence it is authorised to see without placing PII in the Passport JWT.
Audit recordsAppend-only rows, per-operator hash chaining and signed records for material decisions and outcomes.Retention depends on the plan. Customer exports can be retained outside STACK.
Data in transitTLS 1.2 or later on the public API, MCP transport and dashboard.The security of the final upstream hop also depends on the receiving service.
Data locationApplication services run in Stockholm, the managed database in Frankfurt and platform KMS in eu-north-1.Selected third-party services may process data elsewhere. The Privacy page records those relationships.
Customer-managed keysEnterprise customers can use an AWS KMS key in their own account for the supported operator ciphertext stores.Revoking the IAM grant makes covered decrypt operations fail closed.

Review STACK for your deployment.

stack | Security — STACK