Effective Date: May 15, 2026 · Operator: StackPass, Inc., a Delaware corporation (AEOSOS)
AEOSOS’s security program is designed to protect the confidentiality, integrity, and availability of Customer Data. This is not a certification. We continuously evolve our program. Questions: team@stackpass.ai (subject: “Security” or “Trust”).
Architecture and infrastructure
Edge-native architecture on a serverless, globally distributed network — no traditional VPC, no virtual machines, no exposed ports.
Multi-tenant isolation with a separate managed database per tenant, per-tenant origin allowlists, and per-tenant API keys.
WORM-style object storage for consent payloads, with cryptographic integrity verification.
Stateless compute with no persistent local state — eliminates entire classes of server compromise risks.
Encryption
In transit: TLS 1.2 minimum, TLS 1.3 preferred, on all Service endpoints. HSTS enforced.
At rest: AES-256 (provider-managed) on our managed database and object storage.
Webhook signatures: HMAC-SHA256 with rotating secrets.
API keys: Stored as hashed values; the plaintext key is shown only at issuance.
Access control
Multi-factor authentication required for all AEOSOS administrative access.
Least-privilege principle for personnel and service-to-service credentials.
Audit logs for administrative operations.
Customer access via OAuth-only sign-in (no password storage); per-tenant API keys for programmatic access.
Dependency monitoring with automated security advisories.
Automated deploys with secrets held in an encrypted, access-controlled secret store.
Monitoring and logging
Request, error, and security event logging at the edge.
Anomaly detection on authentication and capture endpoints.
Rate limiting at multiple layers.
Audit trail for billing events, webhook signature failures, tenant configuration changes, and Personal Data exports.
Vulnerability management
Dependency scanning on every build.
Responsible disclosure: contact team@stackpass.ai with subject “Security disclosure”. We commit to acknowledging credible reports promptly and to good-faith engagement with researchers acting under standard responsible-disclosure norms. See also security.txt and Vulnerability disclosure.
Coordinated disclosure before public release of any vulnerability affecting Customers where feasible.
Incident response
Documented playbook with severity classification.
24-hour triage window for credible reports.
Customer notification within 72 hours of confirmed Personal Data Breach (see DPA §9), and within 30 days of confirmed PHI Breach when a BAA is in effect (BAA §4.3).