Skip to content

Stacksync × Supabase Miami: AI-Native OperationsOct 13Reserve your spot

SECURITY

Security &
Trust.

Stacksync shares its SOC 2 Type II report under NDA through its Trust Center, and your security team can request it as soon as your evaluation starts. Two-way sync moves records between your systems without keeping a copy of them; logs and undelivered events persist only as this page sets out.

AT A GLANCE

What your security review will ask first

Short answers for a vendor security review. Plan availability matches the compare table on /pricing.
Question Answer Details
Frameworks SOC 2 Type II, ISO 27001, HIPAA, GDPR, CCPA and DPF US-EU, UK, CH. HIPAA workloads run under a Business Associate Agreement.
SOC 2 Type II report Available under NDA from the Trust Center. Request it when your evaluation starts and check its audit period.
Does Stacksync store our records? The two-way sync path keeps no copy. Five things do persist for a time: undelivered payloads and events, logs for your plan's retention period, encrypted connection credentials, sync state (record IDs and change-detection fingerprints) and any database or event queue you choose to host on Stacksync.
Encryption TLS 1.2+ in transit, AES-256 at rest.
Compliance by plan SOC 2 Type II, ISO 27001, HIPAA and DPF US-EU-UK-CH on Pro and up; GDPR and CCPA on every plan.
MFA, SSO and SCIM MFA on Pro and up. SSO & SCIM on Enterprise only.
Processing region You select it. The choice widens by plan, up to custom regions on Enterprise.
FedRAMP and on-premise FedRAMP is not in the framework list above, so raise it before a POC. On-premise deployment is on Enterprise only.
SECURITY

Security teams trust Stacksync

As a data company, we understand the importance of keeping your data secure. Stacksync is built with security best practices to keep your data safe at every layer, and is DPF-certified for US, EU, UK and CH data transfers.

SOC 2 Type II
ISO 27001
HIPAA BAA
GDPR
CCPA
DPF US-EU-UK-CH
→ SECURITY WITH BENEFITS

SSO & SCIM

Let your users access Stacksync from your centralized user management systems. Works with Okta, Azure, Google SSO and more.

Alerts

Immediately get alerted about record syncing issues over email, Slack, PagerDuty and WhatsApp. Resolve issues from a centralized dashboard with retry and revert options.

Secure connection options

Securely connects to your systems with:

DATA HANDLING

What Stacksync stores, and for how long

The sync path keeps no copy of your records. Five other places can hold data for a while, and your reviewer should know each one. Stacksync encrypts data with TLS 1.2+ in transit and AES-256 at rest.

  1. 01

    Records in the sync path

    Stacksync reads a change from one system and writes it to the other. It keeps no copy of your records once the write lands. /pricing lists a “No data retention” policy on every plan, and that policy covers this path.

  2. 02

    Undelivered payloads and events

    When a destination is down or rate-limits a write, Stacksync holds the sync payload or workflow event only as long as it needs to deliver it. You inspect failed records in the Issues dashboard and retry or revert them.

    Issues dashboard docs
  3. 03

    Logs

    Stacksync keeps sync and workflow logs for the retention period your plan sets (see the plan table below). Storing logs in your own storage is available on Enterprise only.

  4. 04

    Connection credentials

    Stacksync stores OAuth tokens, API keys and database passwords encrypted. You can revoke or rotate them in the source system at any time.

  5. 05

    Sync state

    Stacksync keeps the record IDs and change-detection fingerprints a sync needs to match records between the two systems and to detect changes.

  6. 06

    Data you choose to host

    A database or event queue you run on Stacksync stores data by design. Those products sit outside the sync path, and you opt into them.

ENTERPRISE-GRADE PROTECTION

Stacksync security enterprise-grade protection.

Stacksync syncs critical CRM, ERP and warehouse data in real time, under controls your security team can audit.

  • AES-256 encryption

    Stacksync encrypts data in transit with TLS 1.2+ and at rest with AES-256. It stores connection credentials encrypted, and you can revoke or rotate them at any time.

  • No copy in the sync path

    Stacksync processes records in flight and keeps no copy once the write lands. Sync payloads and workflow events stay only as long as delivery takes; logs follow your plan's retention period.

  • Advanced connection security

    OAuth 2, SSH tunneling, SSL certificates, IP allowlisting, VPN gateway and VPC peering. Pick the model your security team already approved; the plan table shows where each one starts.

CONTROLS BY PLAN

Which plan includes which control

This table reads from the /pricing compare table, so the two pages match. Read the column for the plan you intend to buy: some controls and frameworks start above Starter, and a security review should see that before procurement does.

Control StarterProManaged ProEnterprise
Access
Passwordless and social logins Included Included Included Included
MFA Not included Included Included Included
SSO & SCIM Not included Not included Not included Included
RBAC (Role Based Access Control) Included Included Included Included
Network
IP whitelisting Not included Included Included Included
SSH tunneling Included Included Included Included
SSL certificates Not included Included Included Included
VPC peering Not included Not included Not included Included
VPN gateway Not included Not included Not included Included
Private networking (PrivateLink, Azure Private Link, Google PSC) Not included Not included Not included Included
Data, logs and deployment
“No data retention” policy Included Included Included Included
Select processing region Basic Extended Extended All (incl. Custom)
Select cloud provider (GCP, AWS, or Azure) Not included Not included Not included Included
Log retention policy 1 day 7 days 7 days 30 days
Store logs in your own storage Not included Not included Not included Included
Audit logs Not included Not included Not included Included
Environments (Dev, Staging, Production) 1 1 1 3
On-premise deployment Not included Not included Not included Included
Compliance
SOC 2 Type II Not included Included Included Included
GDPR Included Included Included Included
CCPA Included Included Included Included
ISO 27001 Not included Included Included Included
HIPAA Not included Included Included Included
DPF US-EU-UK-CH Not included Included Included Included

ENTERPRISE CAPABILITIES

Enhance your data security

Network, region and deployment options for regulated teams. Several start at Enterprise; the plan table above lists each one.

  • Private networking

    SSH tunnels through a bastion host, VPC peering, AWS PrivateLink, Azure Private Link, Google PSC and VPN gateways keep traffic off the public internet. Private networking is on Enterprise only.

  • Regional processing

    You choose where Stacksync processes your data. Region choice by plan: Starter Basic, Pro Extended, Managed Pro Extended, Enterprise All (incl. Custom). Ask for the current region list and the egress IPs to allowlist during your review.

  • MFA & SSO enforcement

    MFA on Pro and up; SSO & SCIM on Enterprise only. SCIM provisioning keeps your directory and Stacksync users in step.

  • On-premise deployment

    On-premise deployment is on Enterprise only, for data that must stay in your own data center.

YOUR SECURITY REVIEW

How to review Stacksync before sandbox access

Start these five steps on day one so the security review runs alongside the technical evaluation.

  1. Step 1

    Request the documents

    The Trust Center holds the SOC 2 Type II report (under NDA), the security whitepaper, the subprocessor list and audit reports. The DPA, privacy notice and terms sit in the Stacksync docs. Check the SOC 2 audit period against what your own auditors need.

  2. Step 2

    Create a scoped integration user

    Give Stacksync a dedicated user or OAuth app in Salesforce, NetSuite, HubSpot or your database, limited to the objects the sync reads and writes. Keep personal admin logins out of it. You own that user, so revoking or rotating it cuts Stacksync off.

  3. Step 3

    Settle vendor-staff access

    Ask your account team for Stacksync's staff-access terms and write them into your DPA or contract. Inside your workspace, RBAC (on every plan) sets what each of your own users can change.

  4. Step 4

    Choose region, network and plan

    Pick the processing region and the connection model: SSH tunnel, IP allowlist or private networking. Then read the plan table for MFA, SSO & SCIM, audit logs and log retention.

  5. Step 5

    Bring your questionnaire to a call

    Book a demo and send your security questionnaire ahead of it, so the review runs next to the technical evaluation.

RECOMMENDED RESOURCES

Security at a glance

The documents your security review team will ask for. Request the SOC 2 report from the Trust Center below.

FAQ

Frequently asked questions

How do we get Stacksync's SOC 2 Type II report?

Request it under NDA through the Stacksync Trust Center at security.stacksync.com, which also holds the security whitepaper, the subprocessor list and audit reports. Ask for it when your evaluation starts, and check the audit period against what your own auditors need.

Does Stacksync store my Salesforce data or just pass it through?

The two-way sync path passes records through: Stacksync reads a change, writes it to the other system and keeps no copy. Five things do persist for a time: undelivered payloads and events, logs for your plan's retention period, encrypted connection credentials, sync state (record IDs and change-detection fingerprints) and any database or event queue you choose to host on Stacksync. Stacksync encrypts data with TLS 1.2+ in transit and AES-256 at rest.

Which Stacksync plans include SOC 2, ISO 27001 and HIPAA coverage?

The compare table on /pricing lists SOC 2 Type II, ISO 27001, HIPAA and DPF US-EU-UK-CH on Pro and up; GDPR and CCPA on every plan. HIPAA workloads run under a Business Associate Agreement. If your review needs a framework on a specific plan, confirm it in your order form before you sign.

Are SSO, SCIM and MFA available on every Stacksync plan?

No. Per the /pricing compare table, MFA is on Pro and up, SSO and SCIM on Enterprise only, and IP allowlisting on Pro and up. Passwordless and social logins and role-based access control are on every plan.

Can Stacksync keep processing in the EU for GDPR?

Yes, Stacksync offers EU processing regions. You select the region for your workspace, and the choice widens by plan, up to every region including custom locations on Enterprise. Stacksync signs a Data Processing Addendum as a GDPR processor and is DPF-certified for US, EU, UK and Swiss transfers. If your policy requires EU-only processing with no US transit, ask for the current region list, the control-plane location and the egress IPs during your review, and write the requirement into the DPA.

How does Stacksync govern its AI features?

Stacksync governs its AI features with the same platform controls as the rest of the product: role-based access, approval steps that hold a write until a person signs off, and the log explorer for each run. Stacksync AI Copilot builds integrations and workflows from a prompt, and Genies are AI agents that act across your connected systems. You can build two-way sync and workflows by hand when a policy keeps AI out of scope. The AI agent governance page at /security/ai-agents covers approvals, audit and the questions to raise in a security review.

Does the processing region cover AI inference?

Not as published: the processing region you select covers sync processing, and the site does not yet state where AI inference for Stacksync AI Copilot and Genies runs. Ask for the inference region, model providers and retention terms in writing during your security review and check them against the Data Processing Addendum and the sub-processor list in the Trust Center. /security/ai-agents lists these questions.

How does Stacksync access our systems?

Through the integration user or OAuth app you create, scoped to the objects the sync needs. Stacksync stores its credentials encrypted, and revoking or rotating that user in the source system stops access. For the terms that govern Stacksync staff access, ask your account team and put them in your DPA or contract.

What should government contractors check about FedRAMP and GovCloud?

Raise FedRAMP and GovCloud requirements with Stacksync before a POC and get the answer in writing, because FedRAMP is not among the frameworks this page lists. For data that must stay in your own data center, on-premise deployment is on Enterprise only.

What security documents should we request before giving an integration vendor sandbox access?

Ask for the SOC 2 Type II report with its audit period, the ISO 27001 certificate, the security whitepaper, the Data Processing Addendum and the subprocessor list. Then confirm three answers in writing: what the vendor stores, where it processes data, and which plan includes the controls you need. For Stacksync, the Trust Center holds the SOC 2 report, whitepaper and subprocessor list, and the DPA sits in the Stacksync docs.