Security

How we protect your data

Security is foundational to MadStack AI. Here's an overview of the controls we have in place.

Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Card images are stored in isolated S3 buckets with server-side encryption.

Access control

Role-based access (Owner, Admin, Member, Billing) with passwordless authentication using one-time codes. JWT tokens use RS256 asymmetric keys.

Monitoring

24/7 anomaly detection, structured audit logs for all data access, and real-time alerting for suspicious activity.

Pen testing

Annual third-party penetration tests conducted by independent security firms. Critical findings are remediated within 72 hours.

Tenant isolation

Each company's data is stored with a tenant-scoped partition key and access-controlled at the database level. Cross-tenant data leakage is structurally prevented — not just policy-controlled.

Incident response

We maintain a documented incident response plan with defined severity tiers and escalation paths. Affected customers are notified within 72 hours of a confirmed breach involving their data, as required by GDPR and applicable state law.

Responsible disclosure

Found a vulnerability? We welcome responsible disclosure. Please email support@madstackai.com with details and a reproduction case. We commit to acknowledging reports within 48 hours and resolving critical issues within 7 days.

Sub-processors

We use a limited set of sub-processors to deliver the service:

Compliance

MadStack AI is designed to support GDPR, CCPA, and SOC 2 Type II compliance for customers in regulated industries. Enterprise customers may request a Data Processing Agreement (DPA) and our most recent security questionnaire by contacting support@madstackai.com.