Security
How we protect your data
Security is foundational to MadStack AI. Here's an overview of the controls we have in place.
Encryption
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Card images are stored in isolated S3 buckets with server-side encryption.
Access control
Role-based access (Owner, Admin, Member, Billing) with passwordless authentication using one-time codes. JWT tokens use RS256 asymmetric keys.
Monitoring
24/7 anomaly detection, structured audit logs for all data access, and real-time alerting for suspicious activity.
Pen testing
Annual third-party penetration tests conducted by independent security firms. Critical findings are remediated within 72 hours.
Tenant isolation
Each company's data is stored with a tenant-scoped partition key and access-controlled at the database level. Cross-tenant data leakage is structurally prevented — not just policy-controlled.
Incident response
We maintain a documented incident response plan with defined severity tiers and escalation paths. Affected customers are notified within 72 hours of a confirmed breach involving their data, as required by GDPR and applicable state law.
Responsible disclosure
Found a vulnerability? We welcome responsible disclosure. Please email support@madstackai.com with details and a reproduction case. We commit to acknowledging reports within 48 hours and resolving critical issues within 7 days.
Sub-processors
We use a limited set of sub-processors to deliver the service:
- Amazon Web Services — cloud infrastructure (US regions).
- OpenAI — AI model API for field extraction (data is not retained for training).
- Stripe — payment processing (PCI-DSS compliant).
- Twilio — SMS delivery for OTP codes.
Compliance
MadStack AI is designed to support GDPR, CCPA, and SOC 2 Type II compliance for customers in regulated industries. Enterprise customers may request a Data Processing Agreement (DPA) and our most recent security questionnaire by contacting support@madstackai.com.
