Security & data
Updated 16 September 2026
How Stack keeps your workspace and your clients’ information safe, where it lives, and the audited services it runs on.
Signing in
Sign in with your email and password, or with Google or Microsoft. Every new device asks for a six-digit code by email or SMS before it gets in, and stays trusted for 30 days. Two-factor sign-in is on for everyone and cannot be switched off. Recovery codes cover a lost phone.
Your workspace is separate from every other
Every record in Stack belongs to one workspace, and the database enforces that boundary on every table, not just the app. A request from your workspace cannot read another’s. The app’s own routes require a two-factor-verified session as well.
Connected accounts
Gmail, Microsoft 365, Slack and Twilio connect through their own sign-in, so Stack never sees your password. The access tokens are kept in an encrypted vault, never in plain text, and you can disconnect any account from Settings at any time. Every message a connected service sends to Stack is signature-checked before Stack acts on it, and images in emails load through Stack’s own proxy so senders cannot track you.
Where your data lives
Your workspace database and files are hosted by Supabase in Sydney, Australia, encrypted at rest and in transit. The Stack app runs on Vercel, served from Sydney and the east coast of the United States. When Penny works on something for you, that request is processed by Google and Anthropic outside Australia; under the commercial terms Stack uses, neither trains its models on your data. Email is sent through Resend, and payments are handled by Stripe, so card numbers never touch Stack.
Keeping and deleting data
Stack keeps a cached copy of your most recent emails so the inbox is fast; copies older than the newest thousand per mailbox are cleared every night, while the message record, tags and links stay. Marketing email from Stack carries one-click unsubscribe and SMS honours STOP. You can export your contacts at any time, delete your own account from Settings, or ask us to delete your workspace.
The services Stack runs on
Stack is built on services that are independently audited. These certifications belong to the providers and cover the infrastructure underneath Stack; Stack’s own controls are the ones described above.
- Supabase — database, files and sign-in, hosted in Sydney. SOC 2 Type 2, ISO 27001, GDPR. Encrypted at rest with AES-256 and in transit with TLS.
- Vercel — the Stack app itself. SOC 2 Type 2, ISO 27001, PCI DSS attestations, GDPR and the EU–US Data Privacy Framework.
- Google Cloud (Vertex AI) — Penny. ISO/IEC 27001:2022, SOC 2 Type II, and assessed under IRAP, the Australian Government’s program, with generative AI on Vertex AI in scope.
- Anthropic — Penny. SOC 2 Type II, ISO 27001:2022 and ISO/IEC 42001:2023, the standard for responsible AI management.
- Stripe — billing. PCI DSS Service Provider Level 1, the highest level in the payments industry, plus SOC 1 and SOC 2 Type II.
- Twilio — SMS, on your own account. ISO/IEC 27001, 27017 and 27018, SOC 2 Type 2, PCI DSS Level 1.
- Resend — email Stack sends you. SOC 2 Type II and GDPR. Its records are stored in the United States.
Privacy and terms
How Stack handles personal information is set out in the privacy policy, and the subscription terms in the terms of service.
Have a security question?
Contact us