Company
Security
Stackap's security is a list of specific controls, each with a test that tries to defeat it.
Controls built in
- Network
- Only SSH, HTTP and HTTPS are open. Postgres listens on localhost and the internal container network only.
- Secrets at rest
- Environment variables and connection strings are encrypted with AES-256-GCM, bound to their project and name. Access tokens are stored only as SHA-256 hashes, so a database leak does not expose usable tokens.
- Secrets in motion
- Secrets reach containers through a private, owner-only file, never on a command line.
- Git access
- A restricted SSH user with a forced command: no shell, no port forwarding, no arbitrary commands. Each organization's keys reach only its own repositories.
- Containers
- No new privileges, CPU, memory and process limits, and generated images run as an unprivileged user.
- Databases
- One role per project, no superuser rights, and connection rights limited to its own database.
- Backups
- Encrypted before upload, authenticated against tampering, and restorable only into new databases.
- Tokens
- Scoped, expiring and rotatable, so an agent can be given exactly the permissions a task needs.
- Human approval
- With an approval-mode token, a risky action such as deleting a project stops until the account owner approves that exact request through a link sent out-of-band. An approval is single-use, bound to the exact action, and expires after an hour. A project deletion is recoverable: code, database and backups are kept.
- Audit
- Pushes, deploys, rollbacks, token and key changes, backups, restores and organization actions are recorded with who did them.
How the walls between organizations are tested
Every lookup of a project, build, backup, token or key goes through one module that filters on the caller's organization, taken from the token alone. A static test reads every route and fails the build if any query touches tenant data without that filter, and the test itself is checked with deliberately leaky examples. An attack suite attempts 43 cross-organization actions, and all are refused. A resource in another organization returns the same response as one that does not exist.
Early access and regulated workloads
Organizations are created by the operator for known teams, because tenant code shares one host in resource-limited containers. Independent penetration testing and compliance certifications are not part of early access. If your application handles regulated data, we will go through your requirements with you before you start. To report a problem, write to hi@stackap.com.
Stackap is in early access. Tell us what you run and we will reply with a straight answer about whether it fits.
Ask for an invitationLast updated .