Read-only discovery model
StackScopes is designed to begin with a customer-authorized cross-account read-only role. The connection should use a unique external ID where applicable, least-privilege permissions, scoped account and Region coverage, session controls, and AWS audit visibility. Collection gaps such as denied permissions or unsupported resources remain visible.
Separate execution authority
A distinct, restricted execution role is required for any approved remediation. Discovery credentials are not treated as production-changing authority. Execution policy should constrain allowed actions, resources, environments, prerequisites, timeouts, validation, and rollback. Human approval remains required for production-impacting action.
Encryption
The product design protects data in transit using current transport encryption and protects retained service data at rest using managed encryption controls appropriate to the deployed service. Key, hosting, and deployment details are defined by the production architecture and applicable agreement.
Tenant isolation and data minimization
Workspace, tenant, account, Region, and environment context remain attached to records and authorization decisions. StackScopes is designed to collect infrastructure and operational context required for the selected workflow while minimizing unrelated customer content. Sensitive values should be omitted, masked, or redacted where they are not necessary.
Audit, evidence, and retention
Discovery, analysis, approvals, restricted actions, and verification should retain auditable context. Findings preserve source, timestamp, confidence, and assumptions. Retention controls follow record type, workspace configuration, security requirements, and the applicable customer agreement.
AI governance
AI workflows remain bounded by policy, allowed tools, scoped data, visible evidence, confidence, and deterministic checks. AI cannot independently grant itself broader authority or initiate unrestricted production actions. Sensitive data should be minimized or masked, and production-impacting remediation requires human approval. Agent activity should remain reviewable and auditable. StackScopes does not characterize customer data as training data without an explicit, factual policy basis.
Access removal
A customer should be able to revoke the cross-account role, remove an integration, disable users, and end future collection. Handling of retained records, exports, deletion, and backups follows the applicable configuration and agreement.
Incident-response principles
Security events should be scoped, contained, investigated, documented, and communicated according to their impact and contractual obligations. Audit evidence and access boundaries support investigation without implying a certification or a guaranteed response time.
Responsible disclosure
Security concerns may be reported to security@stackscopes.com. Please include a clear description, affected surface, reproduction details, and a safe way for the security team to follow up.