Security overview
StackScopes connects operational context without removing the need for least privilege, customer authorization, provider audit logs, encryption, tenant-aware access, and explicit recovery control.
Data handling
Product data should remain scoped to the selected workspace, approved integrations, contractual purpose, and configured retention. Data minimization and masking reduce exposure to content that is not required for infrastructure-intelligence workflows.
Access model
Read-only discovery uses customer-approved cross-account access and keeps collection separate from any restricted execution authority. Users and service roles should receive only the access required for their responsibilities.
AI governance
AI assistance is constrained by approved data, policy, allowed tools, evidence, confidence, and human review. It cannot independently initiate unrestricted production action or silently turn a hypothesis into a fact.
Availability and resilience approach
StackScopes applies the same systems-thinking principles to its service design: explicit dependencies, controlled change, recovery planning, verification, and review. No public availability percentage or service-level guarantee is asserted without a signed agreement.
Privacy
The Privacy Policy describes public-site, account, product, support, security, and communication information. Customer-specific processing terms and instructions are addressed through the applicable agreement.
Legal documents
The public legal library includes the Privacy Policy, Terms of Service, Acceptable Use Policy, Cookie Policy, Email Practices, Data Processing overview, and Subprocessors page.
Vulnerability disclosure
Security concerns may be sent to security@stackscopes.com with reproduction details and a safe contact method. Do not include customer secrets or access systems without authorization.
Contact channels
General, sales, support, security, privacy, legal, and email-abuse questions use purpose-specific StackScopes domain addresses listed on the Contact and policy pages.
Subprocessors
Customers and prospective customers may request the current production subprocessor schedule and applicable change-notice terms from privacy@stackscopes.com.
Data retention
Retention depends on record type, workspace settings, security requirements, backups, and the applicable customer agreement. Access removal and deletion requests follow the relevant operational and legal process.
Assurance claims
Security certifications, independent audits, partner badges, and compliance claims are published only when their scope and current status can be substantiated.