Last reviewed: May 2026
Infrastructure
Stactiq is hosted on Google Cloud Platform (GCP) within the United States. Data at rest is encrypted using AES-256. All data in transit is encrypted using TLS 1.3. Infrastructure access is restricted to authorised Stactiq engineering personnel via VPN-gated access with mandatory multi-factor authentication.
Authentication
Stactiq accounts require email-verified authentication. Organisation administrators may enforce single sign-on (SSO) via SAML 2.0 for enterprise accounts. Session tokens expire after a configurable idle period. Brute-force login attempts trigger automatic lockout and alerting.
Access control
Role-based access control (RBAC) governs all system access. Roles include Organisation Administrator, Technical Director, Coach, and Read-Only. Authorised Users access only the data associated with their Customer organisation. Cross-organisation data access is architecturally prevented.
Stactiq personnel access to Customer Content is restricted to designated support engineers and requires explicit Customer-initiated authorisation for support cases. All access is logged.
AI inference security
AI inference payloads — including Methodology DNA context assembled to govern outputs — are transmitted to model providers over encrypted connections. Payloads are scoped to the minimum context required for the operation. Customer Content from one organisation is never included in inference context for another organisation. Inference logs are retained for 30 days and then deleted.
Audit logging
All Customer Content access events, authentication events, administrative actions, and billing operations are recorded in immutable audit logs. Logs are retained for 12 months. Enterprise Customers may request access to their organisation's audit log on request.
Vulnerability management
Stactiq conducts internal security reviews on a quarterly basis. Critical vulnerabilities in dependencies are patched within 72 hours of disclosure. Stactiq does not operate a public bug bounty programme. Responsible disclosure may be submitted to security@stactiq.ai.
Incident response
In the event of a confirmed data breach affecting Customer Content, Stactiq will notify affected Customers within 72 hours of confirmation, in accordance with GDPR Article 33 obligations where applicable. Notification includes the nature of the incident, data categories affected, and remediation steps taken.
Compliance posture
| Standard | Status |
|---|---|
| GDPR | Compliant — DPA available at /legal/dpa |
| CCPA | Compliant |
| SOC 2 Type II | In progress — target Q4 2026 |
| ISO 27001 | Roadmap — 2027 |
| FERPA | Evaluated on a per-Customer basis |