Zero direct storage exposure
Storage buckets are not public. Uploads, previews, and downloads flow through the Stoatify API, and clients do not receive object-storage credentials or presigned object-storage URLs.
Security, privacy, and assurance
Review the architecture, access controls, subprocessors, and security documents behind the Stoatify vault.
Security architecture
Authenticated file requests resolve organization membership before document access. Signed preview and download requests also check the document state before returning content.
Storage buckets are not public. Uploads, previews, and downloads flow through the Stoatify API, and clients do not receive object-storage credentials or presigned object-storage URLs.
Storage buckets are not public. Uploads, previews, and downloads flow through the Stoatify API, and clients do not receive object-storage credentials or presigned object-storage URLs.
Authenticated requests resolve organization membership and scope document queries to the active organization. Forbidden document records return 404.
Stoatify currently provides Owner, Admin, and Member roles for organization membership and administration.
Preview and download URLs use short-lived, signed capabilities scoped to a user, document, and disposition, with document status checked when content is requested.
Documents in Trash follow the organization's retention period. The purge process removes expired document records and their storage objects.
Stoatify validates sign-in tokens before authenticated API handlers resolve the requesting user and organization membership.
Assurance library
Public attestations are available directly. Detailed questionnaires and operating policies require a work email.
Stoatify's assessment against the Minimum Viable Secure Product baseline controls.
Manually published component status, incidents, and service history for Stoatify.
Vendor Security Alliance assessment of data protection, access control, and vulnerability management.
Governance for production security, access, key management, and risk management.
Document lifecycle, trash retention, permanent purge, and backup handling practices.
Detection, containment, investigation, communication, and recovery procedures.
Subprocessors
Stoatify uses a focused set of service providers to operate the platform. The primary application database and customer file storage are located in the United States. Optional AI processing sends relevant document text to the listed AI providers when the user invokes that feature.
Have a security question?
For questionnaires, architecture questions, vulnerability reports, or procurement reviews, contact Stoatify security.