View manually published system status

Security, privacy, and assurance

See how Stoatify keeps
your documents private.

Review the architecture, access controls, subprocessors, and security documents behind the Stoatify vault.

Encrypted transportHTTPS for public services
Organization-scoped queriesForbidden documents return 404
Private object storageFile access flows through the API
Security documentationPolicies and control reviews

Security architecture

Defense in depth across every file interaction.

Authenticated file requests resolve organization membership before document access. Signed preview and download requests also check the document state before returning content.

Request path

Files stay behind the API boundary.

Storage buckets are not public. Uploads, previews, and downloads flow through the Stoatify API, and clients do not receive object-storage credentials or presigned object-storage URLs.

01Client AppHTTPS connection
03Application MetadataOrganization-scoped records
04Private File StorageProvider-managed encryption at rest
01

Zero direct storage exposure

Storage buckets are not public. Uploads, previews, and downloads flow through the Stoatify API, and clients do not receive object-storage credentials or presigned object-storage URLs.

02

Multi-tenant data isolation

Authenticated requests resolve organization membership and scope document queries to the active organization. Forbidden document records return 404.

03

Built-in organization roles

Stoatify currently provides Owner, Admin, and Member roles for organization membership and administration.

04

Time-bounded access tokens

Preview and download URLs use short-lived, signed capabilities scoped to a user, document, and disposition, with document status checked when content is requested.

05

Document retention and deletion

Documents in Trash follow the organization's retention period. The purge process removes expired document records and their storage objects.

06

Authenticated identity

Stoatify validates sign-in tokens before authenticated API handlers resolve the requesting user and organization membership.

Assurance library

Security documents for your review.

Public attestations are available directly. Detailed questionnaires and operating policies require a work email.

PublicNo access request required
Public attestationAvailable

MVSP Self-Attestation

Stoatify's assessment against the Minimum Viable Secure Product baseline controls.

Operational transparencyPublic

System Status

Manually published component status, incidents, and service history for Stoatify.

Controlled accessWork email required when available
Security questionnaireAvailable

VSA Core

Vendor Security Alliance assessment of data protection, access control, and vulnerability management.

Operating policyAvailable

Information Security Policy

Governance for production security, access, key management, and risk management.

Operating policyAvailable

Data Deletion and Retention Policy

Document lifecycle, trash retention, permanent purge, and backup handling practices.

Operating policyAvailable

Incident Response Plan

Detection, containment, investigation, communication, and recovery procedures.

Subprocessors

Service providers and the work they perform.

Stoatify uses a focused set of service providers to operate the platform. The primary application database and customer file storage are located in the United States. Optional AI processing sends relevant document text to the listed AI providers when the user invokes that feature.

ProviderPurposeData involved
01RailwayApplication hosting and database infrastructureCustomer content, metadata, and service data
02CloudflareNetwork edge and traffic protectionNetwork and request metadata
03StripeSubscription billing and payment processingBilling and transaction data
04Backblaze B2Encrypted object storageCustomer file content
05ClerkAuthentication and identity managementAccount and authentication data
06Amazon Web ServicesTransactional email and SMS deliveryContact details and message content
07Microsoft AzureAzure OpenAI inference for AI-assisted organizationDocument text and AI output when the user invokes an AI feature

Have a security question?

Talk directly with our team.

For questionnaires, architecture questions, vulnerability reports, or procurement reviews, contact Stoatify security.

security@stoatify.com