StackAdapt Trust and Security Center
Last Updated and Effective: July 30, 2026
StackAdapt’s Commitment to Trust
At StackAdapt, protecting our clients’ data is a core responsibility and a fundamental part of how we operate. We are committed to maintaining industry-recognized security and compliance practices to safeguard data and earn the trust of our clients, partners, and stakeholders.
Our information security program is designed to align with industry-recognized frameworks and best practices, including ISO/IEC 27001:2022 and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). We continuously review our internal security program in order to drive enhancements, identify and manage key risks and assess changes to the evolving threat landscape.
Security Program Overview
StackAdapt maintains a comprehensive, risk-based information security program designed to protect the confidentiality, integrity, and availability of users, systems and information within our environment.
Our information security program includes:
- A formal Information Security Management System (ISMS)
- Defined security policies, standards and guidelines
- Clearly assigned roles, responsibilities, and an accountability framework
- Ongoing risk assessment and controls testing
- Continuous monitoring and improvement
Security governance is led by our Information Security Team and supported by cross-functional stakeholders across the organization.
Policies, Standards, and Guidelines
StackAdapt maintains a comprehensive set of information security policies, standards, and guidelines designed to set clear rules, consistent requirements, and practical guidance for managing security risks across the organization. These policies, standards and guidelines define employee responsibilities and management oversight for safeguarding StackAdapt’s data and systems. All policies are reviewed at least annually, approved by senior management, and communicated to all employees.
Security Controls and Safeguards
StackAdapt implements and maintains layered administrative, technical, and organizational controls to protect information assets.
Key security measures include:
- Encryption of data in transit and at rest
- Role-based access controls, least-privilege principles and regular user access reviews
- Industry-standard authentication controls
- Background checks on all new employees, where local laws permit
- Data classification and handling procedures
- Asset lifecycle management procedures
- Secure configuration and management of endpoints/software
- Secure development and change/configuration management practices
- Vulnerability and patch management processes
- Annual penetration testing
- Centralized logging and security monitoring
Infrastructure Security
The StackAdapt platform is a fully cloud-based solution, with no on-premise infrastructure. StackAdapt’s systems are hosted across multiple Availability Zones in Amazon Web Services (AWS) data centers, providing high availability and resilience.
AWS data centers employ industry-leading physical, environmental, and operational security measures. Security in the cloud follows a shared responsibility model, where AWS secures the underlying infrastructure, and StackAdapt secures its applications, configurations, and client data. For more information, please refer to AWS Trust Center.
Risk Management
StackAdapt maintains an enterprise-wide risk management framework designed to identify, assess, and manage risks across the organization. Formal risk assessments are conducted on a regular basis.
In support of this framework, the Information Security team maintains a documented Information Security Risk Management Policy that defines how security risks are identified, assessed, treated, and monitored. The team also maintains an Information Security Risk Register to track identified risks, mitigation activities, and residual risk, and conducts regular security risk reviews to support continuous improvement of StackAdapt’s security posture.
StackAdapt maintains insurance coverage, including cyber liability insurance, designed to address material operational and security risks in accordance with industry practice.
Vendor Security
StackAdapt maintains a formal Vendor Security Policy that defines the process for identifying, assessing, and managing information security risks associated with third party vendors. Vendors are evaluated based on risk, and appropriate security and privacy controls are required when third parties process or access StackAdapt data.
StackAdapt maintains a list of approved subprocessors that may process client data. StackAdapt’s subprocessors are thoroughly vetted to ensure their own privacy and security programs are at least equally as protective as StackAdapt’s own, and are bound through contractual obligations to maintain such programs at an acceptable standard.
Security Awareness and Training
All StackAdapt employees are required to complete security and privacy training upon hire and annually thereafter. Training is reinforced through monthly phishing awareness simulations, among other things, in order to promote strong security awareness across the organization as part of StackAdapt’s culture.
Resilience
StackAdapt maintains a documented Backup Policy that defines the requirements for data backup, restoration, and monitoring within its cloud-based environment. Backups of critical data are performed regularly using AWS-native backup capabilities to support data availability and recovery objectives.
StackAdapt maintains a formal Disaster Recovery and Business Continuity Plan that governs its approach to maintaining the resilience of critical IT systems and responding to disruptive events. The plan outlines response and recovery activities involving service disruption or data loss, and includes defined Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) for key StackAdapt platform services. The plan is tested on a periodic basis, and no less than annually.
Incident Response
StackAdapt maintains a Security Incident Response Plan that governs the procedures for detecting, analysing, containing, eradicating, responding to security incidents, and post-incident root cause analysis. Incident response exercises are conducted annually.
In the event of a confirmed security incident impacting client data, StackAdapt will notify affected clients without undue delay and in no event later than forty-eight (48) hours after confirmation of the incident, in accordance with applicable contractual and regulatory requirements.
Compliance and Certification

StackAdapt maintains a comprehensive information security and compliance program designed to protect the confidentiality, integrity, and availability of its systems and data. The effectiveness of this program is verified through independent third-party audits conducted annually, including SOC 1 (Type II) and SOC 2 (Type II) examinations. Audit reports can be requested from your StackAdapt Account Manager.

StackAdapt maintains compliance with the Payment Card Industry Data Security Standard (PCI DSS). StackAdapt leverages Stripe, a PCI DSS–compliant payment processor, to securely handle payment card transactions. StackAdapt does not store full payment card numbers on its systems and relies on Stripe’s secure infrastructure to process and protect cardholder data in accordance with PCI DSS requirements.

StackAdapt complies with the EU–U.S. Data Privacy Framework (EU–U.S. DPF), the UK Extension to the EU–U.S. DPF, and the Swiss–U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce. StackAdapt has certified that it adheres to the Data Privacy Framework Principles for the processing of personal data transferred from the EU, UK, and Switzerland to the United States. More on certification details.
Security, privacy, and responsible innovation are embedded in how StackAdapt operates. Our comprehensive governance framework, technical safeguards, and independent certifications reflect our commitment to protecting customer data and maintaining platform resilience. We continuously evaluate and enhance our controls to meet emerging risks and evolving regulatory expectations.
Contact the Information Security Team
Contact us at security@stackadapt.com for any questions you may have.


