Skip to content

COMPLIANCE

Enterprise-grade compliance,
without compromise.

Stay ahead of regulatory requirements with globally recognized certifications and data protection standards.

Last audit
2026 Q1
Sub-processors
12
Trust center
Live
DPA
Self-serve

FRAMEWORKS

Compliance you can trust

Our certifications and frameworks ensure your business data remains safe, compliant, and reliable at every scale.

SOC 2 Type II 01 / 06

SOC 2 Type II

Independently audited controls for security, availability, and confidentiality.

Scope
Annual audit
Region
Global
ISO 27001 02 / 06

ISO 27001

Global standard for information security management systems.

Scope
Certified 2024
Region
Global
GDPR 03 / 06

GDPR

Compliant with the EU General Data Protection Regulation.

Scope
Continuous
Region
EU · EEA · UK
HIPAA 04 / 06

HIPAA

Safeguards for Protected Health Information (PHI). BAA available.

Scope
BAA on request
Region
United States
CCPA 05 / 06

CCPA

Meets California Consumer Privacy Act obligations end-to-end.

Scope
Continuous
Region
California, US
DPF · US-EU, UK, CH 06 / 06

DPF · US-EU, UK, CH

Certified under the Data Privacy Framework for cross-border transfers.

Scope
Cross-border
Region
US ⇄ EU · UK · CH

RECOMMENDED RESOURCES

Security at a glance

As a data company, we understand the importance of keeping your data secure. Stacksync is built with security best practices to keep your data safe at every layer.

FAQ

Frequently asked questions

Which compliance certifications does Stacksync hold?

SOC 2 Type II (audited annually by an independent CPA firm), ISO 27001 (information security management), HIPAA-aligned controls for healthcare workloads, GDPR-compliant for EU customer data, CCPA-compliant for California residents, and EU-US Data Privacy Framework (DPF) certified. The current audit reports are available on request under NDA. Trust-center documents are published at stacksync.com/security.

Is Stacksync HIPAA compliant for healthcare data?

Stacksync supports HIPAA-aligned deployments under a Business Associate Agreement (BAA). HIPAA-eligible plans run on isolated infrastructure with audit logging, encryption, customer-managed keys, and minimum-necessary access controls. The BAA is signed at the start of any healthcare engagement. Common HIPAA use cases include EHR-to-CRM sync, claims sync between billing platforms, and lab-result routing.

Where is Stacksync data processed and stored?

Data is processed in your chosen region: US (Virginia / Oregon), EU (Frankfurt / Ireland), or APAC (Singapore / Tokyo). Region pinning is enforced at the infrastructure layer — no customer data leaves the chosen region for any reason. Multi-region deployments are supported for enterprises with cross-regional sync needs. Backup data is replicated within the same region only.

Can I get a copy of the SOC 2 Type II report?

Yes — the full SOC 2 Type II report is available under NDA. Request it through your account team or the contact form. The report covers a 12-month audit period and is renewed annually. For initial security reviews, the executive summary is available without NDA. Many enterprise customers also request our ISO 27001 certificate and most recent penetration test summary at the same time.

Is Stacksync GDPR compliant for EU customer data?

Yes. Stacksync acts as a data processor under GDPR with a standard Data Processing Addendum (DPA) signed at contract. EU customer data is processed in EU regions only (Frankfurt or Ireland) when EU region pinning is enabled. Data subject access requests (DSAR) are supported via the dashboard: search for a customer, export their data, or delete on request. Audit trails of access and modifications are retained per GDPR Article 30.

Do you support customer-managed encryption keys?

Yes — CMEK is available on enterprise plans. Stacksync can encrypt customer data and credentials with keys managed in your AWS KMS or GCP KMS account. The Stacksync platform never holds the master key; if you revoke access, all encrypted data becomes unreadable until access is restored. CMEK supports key rotation, BYOK lifecycle, and external HSM integration.

How do you handle data subject access requests?

The dashboard includes a DSAR tool: search by email, name, or external ID; export the data subjects records as JSON or CSV; or delete on request. All DSAR actions are audit-logged. For complex deletion (where data has propagated through many sync paths), the platform shows the downstream systems affected before executing. Custom DSAR workflows can be built using the workflow engine.

GET STARTED

Syncing data at scale
across all industries.

  • POC from integration engineers
  • Two-way, real-time sync
  • Workflow automation
  • White-glove onboarding
Book a demo