---
title: "Security & Trust: SOC 2, ISO 27001, HIPAA | Stacksync"
description: "SOC 2 Type II report under NDA, what Stacksync stores and for how long, processing regions, and which plan includes MFA, SSO, SCIM and audit logs."
canonical: https://www.stacksync.com/security
last_modified: 2026-09-29
---

SECURITY

# Security & Trust.

Stacksync shares its SOC 2 Type II report under NDA through its Trust Center, and your security team can request it as soon as your evaluation starts. Two-way sync moves records between your systems without keeping a copy of them; logs and undelivered events persist only as this page sets out.

[Book a demo](https://www.stacksync.com/book-a-demo)

Stacksync holds SOC 2 Type II and ISO 27001, offers a Business Associate Agreement for HIPAA workloads, and covers GDPR, CCPA and DPF transfers. It encrypts data with TLS 1.2+ in transit and AES-256 at rest. MFA, SSO and SCIM, IP allowlisting, audit logs and region choice depend on your plan.

AT A GLANCE

## What your security review will ask first

**Short answers for a vendor security review. Plan availability matches the compare table on /pricing.**

| Question | Answer | Details |
| --- | --- | --- |
| Frameworks | SOC 2 Type II, ISO 27001, HIPAA, GDPR, CCPA and DPF US-EU, UK, CH. HIPAA workloads run under a Business Associate Agreement. | [Compliance](https://www.stacksync.com/compliance) |
| SOC 2 Type II report | Available under NDA from the Trust Center. Request it when your evaluation starts and check its audit period. | [Trust Center](https://security.stacksync.com/) |
| Does Stacksync store our records? | The two-way sync path keeps no copy. Five things do persist for a time: undelivered payloads and events, logs for your plan's retention period, encrypted connection credentials, sync state (record IDs and change-detection fingerprints) and any database or event queue you choose to host on Stacksync. | Data handling |
| Encryption | TLS 1.2+ in transit, AES-256 at rest. | Data handling |
| Compliance by plan | SOC 2 Type II, ISO 27001, HIPAA and DPF US-EU-UK-CH on Pro and up; GDPR and CCPA on every plan. | [Pricing](https://www.stacksync.com/pricing) |
| MFA, SSO and SCIM | MFA on Pro and up. SSO & SCIM on Enterprise only. | Plan controls |
| Processing region | You select it. The choice widens by plan, up to custom regions on Enterprise. | Plan controls |
| FedRAMP and on-premise | FedRAMP is not in the framework list above, so raise it before a POC. On-premise deployment is on Enterprise only. | Deployment |

SECURITY

## Security teams trust Stacksync

As a data company, we understand the importance of keeping your data secure. Stacksync is built with security best practices to keep your data safe at every layer, and is DPF-certified for US, EU, UK and CH data transfers.

[Learn more about security](https://www.stacksync.com/security)

|  |  |
| --- | --- |
|  | SOC 2 Type II |
|  | ISO 27001 |
|  | HIPAA BAA |
|  | GDPR |
|  | CCPA |
|  | DPF US-EU-UK-CH |

→ SECURITY WITH BENEFITS

### SSO & SCIM

Let your users access Stacksync from your centralized user management systems. Works with Okta, Azure, Google SSO and more.

### Alerts

Immediately get alerted about record syncing issues over email, Slack, PagerDuty and WhatsApp. Resolve issues from a centralized dashboard with retry and revert options.

### Secure connection options

Securely connects to your systems with:

[OAuth 2](https://www.stacksync.com/security) [SSH Tunnelling](https://docs.stacksync.com/two-way-sync/connectors/setup-options/ssh-tunneling) [SSL certificates](https://docs.stacksync.com/two-way-sync/connectors/postgres/authorize-postgres/amazon-rds/ensuring-secure-rds-connections-with-ssl-certificate) [IP Whitelisting](https://docs.stacksync.com/two-way-sync/connectors/setup-options/ip-whitelisting) [VPN gateway](https://docs.stacksync.com/two-way-sync/legal/service-consumption-tables#:~:text=%E2%9C%93-,VPN%20gateway,-%2D) [VPC peering](https://www.stacksync.com/security) and more

DATA HANDLING

## What Stacksync stores, and for how long

The sync path keeps no copy of your records. Five other places can hold data for a while, and your reviewer should know each one. Stacksync encrypts data with TLS 1.2+ in transit and AES-256 at rest.

1. 01

   ### Records in the sync path

   Stacksync reads a change from one system and writes it to the other. It keeps no copy of your records once the write lands. /pricing lists a “No data retention” policy on every plan, and that policy covers this path.
2. 02

   ### Undelivered payloads and events

   When a destination is down or rate-limits a write, Stacksync holds the sync payload or workflow event only as long as it needs to deliver it. You inspect failed records in the Issues dashboard and retry or revert them.

   [Issues dashboard docs](https://docs.stacksync.com/two-way-sync/features/issues-dashboard)
3. 03

   ### Logs

   Stacksync keeps sync and workflow logs for the retention period your plan sets (see the plan table below). Storing logs in your own storage is available on Enterprise only.
4. 04

   ### Connection credentials

   Stacksync stores OAuth tokens, API keys and database passwords encrypted. You can revoke or rotate them in the source system at any time.
5. 05

   ### Sync state

   Stacksync keeps the record IDs and change-detection fingerprints a sync needs to match records between the two systems and to detect changes.
6. 06

   ### Data you choose to host

   A database or event queue you run on Stacksync stores data by design. Those products sit outside the sync path, and you opt into them.

   [Database hosting](https://www.stacksync.com/database-hosting) [Event queues](https://www.stacksync.com/event-queues)

ENTERPRISE-GRADE PROTECTION

## Stacksync security enterprise-grade protection.

Stacksync syncs critical CRM, ERP and warehouse data in real time, under controls your security team can audit.

- ### AES-256 encryption

  Stacksync encrypts data in transit with TLS 1.2+ and at rest with AES-256. It stores connection credentials encrypted, and you can revoke or rotate them at any time.
- ### No copy in the sync path

  Stacksync processes records in flight and keeps no copy once the write lands. Sync payloads and workflow events stay only as long as delivery takes; logs follow your plan's retention period.
- ### Advanced connection security

  OAuth 2, SSH tunneling, SSL certificates, IP allowlisting, VPN gateway and VPC peering. Pick the model your security team already approved; the plan table shows where each one starts.

CONTROLS BY PLAN

## Which plan includes which control

This table reads from the [/pricing](https://www.stacksync.com/pricing) compare table, so the two pages match. Read the column for the plan you intend to buy: some controls and frameworks start above Starter, and a security review should see that before procurement does.

| Control | Starter | Pro | Managed Pro | Enterprise |
| --- | --- | --- | --- | --- |
| Access |  |  |  |  |
| Passwordless and social logins | Included | Included | Included | Included |
| MFA | Not included | Included | Included | Included |
| SSO & SCIM | Not included | Not included | Not included | Included |
| RBAC (Role Based Access Control) | Included | Included | Included | Included |
| Network |  |  |  |  |
| IP whitelisting | Not included | Included | Included | Included |
| SSH tunneling | Included | Included | Included | Included |
| SSL certificates | Not included | Included | Included | Included |
| VPC peering | Not included | Not included | Not included | Included |
| VPN gateway | Not included | Not included | Not included | Included |
| Private networking (PrivateLink, Azure Private Link, Google PSC) | Not included | Not included | Not included | Included |
| Data, logs and deployment |  |  |  |  |
| “No data retention” policy | Included | Included | Included | Included |
| Select processing region | Basic | Extended | Extended | All (incl. Custom) |
| Select cloud provider (GCP, AWS, or Azure) | Not included | Not included | Not included | Included |
| Log retention policy | 1 day | 7 days | 7 days | 30 days |
| Store logs in your own storage | Not included | Not included | Not included | Included |
| Audit logs | Not included | Not included | Not included | Included |
| Environments (Dev, Staging, Production) | 1 | 1 | 1 | 3 |
| On-premise deployment | Not included | Not included | Not included | Included |
| Compliance |  |  |  |  |
| SOC 2 Type II | Not included | Included | Included | Included |
| GDPR | Included | Included | Included | Included |
| CCPA | Included | Included | Included | Included |
| ISO 27001 | Not included | Included | Included | Included |
| HIPAA | Not included | Included | Included | Included |
| DPF US-EU-UK-CH | Not included | Included | Included | Included |

ENTERPRISE CAPABILITIES

## Enhance your data security

Network, region and deployment options for regulated teams. Several start at Enterprise; the plan table above lists each one.

- ### Private networking

  SSH tunnels through a bastion host, VPC peering, AWS PrivateLink, Azure Private Link, Google PSC and VPN gateways keep traffic off the public internet. Private networking is on Enterprise only.
- ### Regional processing

  You choose where Stacksync processes your data. Region choice by plan: Starter Basic, Pro Extended, Managed Pro Extended, Enterprise All (incl. Custom). Ask for the current region list and the egress IPs to allowlist during your review.
- ### MFA & SSO enforcement

  MFA on Pro and up; SSO & SCIM on Enterprise only. SCIM provisioning keeps your directory and Stacksync users in step.
- ### On-premise deployment

  On-premise deployment is on Enterprise only, for data that must stay in your own data center.

YOUR SECURITY REVIEW

## How to review Stacksync before sandbox access

Start these five steps on day one so the security review runs alongside the technical evaluation.

1. Step 1

   ### Request the documents

   The Trust Center holds the SOC 2 Type II report (under NDA), the security whitepaper, the subprocessor list and audit reports. The DPA, privacy notice and terms sit in the Stacksync docs. Check the SOC 2 audit period against what your own auditors need.

   [Trust Center](https://security.stacksync.com/) [DPA](https://docs.stacksync.com/security-and-other-resources/legal/data-processing-addendum-dpa)
2. Step 2

   ### Create a scoped integration user

   Give Stacksync a dedicated user or OAuth app in Salesforce, NetSuite, HubSpot or your database, limited to the objects the sync reads and writes. Keep personal admin logins out of it. You own that user, so revoking or rotating it cuts Stacksync off.
3. Step 3

   ### Settle vendor-staff access

   Ask your account team for Stacksync's staff-access terms and write them into your DPA or contract. Inside your workspace, RBAC (on every plan) sets what each of your own users can change.
4. Step 4

   ### Choose region, network and plan

   Pick the processing region and the connection model: SSH tunnel, IP allowlist or private networking. Then read the plan table for MFA, SSO & SCIM, audit logs and log retention.

   Plan controls
5. Step 5

   ### Bring your questionnaire to a call

   Book a demo and send your security questionnaire ahead of it, so the review runs next to the technical evaluation.

   [Book a demo](https://www.stacksync.com/book-a-demo)

RELATED READING

- [Compliance frameworks](https://www.stacksync.com/compliance)
- [Pricing and plan comparison](https://www.stacksync.com/pricing)
- [Two-way sync](https://www.stacksync.com/two-way-sync)
- [GDPR and two-way CRM sync](https://www.stacksync.com/blog/ensuring-gdpr-compliance-with-bidirectional-crm-synchronization)
- [Stacksync company facts and funding](https://www.stacksync.com/about)

RECOMMENDED RESOURCES

## Security at a glance

The documents your security review team will ask for. Request the SOC 2 report from the Trust Center below.

- [01 Policy Privacy policy How we protect and manage your personal data.](https://docs.stacksync.com/security-and-other-resources/legal/privacy-notice)
- [02 Legal Terms of service Rules and guidelines for using our platform.](https://docs.stacksync.com/security-and-other-resources/legal/terms-of-service-and-conditions-tc)
- [03 Legal Data Processing Addendum GDPR-compliant data processing framework.](https://docs.stacksync.com/security-and-other-resources/legal/data-processing-addendum-dpa)
- [04 Guide AI agent governance Approvals, access, logs and AI scope for Copilot and Genies.](https://www.stacksync.com/security/ai-agents)

TRUST CENTER

### Live status for all things compliance

The SOC 2 Type II report under NDA, security whitepapers, subprocessors, audit reports and one-click access to our policies.

[Visit Trust Center](https://security.stacksync.com/)

FAQ

## Frequently asked questions

### How do we get Stacksync's SOC 2 Type II report?

Request it under NDA through the Stacksync Trust Center at security.stacksync.com, which also holds the security whitepaper, the subprocessor list and audit reports. Ask for it when your evaluation starts, and check the audit period against what your own auditors need.

### Does Stacksync store my Salesforce data or just pass it through?

The two-way sync path passes records through: Stacksync reads a change, writes it to the other system and keeps no copy. Five things do persist for a time: undelivered payloads and events, logs for your plan's retention period, encrypted connection credentials, sync state (record IDs and change-detection fingerprints) and any database or event queue you choose to host on Stacksync. Stacksync encrypts data with TLS 1.2+ in transit and AES-256 at rest.

### Which Stacksync plans include SOC 2, ISO 27001 and HIPAA coverage?

The compare table on /pricing lists SOC 2 Type II, ISO 27001, HIPAA and DPF US-EU-UK-CH on Pro and up; GDPR and CCPA on every plan. HIPAA workloads run under a Business Associate Agreement. If your review needs a framework on a specific plan, confirm it in your order form before you sign.

### Are SSO, SCIM and MFA available on every Stacksync plan?

No. Per the /pricing compare table, MFA is on Pro and up, SSO and SCIM on Enterprise only, and IP allowlisting on Pro and up. Passwordless and social logins and role-based access control are on every plan.

### Can Stacksync keep processing in the EU for GDPR?

Yes, Stacksync offers EU processing regions. You select the region for your workspace, and the choice widens by plan, up to every region including custom locations on Enterprise. Stacksync signs a Data Processing Addendum as a GDPR processor and is DPF-certified for US, EU, UK and Swiss transfers. If your policy requires EU-only processing with no US transit, ask for the current region list, the control-plane location and the egress IPs during your review, and write the requirement into the DPA.

### How does Stacksync govern its AI features?

Stacksync governs its AI features with the same platform controls as the rest of the product: role-based access, approval steps that hold a write until a person signs off, and the log explorer for each run. Stacksync AI Copilot builds integrations and workflows from a prompt, and Genies are AI agents that act across your connected systems. You can build two-way sync and workflows by hand when a policy keeps AI out of scope. The AI agent governance page at /security/ai-agents covers approvals, audit and the questions to raise in a security review.

### Does the processing region cover AI inference?

Not as published: the processing region you select covers sync processing, and the site does not yet state where AI inference for Stacksync AI Copilot and Genies runs. Ask for the inference region, model providers and retention terms in writing during your security review and check them against the Data Processing Addendum and the sub-processor list in the Trust Center. /security/ai-agents lists these questions.

### How does Stacksync access our systems?

Through the integration user or OAuth app you create, scoped to the objects the sync needs. Stacksync stores its credentials encrypted, and revoking or rotating that user in the source system stops access. For the terms that govern Stacksync staff access, ask your account team and put them in your DPA or contract.

### What should government contractors check about FedRAMP and GovCloud?

Raise FedRAMP and GovCloud requirements with Stacksync before a POC and get the answer in writing, because FedRAMP is not among the frameworks this page lists. For data that must stay in your own data center, on-premise deployment is on Enterprise only.

### What security documents should we request before giving an integration vendor sandbox access?

Ask for the SOC 2 Type II report with its audit period, the ISO 27001 certificate, the security whitepaper, the Data Processing Addendum and the subprocessor list. Then confirm three answers in writing: what the vendor stores, where it processes data, and which plan includes the controls you need. For Stacksync, the Trust Center holds the SOC 2 report, whitepaper and subprocessor list, and the DPA sits in the Stacksync docs.
