Trust center
Give AI useful access without handing over every key.
Stackyapper sits between your team’s AI assistants and the systems your business uses. It keeps provider credentials private, checks what each person can use, and records what happened without routinely storing the business data returned by your apps.
What happens when AI asks to use a tool?
A connected AI assistant does not receive an open door to every app. Stackyapper checks the caller, workspace, connection, tool permission, action risk, and any required confirmation before it sends a request to the connected system.
- Identify the caller. The MCP endpoint authenticates the person or service making the request.
- Select the workspace. Users, connections, grants, sessions, and activity stay inside the chosen company or customer workspace.
- Check the exact tool. Connecting an app does not grant every operation. Current app and tool permissions are checked again when the tool runs.
- Apply action safeguards. Reads, writes, deletes, financial actions, and credential-sensitive actions can receive different treatment. Actions that require confirmation are bound to the arguments the user reviewed.
- Use the provider credential. Stackyapper resolves the separately stored app credential for the approved request. The AI client does not receive that credential.
- Record the outcome. Administrators can review operational metadata such as the actor, workspace, app, tool, result, client, and duration.
Read the complete security and access-control model for implementation details, infrastructure, retention, incident response, and the shared-responsibility boundary.
How credentials and business data are handled
- Provider credentials are encrypted at rest. They are resolved only for an authorized request and are not returned to the AI client.
- MCP API keys are stored as hashes. The original key cannot be read back from the database.
- Ordinary tool responses pass through. Stackyapper does not write the information returned by ordinary passthrough calls to its database or file system.
- Routine activity records contain metadata, not tool arguments or returned business data. Some clearly identified workflows may save an approved output or run record.
- Outbound connector traffic is restricted to public network addresses. This reduces the risk of using a connector to reach private infrastructure.
- Notification email carries identifiers and counts, not tool contents. No Stackyapper email includes tool arguments, data returned by a connected app, provider credentials, or API keys. See what an email contains.
What your administrators control
| Customer security feature | What your team can control |
|---|---|
| App and tool access | Allow an app or a smaller set of tools by group or person. Explicit restrictions take priority over broader grants. |
| Higher-impact actions | Require a short-lived confirmation bound to the exact proposed call when that safeguard applies. |
| Security alerts | Send currently available event types immediately or collect them into a daily summary. Owners and administrators are included, and verified shared recipients can be added. |
| Weekly security summary | Review access changes, alerts, higher-risk activity, denied requests, and other enabled summary sections in one scheduled email. |
| Location and network context | Record expected countries and choose whether audited client addresses are stored in full, truncated, or not retained. Immediate new-country and new-network alerts are not yet available. |
| Audit and investigation | Filter by workspace, time, app, outcome, and AI client, then export the narrowed activity record when needed. |
| Revocation | Remove an AI client, API key, session, app or tool grant, provider connection, or workspace membership without granting broader access elsewhere. |
| Managed identity | Business workspaces can use managed SAML and Microsoft Entra SCIM for company sign-in and user lifecycle management. |
AI client allow and block rules
Stackyapper's client-admission controls are in release verification. The release candidate lets direct workspace owners and administrators choose approved clients only, allow or block exact OAuth registrations and reviewed product profiles, and separately decide whether direct API-key clients may connect. This is not a general-availability claim until production canaries are complete.
See the administrator security checklist, notification settings, effective-access guide, and investigation guide.
What these controls do not promise
No MCP gateway can make every AI instruction, provider action, or compromised account safe.
Your organization still controls identity security, provider-side scopes, endpoint security, tool grants, workflow design, and human oversight. Stackyapper limits what an authenticated request can reach and gives administrators evidence to review. It does not replace those responsibilities.
Privacy, legal, and data-processing documents
- Privacy Policy: how personal and service data is handled.
- Data Processing Addendum: processing terms for customers.
- Subprocessors: third parties involved in delivering the service.
- Acceptable Use Policy: prohibited uses and customer responsibilities.
- Support Policy: email support, response targets, and service boundaries.
Certification status
Stackyapper does not hold a third-party security certification today.
The controls documented here are implemented product controls, not a certification or warranty. Certifications held by infrastructure providers apply to their infrastructure, not automatically to Stackyapper.
SOC 2 roadmap
Current status: Preparation. Stackyapper is preparing its security program and evidence collection for a future SOC 2 examination. Stackyapper is not currently SOC 2 certified, and no examination has been completed. We will update this Trust Center as milestones are reached and notify customers when our compliance status materially changes.
Security and review contact
Report a suspected vulnerability or security incident to security@stackyapper.dev. For product support, use support@stackyapper.dev or visit the support documentation.