Skip to main content
Security & Privacy

Security & GDPR FAQs

A high-level overview of our security practices, GDPR compliance, and data protection measures. For detailed documentation, contact our support team.

Security Infrastructure

Where is ShortStack hosted?
ShortStack is hosted on Amazon Web Services (AWS) infrastructure located in the United States, in data centers AWS maintains under its own SOC 2 Type II certification. We use multiple availability zones for redundancy and high availability.
How is data encrypted?
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption.
What security certifications does ShortStack have?
ShortStack itself is not SOC 2 or ISO 27001 certified. Our infrastructure providers maintain SOC 2 Type II, ISO 27001, and PCI DSS Level 1 certifications, and ShortStack runs weekly automated vulnerability and web application scanning with continuous cloud configuration monitoring, and supports customer-initiated penetration testing — see 'How often do you conduct security assessments?' below.
How do you handle DDoS attacks?
Campaign pages are served through a global content delivery network with always-on network-layer DDoS mitigation, and all public traffic sits behind a web application firewall that filters malicious request patterns at the edge. Our infrastructure scales to absorb traffic spikes.

Access Control

Who has access to customer data?
Access to customer data is strictly limited to authorized ShortStack personnel who require it for their job functions. All employees sign confidentiality agreements, complete annual security awareness training, and review and acknowledge our Employee Security Policy annually.
Does ShortStack support multi-factor authentication?
Yes. MFA is available on all customer accounts using a TOTP authenticator app, and we strongly recommend enabling it. For ShortStack staff it is not optional — multi-factor authentication is required for all administrative access to production, enforced by the platform rather than left to individual configuration.
How are employee access rights managed?
We implement role-based access control (RBAC) with the principle of least privilege. Access is reviewed periodically and revoked promptly on role change or departure. All access is logged and monitored.

GDPR Compliance

Is ShortStack GDPR compliant?
Yes. ShortStack acts as a data processor and has implemented technical and organizational measures designed to meet its obligations under the General Data Protection Regulation (GDPR), as set out in our Data Processing Agreement and its Annex II. GDPR compliance is a shared responsibility: as the data controller, you determine what personal data you collect through ShortStack and for what purpose.
Can I sign a Data Processing Agreement (DPA)?
Yes, our DPA is available to all customers and covers our obligations as a data processor. View our Data Processing Agreement page for full details and to request execution.
How do I exercise data subject rights (access, deletion, etc.)?
As the data controller, you can access, export, and delete data directly through your ShortStack account. For assistance with data subject requests, contact our support team at support@shortstack.com.
Where is personal data stored?
Personal data is stored primarily in AWS data centers in the United States. For transfers from the EEA, Switzerland and the United Kingdom, our Data Processing Agreement makes available the EU Standard Contractual Clauses, those same clauses as modified to satisfy the Swiss nFADP, and the UK Addendum to the SCCs for transfers subject to the UK GDPR. Pancake Laboratories is also certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework. See Section 11 of our DPA for details.
How long is data retained?
Data is retained for the duration of your subscription. You can also set an automatic retention period on any entry list, after which entries older than that period are purged on your schedule. Deleted entries are removed permanently after a 30-day grace period. If you request permanent deletion of your account, deletion is immediate and irreversible as described in our Terms and Conditions; if a subscription simply lapses or an account is closed without that request, the account is disabled and becomes eligible for permanent purge 30 days later, unless retention is required by law. Backup copies age out under our backup retention schedule.

Data Protection

How do you prevent data breaches?
We apply layered controls: a web application firewall at the edge, network segmentation with application and database tiers in private subnets, mandatory multi-factor authentication for staff access, weekly automated vulnerability scanning with continuous cloud configuration monitoring, and annual security policy acknowledgement for all employees. We also maintain documented incident response and business continuity procedures.
What happens if there is a data breach?
In the event of a breach, we will notify affected customers within 48 hours of becoming aware. We will provide details about the breach, affected data, and remediation steps. We also assist with regulatory notifications as required.
How is data backed up?
Databases are replicated across multiple availability zones with automatic failover, and backups are encrypted, automated and continuous. Backup copies are retained on a defined schedule and replicated to a second AWS region, so copies are held in multiple geographic locations — all of them within the United States. Restoration is tested periodically, and backup and recovery procedures are documented in our Business Continuity Plan. Detailed retention periods and measured recovery durations are available on request.
Can I export my data?
Yes, you can export all your data at any time through your account dashboard. We provide export functionality in multiple formats including CSV and JSON.

Compliance & Auditing

What other compliance standards does ShortStack meet?
In addition to GDPR, we comply with CCPA (California), PIPEDA (Canada), Australian Privacy Act, UK DPA, Swiss DPA, and participate in the EU-U.S. Data Privacy Framework.
Can I audit ShortStack's security practices?
Yes. Audit rights are set out in our Data Processing Agreement and are available subject to the notice, frequency and confidentiality conditions stated there. On written request we can also make available documentation and certifications demonstrating our compliance.
How often do you conduct security assessments?
We run weekly automated vulnerability and web application scanning against our production environment, with continuous monitoring of our cloud configuration, and findings are triaged and tracked to resolution under documented severity timelines. We also support customer-initiated penetration testing: with reasonable prior written notice we will coordinate a testing window, review the results with you, and remediate validated findings.
Do you have a bug bounty program?
Yes, we maintain a responsible disclosure program. Security researchers who discover vulnerabilities can report them to support@shortstack.com. Reports are reviewed regularly, and validated findings are tracked and remediated under documented severity timelines.

Application Security

How do you prevent SQL injection and XSS attacks?
We use parameterized queries, input validation, output encoding, and Content Security Policy (CSP) headers. Our code undergoes regular security reviews and automated vulnerability scanning.
How are passwords stored?
Passwords are stored only as salted one-way hashes, using an algorithm purpose-built for password storage. We never store passwords in plain text, and password complexity requirements are enforced.
Do you scan for vulnerabilities?
Yes. We run continuous automated scanning of our cloud environment configuration alongside weekly automated web application scanning. Application dependencies — server-side libraries, JavaScript packages and container images — are audited on a defined cadence, and significant changes also receive a manual security review before release.
How quickly are security patches applied?
Security patches are tracked from the time of discovery and resolved under documented severity-based timelines, with critical and high-severity findings prioritized. Anything with an active exploit path against customer data is escalated and patched immediately. Where a patch is unavailable or blocked for a technical or business reason, the reason is recorded in the tracking item.

Third-Party Security

How do you vet third-party service providers?
All subprocessors undergo security and privacy assessments before engagement. We maintain a list of approved subprocessors and notify customers of changes. See our Subprocessors page for details.
Do third parties have access to my data?
Subprocessors only access data as necessary to provide specific services (e.g., hosting, email delivery). All subprocessors sign Data Processing Agreements and comply with our security standards.

Additional Resources

For more detailed information, review our compliance documentation.

Still have questions?

Contact our support team for specific inquiries.