Security
Compliance
PandaStack's current compliance posture — what exists today, stated plainly, with no certifications claimed that we do not hold.
This page states what exists today. We would rather be precise than impressive.
What we have
- Coordinated vulnerability disclosure. A security.txt is published per RFC 9116 with a monitored security contact. If you find a vulnerability, that is the fastest path to us.
- Data Processing Agreement. A GDPR Article 28 DPA is available, incorporating Standard Contractual Clauses and a technical-and-organizational-measures annex that describes the real architecture (the same one documented in the isolation model and data handling pages).
- Subprocessors list. Our subprocessors are published — the infrastructure and service providers that process customer data on our behalf.
- Public security posture. The security page on our website describes our controls and posture, including what we do not yet have.
- Open source. The platform is Apache-2.0 licensed. The isolation, networking, and data-path code these security pages describe is public and independently auditable — you are not limited to trusting a summary PDF.
- Self-hosting. For data-residency or regulatory requirements that a managed service cannot meet, you can run PandaStack on your own infrastructure, in your own cloud account or on-prem, where data never leaves your environment.
What we do not have (yet)
We do not currently hold a SOC 2 report, ISO 27001 certification, or HIPAA compliance attestation, and we will not claim them until an independent audit says so. If your procurement process requires a specific certification, tell us — audit scope and timing are driven by customer demand.
Security questionnaires
For vendor reviews, our public security posture page answers most standard questions; for anything it does not cover, contact us and we will complete your questionnaire directly.