Effective: October 2, 2026
1. Our approach
Stack Max builds and operates software for businesses, and security is treated as part of engineering rather than a step at the end. We favor managed, well-maintained infrastructure, typed and reviewed code, least-privilege access, and designs that keep the amount of sensitive data we hold as small as the work allows.
2. Technical and organizational measures
- Encryption in transit. Our websites and services are served over TLS, with HTTP Strict Transport Security enabled.
- Encryption at rest. Managed databases and object storage use provider-level encryption at rest.
- Access control. Production access is limited to those who need it, protected by multi-factor authentication and revoked promptly when no longer required.
- Secret management. Credentials and API keys are held in managed secret stores and environment configuration, never committed to source control.
- Dependency hygiene. Dependencies are kept current, and security advisories affecting our stack are reviewed and patched on a priority basis.
- Change management. Changes move through version control and review before reaching production, with the ability to roll back.
- Backups. Production data stores are backed up by our infrastructure providers with point-in-time recovery where the service supports it.
- Payments. Card payments are handled by established payment processors. We do not store full payment card numbers or card security codes on our systems.
- Data minimization. This website requires no account. Contact inquiries submitted through the embedded Typeform on our contact page are processed by Typeform as our service provider and retained only as needed to respond and administer the relationship.
No system is perfectly secure. These measures reduce risk; they are not a guarantee, and this page is a description of our practices rather than a contractual commitment. Security obligations for a specific engagement are set in the applicable written agreement.
3. Reporting a vulnerability
We welcome reports from security researchers and will not pursue legal action against anyone who reports a vulnerability in good faith under the guidelines below.
Email contact@stackmax.tech with the subject line “Security report.” Please include the affected domain or product, a description of the issue and its impact, and the steps or proof of concept needed to reproduce it. We acknowledge reports within three business days and will keep you informed as we investigate. We ask that you give us a reasonable opportunity to remediate before disclosing publicly, and we are glad to credit reporters who would like acknowledgement.
4. Testing guidelines
When investigating, please:
- test only against systems operated by Stack Max LLC;
- use only your own accounts and test data, and stop as soon as you confirm a vulnerability;
- avoid accessing, modifying, exfiltrating, or retaining data belonging to anyone else, and delete any such data you encounter incidentally;
- avoid denial-of-service testing, physical attacks, social engineering of our staff or providers, spam, and anything that degrades service for others;
- avoid automated scanning at a volume that would affect availability, and respect rate limits.
We do not currently operate a paid bug bounty program. Out-of-scope reports include missing best-practice headers with no demonstrated impact, results from automated scanners without a working proof of concept, and vulnerabilities in third-party services we do not control, which should be reported to that provider.
5. Incident response
If we become aware of a security incident affecting personal data or client systems, we move to contain and remediate it, assess the scope and impact, and notify affected clients and, where applicable, regulators within the timeframes required by law. Where we act as a processor for a client, we notify that client without undue delay so they can meet their own obligations.
6. Security questionnaires and due diligence
For vendor security reviews, due diligence questionnaires, or documentation required by your procurement or compliance process, email contact@stackmax.tech with the requesting organization and what is needed. We respond to these requests in writing.