SECURITY · DATA HANDLING · NO CERTIFICATIONS

We hold no
certifications. Here is
what we actually do.

No SOC 2. No ISO 27001. No FedRAMP. No HIPAA BAA. No penetration test. What follows is a plain description of how your data is stored, who can reach it, and what happens when you delete it.

Open the Trust Center Privacy policySub-processorsAsk a question
01 / The disclosure

Read this first.

Security pages exist to make you comfortable. This one exists to make sure you are not comfortable for the wrong reasons.

wrxstack is an independent product built by one person. It has never been audited by a third party. No CPA firm has issued an attestation about it. No certification body has certified anything about it. No security firm has tested it.

Are you evaluating wrxstack for regulated data? Health records, cardholder data, government workloads, or anything covered by a compliance regime your organization answers for? Then the correct decision is to choose a different vendor. We will not pretend otherwise to win the deal.

If you are an individual, a small team, or a company storing ordinary business data, read on. The controls below are real, they are modest, and we have described them without inflation.

02 / What we do

The controls that exist.

Each item here is either something you can independently verify, or something enforced by a provider underneath us whose terms we are bound by. Nothing on this list rests on our good intentions alone.

Encryption

TLS 1.3 in transit on every domain, with HTTP redirected rather than served. Data at rest sits on managed storage with provider-level volume encryption.

  • Verify the transit claim yourself with any SSL checker
  • At-rest encryption is inherited from our host, not built by us
  • We do not offer customer-managed keys, BYOK, or KMS integration

Identity and access

Authentication is handled at auth.wrxstack.com. Passwords are hashed, never stored in plaintext, and never logged.

  • Access to production is limited to the people who build it
  • SAML and OIDC single sign-on is available, with just-in-time provisioning and group-to-role mapping
  • We do not offer SCIM provisioning or custom RBAC roles
  • Enable MFA on your account if it is offered to you

AI and your content

Your content is not used to train any model, ours or anyone else's. We use model providers on API tiers whose terms prohibit training on submitted data.

  • Prompts are not retained at the model layer beyond the request
  • We do not fine-tune on customer content
  • Sub-processors receiving content are named on the Trust Center

Dependencies and patching

Dependencies are updated when advisories land. Automated dependency alerts are enabled on the repository.

  • We do not run SAST, DAST, or container scanning in CI
  • We have no formal patch SLA and will not invent one
  • We have never commissioned a penetration test

Availability and backups

The application runs on managed hosting with automated database backups taken by the provider. There is no published SLA and no service credit scheme.

  • Single region. No multi-region failover
  • No disaster-recovery drill cadence, and no rehearsed restore
  • Live checks on the status page, which measures rather than estimates

Retention and deletion

Delete your account and we delete your data from the live database. Provider backups age out on the provider's own rotation, which we do not control.

03 / What we do not do

Stated explicitly.

Absence of a claim is easy to miss. So rather than let you infer these from silence, here they are as a list. If a competitor's page lists any of these and ours does not, that difference is real.

CapabilityStatusWhat to do instead
SOC 2 / ISO 27001 reportDoes not existUse a vendor that has one. See the Trust Center.
Signed BAA for PHINot offeredDo not store protected health information in wrxstack.
Penetration test summaryDoes not existNothing to request. We will say so if you ask.
Completed CAIQ / SIG / HECVATNot maintainedSend yours and we will answer it honestly, including the blanks.
Customer-managed encryption keysNot supportedEncryption keys are managed by our hosting provider.
Data residency selectionNot supportedSingle region. Ask us which one before you commit.
Single-tenant VPC, on-prem, air-gapNot offeredMulti-tenant managed cloud is the only deployment.
Uptime SLA with creditsNot offeredBest effort. Watch the status page.
24/7 on-call rotationDoes not existIncidents are handled during waking hours by a human, not a rota.
Paid bug bountyNot fundedReport anyway to contact@wrxstack.com. We will credit you.
04 / The AI question

"Is our data used to train your models?"

No. This is the question worth answering carefully, because it is the one where a vague answer does the most damage.

No training

Not by us. Not by our providers.

wrxstack does not train, fine-tune, or evaluate models on your content. We call model providers through their commercial API tiers, whose terms prohibit training on submitted data. That prohibition is theirs to honor, and it is the strongest form of this promise available to us.

No retention at the model layer

Prompts are not stored by the model.

The provider returns a completion and does not retain the prompt beyond serving the request and its own abuse-monitoring window. We do not have a negotiated zero-retention agreement, and we are not going to claim one.

What we do store

Your content, so the product works.

Tasks, documents, and messages live in our database because that is what makes them retrievable. They are readable by the application, and in principle by whoever operates it. Encryption at rest protects the disk, not the query.

Who else sees it

Only the vendors we name.

The hosting provider, and the model provider for the specific text you send to an AI feature. Both are listed on the Trust Center. Nobody else. We do not sell data and we have no advertising business.

Opting out

Do not use the AI features.

If you never invoke an AI feature, no content leaves our hosting provider for a model provider. There is no background indexing job quietly sending your documents somewhere for embedding.

Bring your own model

Not supported today.

You cannot point wrxstack at your own Azure OpenAI, Bedrock, or Vertex endpoint, and you cannot run inference inside your own tenant. If that is a requirement, it is a requirement we do not meet.

05 / Questions

Frequently asked questions.

The questions a security reviewer actually asks, answered without spin. Where the answer is no, it says no.

Is my data encrypted in transit and at rest?

Yes. Every request is served over TLS 1.3, and HTTP is redirected rather than accepted, so you can confirm the transit claim with any SSL checker. Data at rest sits on managed storage with provider-level volume encryption. The at-rest encryption is inherited from our hosting provider, not something we built, and we do not offer customer-managed keys.

Is my content used to train AI models?

No. wrxstack does not train, fine-tune, or evaluate any model on your content, and we do not permit our model providers to. We call model providers on their commercial API tiers, whose terms prohibit training on submitted data. If you never invoke an AI feature, your content never leaves our hosting provider for a model provider at all.

Do you support single sign-on and SAML?

Yes. SAML and OIDC single sign-on is available, with just-in-time provisioning and group-to-role mapping. Authentication is handled at auth.wrxstack.com, passwords are hashed and never logged, and we do not offer SCIM provisioning or custom RBAC roles.

Is there an audit log?

Yes. Administrative and security-relevant actions are recorded to an audit log so you can see who did what and when. Access to production itself is limited to the people who build wrxstack.

How do I export or delete my data?

Ask for an export before you delete and we will send it. Delete your account and we remove your data from the live database. Provider backups age out on the provider's own rotation, which we do not control. Deletion requests go to contact@wrxstack.com and the full detail is in the privacy policy.

What security certifications do you hold?

None. wrxstack holds no SOC 2, no ISO 27001, no FedRAMP, and no HIPAA BAA, and it has never had an independent penetration test. If your review requires an attestation, wrxstack will fail it, and it should. Send your questionnaire and we will answer it honestly, including the blanks.

Can you store regulated data like health or cardholder records?

No. We do not sign a BAA, so do not store protected health information in wrxstack. Payments, if any, are handled by a third-party processor and we never see card data. For anything covered by a compliance regime your organization answers for, choose a vendor that carries the matching attestation.

Security

Send your questionnaire.
We will fill in the blanks.

Including the ones where the answer is no. A security review of wrxstack should be short, and it should end with an accurate picture rather than a favorable one.