What we can prove.
And what we cannot.
wrxstack is a small, independent product. We hold no security certifications. Rather than imply otherwise with badges, this page states exactly where we stand, what we actually do with your data, and who else touches it.
No badges we have
not earned.
Security certifications are audits, not adjectives. Each one below requires an accredited third party, a defined observation window, and a real fee. We have not been through any of them. If a vendor page tells you otherwise about us, it is out of date.
| Framework | What it requires | Our status |
|---|---|---|
| SOC 2 Type I / II | Attestation by a licensed CPA firm over an observation window | Not held. No audit has been performed. |
| ISO/IEC 27001 | Certification by an accredited certification body | Not held. No ISMS has been certified. |
| ISO/IEC 27017, 27018 | Extensions to a certified ISO 27001 ISMS | Not held. |
| FedRAMP | Federal agency sponsor and a 3PAO assessment | Not held. No sponsor, no assessment, not in process. |
| HIPAA / HITECH | A signed BAA and the safeguards of 45 CFR 160 and 164 | We do not offer a BAA. Do not put PHI in wrxstack. |
| PCI DSS | QSA assessment or a completed self-assessment questionnaire | Not applicable. Payments, if any, are handled by a third-party processor. We never see card data. |
| CSA STAR, HITRUST | Registry submission or validated assessment | Not held. Not submitted. |
| Independent penetration test | An engagement with a security firm | None performed. We have never commissioned one. |
| GDPR / UK GDPR | A legal obligation, not a certificate anyone issues | We are subject to it and describe our handling in the privacy policy. |
| CCPA / CPRA | A legal obligation, not a certificate anyone issues | We do not sell or share personal information. See the CCPA statement. |
GDPR and CCPA sit apart from the rest of this table on purpose. They are laws that apply to us whether or not we do anything about them, and no body issues a certificate for either. Every other row is a badge that must be granted by someone else, and nobody has granted us one.
The short, verifiable list.
Everything here is something you can check yourself, or something we are contractually bound to by the providers underneath us. There is nothing on this list that depends on you taking our word for it.
Encrypted in transit
Every request to wrxstack.com, atlas.wrxstack.com, and portfolio.wrxstack.com is served over TLS. HTTP is redirected, not accepted. You can confirm this from your browser's address bar or with any SSL checker.
256
Encrypted at rest
Application data is stored on managed infrastructure with volume-level encryption at rest enabled by the provider. This is inherited from our host, not something we implemented, and we will not claim more than that.
TRAIN
Your content does not train models
We do not train any model on your content, and we do not permit our model providers to. This is enforced by the provider's API terms on the tier we use, not by a promise we make on our own behalf.
Things we deliberately do not claim: customer-managed encryption keys, regional data residency, single-tenant deployment, on-premise or air-gapped installation, a 24/7 on-call rotation, a formal vulnerability management SLA, background checks, or a disaster-recovery drill cadence. None of those exist here today.
Everyone who touches it.
The complete list of third parties involved in running wrxstack. If a vendor is not on this list, it does not receive your data. We update this page before adding a new one, not after.
| Vendor | Purpose | What it receives |
|---|---|---|
| Render | Application and site hosting | All application data, at rest and in transit |
| PostHog | Product analytics on the marketing site | Page views, coarse device and country data |
| Google Tag Manager | Analytics tag loading | Page load events |
| FormSubmit | Contact form delivery | Whatever you type into the contact form |
Tell us, and we will fix it.
We read every report, respond with a human, credit you if you want the credit, and fix the issue. This is not a paid programme and we offer no monetary reward.
What happens when it breaks.
We have no incident history to publish. There is no archive of postmortems here because there is nothing yet to put in it, and we are not going to pad the page with drills and maintenance windows to make it look lived-in. Here is what we commit to when the first real one happens.
The honest version is shorter.
Most trust centers are designed to get a procurement checklist ticked. Ours is designed so that nothing on it can be contradicted by someone who checks.
We are not your vendor yet.
If your security review requires an attestation, wrxstack will fail it, and it should. Use a vendor that has one. We would rather lose the deal than manufacture a report.
Do not put it here.
We will not sign a BAA. Signing one without the safeguards behind it would transfer real legal liability to us and give you a false sense of protection.
This page changes first.
The day we complete an audit, the certificate and the auditor's name go here, and you will be able to ask them directly. Until that day, this table says no.
Frequently asked questions.
Where your data lives, who else touches it, and what happens when something goes wrong.
Where is my data hosted?
On Render, our application and site host, in a single region. Data lives on managed database and object storage with provider-level encryption at rest. We do not offer regional data residency selection, so ask us which region before you commit if that matters to you.
Who are your sub-processors?
Render for hosting, PostHog and Google Tag Manager for marketing-site analytics, and FormSubmit for contact-form delivery, plus the model provider for text you send to an AI feature. If a vendor is not on that list, it does not receive your data. We update this page before adding a new one, not after.
Is there an uptime SLA?
No. There is no published uptime SLA and no service-credit scheme. The application runs on managed hosting on a best-effort basis. The status page checks the site, Atlas, and Portfolio from your browser in real time, reporting what it observes rather than a headline number.
How do you handle incidents?
If your data is exposed, we email you directly rather than posting a status update you have to go looking for, and we do so within 72 hours of becoming aware, which is what GDPR Article 33 requires of us. The root cause and the fix are published in a public postmortem. We have no incident history to publish yet and will not pad the page to look lived-in.
How do I report a security vulnerability?
Email contact@wrxstack.com with the subject line Security and include the affected URL, the steps to reproduce, and what you were able to access. You get an acknowledgement from a human, not an autoresponder, and credit if you want it. Act in good faith, do not touch data that is not yours, and we will not pursue legal action.
Do you run a paid bug bounty?
No. This is responsible disclosure, not a paid programme, and we offer no monetary reward. Report the issue anyway. We read every report, respond with a human, and fix what needs fixing.
What certifications does wrxstack hold?
None. No SOC 2, no ISO 27001, no FedRAMP, no HIPAA BAA, and no independent penetration test. GDPR and CCPA are laws that apply to us regardless, and we describe our handling in the privacy policy. If a vendor page claims a certification for us, it is out of date.
Ask us anything.
We will answer plainly.
Security questions, data-handling questions, questions about what happens to your content. Email a human. If the answer is "we don't do that," that is what you will get.