TRUST CENTER · WHAT WE CAN PROVE

What we can prove.
And what we cannot.

wrxstack is a small, independent product. We hold no security certifications. Rather than imply otherwise with badges, this page states exactly where we stand, what we actually do with your data, and who else touches it.

contact@wrxstack.com How we handle dataPrivacy policyReport a vulnerability
01 / Where we stand

No badges we have
not earned.

Security certifications are audits, not adjectives. Each one below requires an accredited third party, a defined observation window, and a real fee. We have not been through any of them. If a vendor page tells you otherwise about us, it is out of date.

FrameworkWhat it requiresOur status
SOC 2 Type I / IIAttestation by a licensed CPA firm over an observation windowNot held. No audit has been performed.
ISO/IEC 27001Certification by an accredited certification bodyNot held. No ISMS has been certified.
ISO/IEC 27017, 27018Extensions to a certified ISO 27001 ISMSNot held.
FedRAMPFederal agency sponsor and a 3PAO assessmentNot held. No sponsor, no assessment, not in process.
HIPAA / HITECHA signed BAA and the safeguards of 45 CFR 160 and 164We do not offer a BAA. Do not put PHI in wrxstack.
PCI DSSQSA assessment or a completed self-assessment questionnaireNot applicable. Payments, if any, are handled by a third-party processor. We never see card data.
CSA STAR, HITRUSTRegistry submission or validated assessmentNot held. Not submitted.
Independent penetration testAn engagement with a security firmNone performed. We have never commissioned one.
GDPR / UK GDPRA legal obligation, not a certificate anyone issuesWe are subject to it and describe our handling in the privacy policy.
CCPA / CPRAA legal obligation, not a certificate anyone issuesWe do not sell or share personal information. See the CCPA statement.

GDPR and CCPA sit apart from the rest of this table on purpose. They are laws that apply to us whether or not we do anything about them, and no body issues a certificate for either. Every other row is a badge that must be granted by someone else, and nobody has granted us one.

02 / What is true

The short, verifiable list.

Everything here is something you can check yourself, or something we are contractually bound to by the providers underneath us. There is nothing on this list that depends on you taking our word for it.

TLS
Verifiable

Encrypted in transit

TLS 1.3, HSTS

Every request to wrxstack.com, atlas.wrxstack.com, and portfolio.wrxstack.com is served over TLS. HTTP is redirected, not accepted. You can confirm this from your browser's address bar or with any SSL checker.

Check it yourselfSSL Labs, curl -I
AES
256
Provider default

Encrypted at rest

Managed database and object storage

Application data is stored on managed infrastructure with volume-level encryption at rest enabled by the provider. This is inherited from our host, not something we implemented, and we will not claim more than that.

Inherited fromHosting provider
NO
TRAIN
Contractual

Your content does not train models

AI features

We do not train any model on your content, and we do not permit our model providers to. This is enforced by the provider's API terms on the tier we use, not by a promise we make on our own behalf.

Enforced byProvider API terms

Things we deliberately do not claim: customer-managed encryption keys, regional data residency, single-tenant deployment, on-premise or air-gapped installation, a 24/7 on-call rotation, a formal vulnerability management SLA, background checks, or a disaster-recovery drill cadence. None of those exist here today.

03 / Sub-processors

Everyone who touches it.

The complete list of third parties involved in running wrxstack. If a vendor is not on this list, it does not receive your data. We update this page before adding a new one, not after.

VendorPurposeWhat it receives
RenderApplication and site hostingAll application data, at rest and in transit
PostHogProduct analytics on the marketing sitePage views, coarse device and country data
Google Tag ManagerAnalytics tag loadingPage load events
FormSubmitContact form deliveryWhatever you type into the contact form
Full sub-processor detail
04 / Reporting a vulnerability

Tell us, and we will fix it.

We read every report, respond with a human, credit you if you want the credit, and fix the issue. This is not a paid programme and we offer no monetary reward.

How to report
Email contact@wrxstack.com with the subject line Security. Include the affected URL, the steps to reproduce, and what you were able to access. Encrypted mail is welcome; ask and we will exchange keys.
What we commit to
An acknowledgement from a human, not an autoresponder. We will tell you whether we consider it a vulnerability and roughly when we expect to have it fixed. If we disagree with your assessment we will say why, rather than going quiet.
What we ask
Do not access, modify, or exfiltrate data that is not yours. Do not run automated scanners against production. Give us a reasonable window before publishing. We will not pursue legal action against anyone acting in good faith under these terms.
Read the full policy contact@wrxstack.com
05 / Incidents

What happens when it breaks.

We have no incident history to publish. There is no archive of postmortems here because there is nothing yet to put in it, and we are not going to pad the page with drills and maintenance windows to make it look lived-in. Here is what we commit to when the first real one happens.

Notification
If your data is exposed, we will email you directly. Not a status page update you have to go looking for. We will tell you what was accessed, when, and by whom if we know.
Timeline
Within 72 hours of becoming aware, which is what GDPR Article 33 requires of us regardless. We would rather send an incomplete notice inside 72 hours than a complete one after.
Postmortem
Published publicly, with the root cause and the fix. Not a paragraph about how seriously we take security.
Live status
The status page checks the site, Atlas, and Portfolio from your browser in real time. It reports what it observes right now. It does not store history and it does not estimate.
How we handle your data Incident response
06 / Why this page reads like this

The honest version is shorter.

Most trust centers are designed to get a procurement checklist ticked. Ours is designed so that nothing on it can be contradicted by someone who checks.

If you need SOC 2

We are not your vendor yet.

If your security review requires an attestation, wrxstack will fail it, and it should. Use a vendor that has one. We would rather lose the deal than manufacture a report.

If you handle PHI

Do not put it here.

We will not sign a BAA. Signing one without the safeguards behind it would transfer real legal liability to us and give you a false sense of protection.

If this changes

This page changes first.

The day we complete an audit, the certificate and the auditor's name go here, and you will be able to ask them directly. Until that day, this table says no.

07 / Questions

Frequently asked questions.

Where your data lives, who else touches it, and what happens when something goes wrong.

Where is my data hosted?

On Render, our application and site host, in a single region. Data lives on managed database and object storage with provider-level encryption at rest. We do not offer regional data residency selection, so ask us which region before you commit if that matters to you.

Who are your sub-processors?

Render for hosting, PostHog and Google Tag Manager for marketing-site analytics, and FormSubmit for contact-form delivery, plus the model provider for text you send to an AI feature. If a vendor is not on that list, it does not receive your data. We update this page before adding a new one, not after.

Is there an uptime SLA?

No. There is no published uptime SLA and no service-credit scheme. The application runs on managed hosting on a best-effort basis. The status page checks the site, Atlas, and Portfolio from your browser in real time, reporting what it observes rather than a headline number.

How do you handle incidents?

If your data is exposed, we email you directly rather than posting a status update you have to go looking for, and we do so within 72 hours of becoming aware, which is what GDPR Article 33 requires of us. The root cause and the fix are published in a public postmortem. We have no incident history to publish yet and will not pad the page to look lived-in.

How do I report a security vulnerability?

Email contact@wrxstack.com with the subject line Security and include the affected URL, the steps to reproduce, and what you were able to access. You get an acknowledgement from a human, not an autoresponder, and credit if you want it. Act in good faith, do not touch data that is not yours, and we will not pursue legal action.

Do you run a paid bug bounty?

No. This is responsible disclosure, not a paid programme, and we offer no monetary reward. Report the issue anyway. We read every report, respond with a human, and fix what needs fixing.

What certifications does wrxstack hold?

None. No SOC 2, no ISO 27001, no FedRAMP, no HIPAA BAA, and no independent penetration test. GDPR and CCPA are laws that apply to us regardless, and we describe our handling in the privacy policy. If a vendor page claims a certification for us, it is out of date.

Trust Center

Ask us anything.
We will answer plainly.

Security questions, data-handling questions, questions about what happens to your content. Email a human. If the answer is "we don't do that," that is what you will get.

contact@wrxstack.com How we handle dataReport a vulnerabilityNo certifications claimed · no reports to request