Security

Tokens are the crown jewels. We treat them that way.

Stacklink holds access to your users' accounts. Here is precisely how that access is stored, scoped, used and revoked — and how to reach us if you find a problem.

UPDATED 26 AUG 2026REPORT TO support@stacklink.inACK WITHIN 2 BUSINESS DAYS
AES-256-GCM at restTokens encrypted before write, never returned by any API.
Per-user grantsNo shared bot identity; the agent acts as the person who signed in.
Writes ask firstHeld for approval, then run exactly once — both recorded.
Free audit trailEvery call, argument and approval recorded — reading logs never meters.

01Credentials

Stacklink holds access tokens for your users' accounts, so this is the part we treat most carefully.

  • Tokens are encrypted with AES-256-GCM before they are written, and decrypted only in memory to serve a call.
  • They are never returned by any API, never rendered in the dashboard, and never written to logs.
  • On the hosted connect page, credentials are submitted by POST — never placed in a URL, where they would end up in browser history and server logs.
  • Grants are per end user. There is no shared bot identity holding everyone's access.
  • Revocation is immediate, from your side or the provider's.

Your API keys identify a project and are shown once at creation. If one leaks, rotate it in the dashboard — the old key stops working immediately.

02How a call is authorised

Every request carries a project key or an MCP OAuth token, and resolves to a specific end user's grant before anything runs. A call can only reach the tools you enabled for that project and the accounts that user actually connected. Reads run; writes can be held for a human approval and, once approved, run exactly once — the approval and the run are both recorded.

03Encryption and isolation

  • In transit: TLS on every connection — API, dashboard, MCP endpoint and webhook deliveries.
  • At rest: managed database and object storage with encryption enabled; sensitive fields additionally encrypted at the application layer.
  • Sandboxes: Workbench runs are isolated per run on Cloudflare's runtime. A sandbox gets what the run needs and is torn down after.
  • Webhooks: deliveries are signed so you can verify they came from us, with retries on failure.

04The record

Every tool call is logged with its arguments, result status, timing, the acting user and the approval that released it. Reading those logs is free and never touches your meter — an audit should not cost extra. Retention follows your plan: 30 days on Free through 365 on Enterprise.

For regulated work, memory records support legal holds, which block erasure while an investigation is open.

05Access on our side

Access to production is limited to the engineers who need it, authenticated through SSO with multi-factor authentication, and granted on a least-privilege basis. Administrative actions are logged. We do not read customer data in the course of normal operations; where debugging genuinely requires it, it is done on the narrowest possible scope with the customer's knowledge.

06Enterprise diligence

We can support your review with a security questionnaire, architecture detail, a data-processing agreement and a subprocessor list. Write to support@stacklink.in and tell us what your process needs.

Book a call

07Reporting a vulnerability

If you find something, tell us at support@stacklink.in — please include enough detail to reproduce it. We aim to acknowledge within two business days and to keep you posted until it is closed.

We ask that you give us a reasonable window to fix an issue before publishing it, that you do not access or modify data that is not yours, and that you avoid degrading the service for other users while testing. Report in good faith under those conditions and we will not pursue legal action.

08Incidents

If a breach affects your data, we will tell you — what happened, what was affected, what we did, and what you should do — without waiting for the story to look tidy, and within the timelines data-protection law requires of us.

Pick a playbook. Keep the guardrails.

Plug in once — MCP or SDK — and every product on this page is already in the run.

30-day trial · no card · first tool call before your coffee cools