Stacklink holds access to your users' accounts. Here is precisely how that access is stored, scoped, used and revoked — and how to reach us if you find a problem.
Stacklink holds access tokens for your users' accounts, so this is the part we treat most carefully.
Your API keys identify a project and are shown once at creation. If one leaks, rotate it in the dashboard — the old key stops working immediately.
Every request carries a project key or an MCP OAuth token, and resolves to a specific end user's grant before anything runs. A call can only reach the tools you enabled for that project and the accounts that user actually connected. Reads run; writes can be held for a human approval and, once approved, run exactly once — the approval and the run are both recorded.
Every tool call is logged with its arguments, result status, timing, the acting user and the approval that released it. Reading those logs is free and never touches your meter — an audit should not cost extra. Retention follows your plan: 30 days on Free through 365 on Enterprise.
For regulated work, memory records support legal holds, which block erasure while an investigation is open.
Access to production is limited to the engineers who need it, authenticated through SSO with multi-factor authentication, and granted on a least-privilege basis. Administrative actions are logged. We do not read customer data in the course of normal operations; where debugging genuinely requires it, it is done on the narrowest possible scope with the customer's knowledge.
We can support your review with a security questionnaire, architecture detail, a data-processing agreement and a subprocessor list. Write to support@stacklink.in and tell us what your process needs.
If you find something, tell us at support@stacklink.in — please include enough detail to reproduce it. We aim to acknowledge within two business days and to keep you posted until it is closed.
We ask that you give us a reasonable window to fix an issue before publishing it, that you do not access or modify data that is not yours, and that you avoid degrading the service for other users while testing. Report in good faith under those conditions and we will not pursue legal action.
If a breach affects your data, we will tell you — what happened, what was affected, what we did, and what you should do — without waiting for the story to look tidy, and within the timelines data-protection law requires of us.
Plug in once — MCP or SDK — and every product on this page is already in the run.
30-day trial · no card · first tool call before your coffee cools