Data Sovereignty & Privacy Physics
StackEngine operates on a Local-First architecture. The primary directive of our platform is to enable security engineers and DevOps specialists to audit candidate infrastructure configurations without risking raw credential exfiltration.
[PHYSICS SPECIFICATION]: CORE PRIVACY GUARANTEES
- • Client-Side Tokenization: AirLock (v1.0.0) redacts high-entropy credentials in your browser's volatile memory before any payload is dispatched.
- • Sterile Transit: Only anonymized, structurally-neutral diagnostic data is transmitted to LLM APIs.
- • Zero Persistence: We do not maintain databases of your proprietary YAML/HCL configs.
- • Note on Compliance: StackEngine is designed to facilitate your internal compliance in your own environment. You remain entirely responsible for maintaining your organizational audit logs.
Information We Collect & Data Handling
StackEngine is an independent developer utility matrix. To maintain our zero-trust baseline while improving the product, we enforce strict data segregation:
[DATA HANDLING SPECIFICATION]
- • Zero Data Retention (ZDR): StackEngine servers do not persist your raw infrastructure manifests or output refactorings.
- • Diagnostic Telemetry: We use PostHog for minimal, first-party functional telemetry (e.g., engine execution latency, tool usage frequency). This pipeline physically operates on a separate layer from our AirLock engine and cannot intercept local YAML/HCL payloads.
- • B2B Waitlist Information: When you voluntarily submit your work email for Enterprise CLI access, this PII is strictly segregated from the parsing engine. It is used exclusively for commercial outreach. Under GDPR/CCPA principles, you may request the immediate deletion of your contact data by emailing us.
Local Tokenization & LLM Sub-processors
When initiating an AI Audit via our web utilities, your payload is processed by our local AirLock Engine.
• In Free Tier (Edge Relay):
Sterile payloads are routed through our edge relay to Anthropic/OpenAI enterprise endpoints. We enforce ZDR on our edge. You acknowledge that sterile payloads transmitted are governed by the respective API data privacy policies of these providers.
• In BYOK Mode:
Your browser establishes a direct connection to your chosen LLM provider. StackEngine servers process 0 bytes of this transaction.
Local Storage & Cookies
StackEngine uses browser localStorage strictly for functional client state (e.g., storing your BYOK API key locally on your device, theme preferences). We deploy zero cross-site marketing cookies.
Third-Party Integrations
Our static assets are hosted via edge CDNs (such as Cloudflare Pages) to deliver sub-50ms TTFB worldwide. Edge network providers process standard TCP/IP request headers (IP address, TLS cipher suite) strictly for DDoS mitigation and routing.
User Rights & Data Custody
Because we do not store personal configuration payloads or user accounts for free web utilities, your data custody remains entirely within your local domain: clearing your browser cache wipes all local scratchpad code and ephemeral state.
Enterprise Compliance & Facilitation
For enterprise organizations requiring formal air-gapped guarantees, StackEngine offers commercial CLI binaries and private VPC deployments designed to facilitate your internal compliance (SOC2, ISO 27001, and HIPAA) in your own environment. StackEngine provides software tools to support your compliance workflows; each customer remains solely responsible for establishing, monitoring, and maintaining its own regulatory certifications and audit trails.
Privacy Inquiries & Data Deletion
StackEngine operates as a lean, independent project focused on local-first security. For all inquiries regarding our AirLock architecture, or to exercise your data deletion rights for waitlist emails, please contact the lead maintainer at: [email protected].