Legal

Security

How Stocked protects the operational records you trust it with — the controls we run, and how to reach us about a vulnerability.

Last updated

Our approach

Stocked holds the operating record of a business: what it stocks, what it owes suppliers, what it sold and to whom. Losing it, or leaking it, is a serious event for the people who depend on it. We build accordingly.

This page describes the controls we actually run today. Where something is planned rather than in place, we say so rather than implying otherwise.

Protecting data

  • All traffic is served over TLS 1.3. HTTP requests are redirected, and HSTS is set.
  • Data at rest is encrypted with AES-256, including database volumes and backups.
  • Backups run continuously with point-in-time recovery over a 35-day window, and restores are tested quarterly.
  • Each business's records are scoped by tenant at the query layer, so one account cannot read another's rows.

Access control

Inside Stocked, you control who sees what through roles — owner, manager and staff — and through per-location scoping, so a shift lead sees their own site and not the rest of the estate.

Inside our own team, production access is granted on a least-privilege basis, requires hardware-backed multi-factor authentication, and is logged. Engineers do not hold standing access to customer data; access is requested for a specific task, granted for a limited window, and reviewed afterwards.

Infrastructure

We run on managed cloud infrastructure in EU and US regions, with providers that maintain ISO 27001 and SOC 2 Type II certification. Environments are isolated from one another, infrastructure is defined in code and peer-reviewed before it changes, and hosts are patched on a monthly cycle with critical fixes applied out of band.

How we build

  • Every change is peer-reviewed before it merges.
  • Automated tests, type checks and dependency scanning run on each commit.
  • Dependencies are monitored for known vulnerabilities and patched on a defined schedule by severity.
  • Secrets live in a managed secret store, never in source control.

Monitoring and response

We log application and infrastructure events centrally and alert on anomalies — unusual sign-in patterns, permission changes, spikes in failed requests. We maintain a written incident response plan with defined severities and owners, and we rehearse it.

If an incident affects your data, we will tell you without undue delay and in any case within 72 hours of confirming it, with what we know, what we have done, and what we recommend you do.

Compliance

Stocked is built to support your obligations under the GDPR and the Nigeria Data Protection Act. We sign data processing agreements on request, and we maintain a register of the subprocessors we use.

We are not currently SOC 2 certified. An audit is on our roadmap, and we would rather say that plainly than let a badge imply otherwise.

Reporting a vulnerability

If you believe you have found a security issue, email security@stocked.com. Tell us what you found and how to reproduce it. We acknowledge reports within one working day and aim to give you a remediation timeline within five.

We will not pursue legal action against researchers who act in good faith: report privately, give us reasonable time to fix the issue, avoid privacy violations and service degradation, and do not access more data than is needed to demonstrate the problem.

Questions about this document? Write to privacy@stocked.com or get in touch.