Your agents run in your cloud. Your model keys stay yours.
That is the design, not a setting. Most agent platforms ask you to hand over your data and your model access so they can run things for you. Stackbone works the other way round: we give you the control plane, and execution happens inside infrastructure you already own and already audit.
Last updated · August 15, 2026
Where things run
Your runtime, your cloud
Agent runtimes deploy into your own AWS, Azure or GCP account. The data your agents process never leaves your perimeter. It does not transit Stackbone, and we cannot read it.
Your model keys
Stackbone is model-agnostic. You bring your own provider keys, whether that is OpenAI, Anthropic, OpenRouter, an open-weights model you host yourself, or anything speaking an OpenAI-compatible API. We never proxy model traffic through Stackbone accounts. Prompts and completions are not visible to us.
Air-gappable by design
Because execution is separated from control, Stackbone can be deployed in environments with no outbound internet access. This matters for defence, banking, healthcare and public sector work. Talk to us if that is your situation.
What Stackbone does hold
We are specific about this so you can scope your review properly. Our control plane holds account and organisation data, agent definitions and versions, deployment configuration, and execution metadata: what ran, when, by whom, how long it took, whether it failed. It does not hold the payloads your agents process.
Platform security
- Encryption in transit. TLS 1.2 or higher on every connection.
- Encryption at rest. All stored data and backups are encrypted.
- Secrets. Credentials and keys are encrypted and scoped to the deployment that needs them. They are write-only from the interface: you can replace a secret, you cannot read it back.
- Isolation. Every deployable ships as a container. Tenants are isolated at the infrastructure level.
- Authentication. Product access uses passwordless email links, so there are no passwords to leak. SSO and SAML are available for enterprise plans.
- Authorisation. Role-based access control across organisations, projects and environments, so people only reach what their role allows.
How we operate
- Least privilege. Internal access is granted by role, reviewed periodically, and removed on the day someone leaves.
- Identity. Google Workspace is our identity provider, with mandatory two-factor authentication on every account.
- Change management. All code lives in a single repository. Every change goes through peer review and an automated pipeline before it can reach production.
- Dependencies. Automated scanning for vulnerable dependencies, with patching prioritised by severity.
- Monitoring. Infrastructure and application logs are centralised and retained, with alerting on anomalies.
- Backups. Control plane databases are backed up continuously with point-in-time recovery, and restores are tested.
Audit and governance
Regulated buyers do not just need agents that work. They need to prove what the agents did.
Stackbone records an immutable execution trail: which version of which agent ran, on whose authority, against which configuration, with what outcome. Versions are tracked, rollbacks are one action, and every deployment is attributable to a person.
Compliance
We are in a SOC 2 Type II programme, with ISO 27001 to follow. We operate under GDPR as a data processor for our customers.
If you are running a vendor security review and need our current status, our subprocessor list, our DPA or a completed questionnaire, write to [email protected] and we will send what we have.
Incident response
We have a documented process for detecting, containing and communicating security incidents. If an incident affects your data, we will notify you without undue delay and within the timeframes our agreements and the GDPR require.
If an incident is affecting you and you have not heard from us, write to [email protected] and say what you are seeing.
Reporting a vulnerability
If you have found a security issue, we want to hear about it. Our Vulnerability Disclosure Policy explains how to report it and what you can expect from us.
Contact
Running a vendor security review?
Most of what a questionnaire asks is answered on this page already. Send us the questions it does not cover and we will answer those in writing.