Security at SteadStack
Your farm data is critical to your livelihood. We treat its protection with the seriousness it deserves.
Data Encryption
All data is encrypted at rest using AES-256 encryption via Google Cloud Platform. Data in transit is protected with TLS 1.2+ encryption. Database connections, API calls, and file transfers are all encrypted end-to-end.
Authentication & Access Control
SteadStack uses Firebase Authentication with bcrypt password hashing, OAuth 2.0 token management, and automatic token rotation. Role-based access control (owner, admin, manager, worker) ensures users only see what they need to.
Multi-Tenant Isolation
Every record includes a tenant identifier. Firestore security rules enforce strict tenant isolation at the database level. There is no API endpoint or query mechanism that allows access to another tenant's data. Each request is validated against the authenticated user's tenant.
Infrastructure
SteadStack runs on Google Cloud Platform, which maintains SOC 1/2/3, ISO 27001, and PCI DSS certifications. Our application is deployed via Firebase Hosting and Cloud Functions with automatic scaling, redundancy, and DDoS protection provided by Google's global infrastructure.
Backups & Recovery
Firestore provides automatic, continuous backups with point-in-time recovery. We maintain daily snapshots with 30-day retention. In the event of data loss, we can restore your tenant's data to any point within the retention window.
Payment Security
All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We never store credit card numbers, CVVs, or other sensitive payment data on our servers. Stripe handles tokenization, encryption, and secure transmission of payment information.
Incident Response
Detection & Notification
We monitor our systems 24/7 for security anomalies. In the event of a data breach that affects your information, we will notify affected users within 72 hours via email, as required by applicable law.
Containment & Recovery
Our incident response process includes immediate containment, root cause analysis, remediation, and post-incident review. We maintain runbooks for common security scenarios and conduct regular tabletop exercises with the engineering team.
Transparency
We believe in being open about security incidents. If a breach occurs, we will communicate clearly about what happened, what data was affected, what we're doing about it, and what steps you should take.
Responsible Disclosure
If you discover a security vulnerability in SteadStack, we ask that you report it responsibly. Please email us at sales@bartdev.org with a description of the issue. We will acknowledge your report within 48 hours and work with you to understand and resolve the vulnerability.
We ask that you:
- Give us reasonable time to fix the issue before public disclosure
- Do not access or modify other users' data
- Do not degrade the service or disrupt other users
- Provide sufficient detail for us to reproduce the issue
Questions about security?
We're happy to answer questions about how we protect your data. Reach out anytime.