How PrivateStack handles your data
Everything a security review needs on one page: our compliance status, how data is handled on each tier, the subprocessors we use, where requests actually flow, and the controls in the product today. No portal, no gating.
Last reviewed: 2026-07-15
Compliance status
SOC 2 Type II: certification in progress
We operate a SOC 2-aligned control environment and a SOC 2 Type II examination is in progress. We do not claim attestations we have not yet earned, and we will update this page as our status changes. Current controls documentation is available under NDA: contact us.
HIPAA-ready architecture
Encryption, access control, audit logging, and isolation consistent with the technical safeguards expected of systems that handle protected health information. Teams working with PHI should talk to us about an Enterprise BYOC deployment, where inference runs inside the cloud account you control.
How your data is handled
Data handling differs by tier, so we describe each one separately rather than blending the claims.
Hosted
- Inference is processed by a disclosed US-based inference subprocessor, contractually bound to zero retention: prompts are processed in memory, never stored, and never used for training. Subprocessor identities are provided in our DPA and under NDA.
- PrivateStack retains audit logs per your configured retention policy. You decide how long governance records are kept.
- We do not use your prompts, responses, or knowledge-base content to train models.
Enterprise BYOC
- Inference runs inside your own AWS account. Prompts, outputs, and workspace content never leave your VPC.
- Audit logs, knowledge bases, and governance records stay inside the cloud account you control, subject to your own retention and access policies.
- DSE engineers deploy and operate the stack with your security team, including architecture review and data-flow walkthroughs.
Subprocessors
The vendors that process customer data on our behalf, listed by role and terms. Subprocessor identities are provided in our DPA and under NDA. Enterprise BYOC deployments keep inference out of this list entirely: it runs in your own cloud account.
| Subprocessor role | Purpose | Region | Data handling |
|---|---|---|---|
| Inference provider (US, contractual zero-retention) | Model inference (hosted tier) | United States | Zero retention: prompts processed in memory, never stored, never used for training. |
| Cloud infrastructure provider (US) | Cloud hosting and infrastructure | United States | Tenant data encrypted in transit and at rest. |
| Authentication provider | Authentication and identity | United States | Account identity data only. No workspace content. |
| Payments processor | Billing and payments | United States | Payment and billing data only. No workspace content. |
Subprocessor names are available under NDA or in your executed DPA. Request via security@privatestackhub.com.
Where your data goes
The two request paths, side by side. Each step below is the literal flow. There are no hidden hops.
- Your userSends a prompt from the workspace UI
- PrivateStack workspacePolicy checks run; the audit log entry is written and stays here, retained per your configured policy
- Inference subprocessor (zero-retention)Prompt processed in memory, response returned. Never stored, never used for training
- Your userSends a prompt from the workspace UI
- PrivateStack workspace in your VPCDeployed inside your own AWS account. Policy checks, audit logs, and inference all run here
- Everything stays insidePrompts, outputs, logs, and knowledge bases never leave the cloud account you control
Security controls, answered directly
The questions buyers ask in every security review, answered here so your review starts from facts instead of a blank questionnaire.
- Is data encrypted in transit?
- Yes. TLS on every connection between users, the workspace, and inference.
- Is data encrypted at rest?
- Yes. Tenant data stores and backups are encrypted at rest.
- Do you support SSO?
- Not yet self-serve. Okta, Google, and Azure AD SSO is on our roadmap — Enterprise customers can talk to us about early access.
- Is there role-based access control?
- Yes. Workspace roles separate administrators, members, and auditors.
- How are tenants isolated?
- Per-tenant data stores and scoped credentials; no shared workspace content.
- Is every AI request logged?
- Yes — every request is recorded in your usage and access logs (who, when, which model). Prompt and response content itself is never retained in our control plane: a real data-minimization advantage under CCPA and GDPR, not a gap in logging.
- Can we export audit logs?
- Yes. Audit history is exportable by tenant administrators.
- Can we hand auditors evidence?
- Yes. Evidence Pack produces a one-click, date-ranged compliance evidence bundle from your audit history.
- Who controls log retention?
- You do. Retention windows are set per tenant by your administrators.
- Can sensitive content be redacted?
- Yes. Redaction controls let administrators remove sensitive material from records.
- Is our data used to train models?
- No, never. Our inference subprocessor is contractually barred from it too.
- Does the inference provider store prompts?
- No. Our inference subprocessor processes prompts in memory with contractual zero retention.
- Who are your subprocessors?
- Listed by role on this page: inference, cloud infrastructure, authentication, and payments. Names are provided in our DPA and under NDA.
- Can inference stay inside our cloud?
- Yes. Enterprise BYOC runs the workspace and inference inside your own AWS account.
- Who owns the company?
- PrivateStack is built by Data Science & Engineering Experts, Inc., a US-owned company based in Atlanta, GA.
Downloads
The documents reviewers ask for, downloadable directly. No form, no gate.
Want to go deeper?
Walk through our architecture and controls with the engineers who run the platform, or send your security questionnaire directly.