Stack Internal Support
Information security overview and FAQ for the Stack Internal platform.
Tags: InfoSec

Overview

Stack Internal uses sign-in controls, organization-specific access checks, and platform protections to safeguard customer information. Protected features check a signed access credential before returning data or accepting a change. Chat conversations and organization records are linked to the correct organization. The platform also uses certificates, traffic filtering, and request limits to protect services. Stack Internal records important product activity and checks the health of key features. When Chat uses OpenAI to prepare an answer, it sends the question and relevant context needed for that request.

FAQ

Security model

How does Stack Internal protect customer data?
Stack Internal requires sign-in before people or applications can use protected features. It checks the user's organization before returning organization-specific information. Chat conversations are linked to the signed-in user and organization, while organization-management actions require authenticated access. Platform controls also protect traffic reaching Stack Internal services. Together, these practices limit access to the information and product actions appropriate for each request.

What security standards guide the product?
Stack Internal uses established security technologies for sign-in, access control, and protected service connections. These include single sign-on (SSO), Open Authorization (OAuth) 2.1 for authorized access, and mutual Transport Layer Security (mTLS) for certificate-based service connections. The product also validates signed access credentials before protected features use them. These approaches are common building blocks for secure cloud applications.

How does Stack Internal handle vulnerabilities and operational risk?
Stack Internal uses platform traffic controls such as a web application firewall (WAF), rate limits, and rules that can block unwanted traffic. A WAF checks web requests against security rules. The product also includes health checks for key functions and records important activity for operational review. These controls help teams identify service problems and reduce the effect of unwanted or excessive traffic.

Privacy and data handling

What customer data does Stack Internal process?
Stack Internal uses the information needed for a particular product feature. This can include user identity details, organization settings, chat questions and answers, and approved knowledge content. Chat stores conversations so users can return to them. Organization management stores the information needed to manage an organization's account. Content functions prepare approved information for search and retrieval.

Does Stack Internal make our private data available to any other online services or external sites not directly related to the function of the product?
No. Stack Internal protects client data and shares it only with those services required to perform the functions of the site.

How does Stack Internal handle AI-related data flow?
Chat sends the question and relevant context to OpenAI when it uses OpenAI to prepare an answer. Stack Internal checks the user's access before it retrieves internal knowledge for that response. Chat stores the conversation so the user can return to it later, and it can show related references with the answer.

Does Stack Internal share private chats with other users by default?
No. Chat conversations are linked to the signed-in user and their organization. Stack Internal uses that relationship when deciding whether a conversation can be accessed. This keeps conversation access tied to the person and organization associated with the chat activity.

What methods does Stack Internal use to maintain strict isolation at the data, application, and network levels?
Stack Internal combines sign-in checks, organization-specific access decisions, and data controls that tie Chat records to the correct user and organization. At the platform level, traffic policies and service authorization controls protect communication between product services. Together, these practices limit access to the product information and functions appropriate for each request. Does Stack Internal use customer data to train AI models?

Sign-in and access

How do users authenticate?
Stack Internal uses WorkOS as its identity provider for browser sign-in and SSO. After a user signs in, Stack Internal exchanges the sign-in result for its own signed access credential. Product features use that credential to recognize the user, organization, and permissions when the user accesses protected information or actions.

How does Stack Internal enforce permissions?
Stack Internal uses the signed-in user's organization and permissions when making access decisions. The product includes this information in its signed access credential. Chat access is tied to the user and organization, while organization-management functions require authenticated access before they return information or accept a change.

How do services authenticate to each other?
Automated Stack Internal services can use cloud workload identity, which gives a service its own short-lived access credential instead of a permanent password or key. Azure can provide that credential for a specific service. The receiving service then uses it to decide whether the automated request is allowed.

Who has admin access of Stack Internal?
Control Center is designed for Stack Internal administrators, IT leads, support teams, and business stakeholders. Its protected functions use sign-in checks and organization-based access checks before showing onboarding information. Platform administration also uses cloud access controls, including Privileged Identity Management (PIM) for elevated Azure access.

Who has access to login details?
WorkOS handles user sign-in for Stack Internal. After a user signs in, Stack Internal exchanges the sign-in result for its own signed access credential. Internal product features use that credential to recognize the user, organization, and permissions, rather than relying on the original WorkOS sign-in credential.

How does Stack Internal support single sign-on?
Stack Internal supports single sign-on (SSO) through WorkOS. After a user signs in, the product issues a signed access credential for use inside Stack Internal. This gives product features a consistent way to recognize the user and their organization when they use protected functions.

How does Stack Internal verify access credentials?
Stack Internal checks that an access credential came from an approved issuer, is intended for the receiving product feature, has not expired, and has a valid signature. These are common checks for protecting application programming interfaces (APIs), which let product features communicate with each other.

How does Stack Internal protect service credentials?
Stack Internal's platform includes secret stores and secret-sync tools for service credentials. It also uses workload identity for some automated service calls. This reduces the need to place long-lived credentials directly in application settings or source code.

Customer separation

How is our data isolated from other customers? What safeguards are in place?
Stack Internal links Chat conversations to the signed-in user and organization. It checks organization information before returning organization-specific data or accepting a change. Organization records also use unique identifiers. These access checks and data controls help keep one customer's product activity separate from another customer's product experience.

Encryption and stored data

What encryption does Stack Internal use for data sent to the cloud?
Stack Internal's platform configuration includes certificate issuers and mTLS support. mTLS uses certificates to protect a connection and verify the service at each end. These controls are used alongside other platform protections for traffic reaching Stack Internal services.

How is client data encrypted?
Stack Internal uses certificate-based controls to protect service connections. Its identity functions can encrypt data-protection keys with certificate material. These controls protect the security information that product features use to establish trusted access and maintain secure sessions.

Auditing

What sort of auditing does Stack Internal offer?
Stack Internal records important product activity for operational use. Chat records submitted questions, and organization management records key changes such as creation, updates, activation, and deactivation. Identity functions also create records about sign-in and signed access credential issuance. Platform change history can provide additional operational traceability.

Additional security questions

How does Stack Internal check that important features are available?
Stack Internal includes health checks for key product functions, including Chat and organization management. These checks verify that the product can reach the information it needs to operate. They help the team identify when a core feature needs attention before it affects normal product use.

How does Stack Internal handle approved content?
Stack Internal accepts approved content so it can prepare that information for search and retrieval. Protected content functions require authenticated access before content is added. The product then creates searchable knowledge records that its features can use when they need to find relevant information.

https://doc-automation.netlify.app/pdfs/docs/internal/for_admins/information_security/infosec_security_overview.pdf

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article