Security & Trust Center
At StitchLink (operated by Project Kaz LLC), we believe your calendar data belongs to you. We built our infrastructure around a strict Zero-Retention Architecture. Here is how we protect your privacy by design.
Zero-Retention Scheduling
StitchLink is designed with "Architectural Blindness." We do not store your calendar event details in our database. Your sensitive meeting titles, descriptions, and attendee lists are processed ephemerally and discarded immediately.
How We Handle Your Data
Fetch
We request your calendar's free/busy data using encrypted OAuth tokens. We ask for the absolute minimum permissions required to find availability.
Process
Event data is processed in memory only on our secure servers strictly to calculate scheduling overlap.
Forget
The moment your availability is calculated, the calendar data is permanently discarded from memory. Nothing is stored, logged, or cached in our databases. Zero retention.
Encryption Standards
🔐 AES-256 Encryption
All sensitive data including OAuth tokens and API keys are encrypted at rest using AES-256 encryption — the same standard used by banks and government agencies.
🔒 TLS 1.3 in Transit
All data transmitted between your browser and our servers uses TLS 1.3 encryption, providing forward secrecy and protection against eavesdropping.
🗄️ Encrypted Database
Our PostgreSQL database uses encrypted storage volumes. Database backups are also encrypted with separate keys.
🔑 Secure Key Management
Encryption keys are managed via environment variables and never stored in code. Keys are rotated regularly and access is strictly controlled.
Infrastructure Security
| Hosting Provider | Vercel (SOC 2 Type II certified) |
| Database | Supabase (SOC 2 Type II, HIPAA eligible) |
| Payments | Stripe (PCI DSS Level 1 certified) |
| Resend (SOC 2 Type II compliant) | |
| CDN/Edge | Cloudflare (ISO 27001, SOC 2) |
| Analytics | PostHog (SOC 2 Type II, consent-gated) |
| Error Monitoring | Sentry (SOC 2 Type II certified) |
| Spam Prevention | hCaptcha (ISO 27001 certified) |
| Rate Limiting | Upstash (SOC 2 Type II certified) |
Access Controls
- Row-Level Security (RLS): Every database table has RLS policies ensuring users can only access their own data.
- OAuth 2.0 Authentication: We use industry-standard OAuth flows via Google and Microsoft. We never see or store your passwords.
- RBAC for Admins: Administrative access is role-based with Super Admin and Support tiers. All admin actions are logged in an immutable audit trail.
- API Key Scoping: API keys are hashed before storage and scoped to specific permissions.
Enterprise SSO — Available Now
LIVESAML 2.0 single sign-on is available for Enterprise customers. Enforce SSO across your organization with Okta, Azure AD, Google Workspace, OneLogin, or any SAML 2.0 provider. Set it up in Organization Settings → SSO.
Security Headers
Every response from StitchLink includes hardened security headers:
Vulnerability Disclosure
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly through our formal program:
Report a Vulnerability
Email security@stitchlink.ai with a description of the issue, steps to reproduce, and potential impact. We respond within 48 hours.
Use secure contact form →Responsible Disclosure Policy
Our full disclosure program includes scope, safe harbor protections, severity-based remediation targets, and researcher recognition.
View security.txt →Incident Response & Breach Notification
StitchLink maintains a documented incident response procedure and GDPR-compliant breach notification plan:
Our zero-retention architecture significantly reduces breach impact — an attacker accessing our database would find no calendar event titles, descriptions, or attendee lists. Only hashed passwords-and emails are stored.
Compliance & Infrastructure
- GDPR & CCPA Ready: Built to support data portability, right to deletion, and California consumer privacy rights.
- Certified Infrastructure: While Project Kaz LLC is a growing startup, every vendor in our infrastructure stack (including Vercel, Supabase, and Stripe) maintains independent SOC 2 Type II certifications to ensure your data is handled in world-class, secure environments.
Note on HIPAA
StitchLink is not HIPAA compliant. Do not use StitchLink to schedule meetings involving Protected Health Information (PHI).
Need enterprise-grade security?
Enterprise plans include SSO, priority support, guided onboarding, and 99.5% uptime target.
Last updated: March 2026