Zero-Retention Architecture

Security & Trust Center

At StitchLink (operated by Project Kaz LLC), we believe your calendar data belongs to you. We built our infrastructure around a strict Zero-Retention Architecture. Here is how we protect your privacy by design.

Zero-Retention Scheduling

StitchLink is designed with "Architectural Blindness." We do not store your calendar event details in our database. Your sensitive meeting titles, descriptions, and attendee lists are processed ephemerally and discarded immediately.

How We Handle Your Data

1

Fetch

We request your calendar's free/busy data using encrypted OAuth tokens. We ask for the absolute minimum permissions required to find availability.

2

Process

Event data is processed in memory only on our secure servers strictly to calculate scheduling overlap.

3

Forget

The moment your availability is calculated, the calendar data is permanently discarded from memory. Nothing is stored, logged, or cached in our databases. Zero retention.

AES-256
Encryption at Rest
TLS 1.3
Encryption in Transit
100%
Enterprise-Grade Infrastructure
AA
WCAG 2.1 Accessible
0
Calendar Events Stored

Encryption Standards

🔐 AES-256 Encryption

All sensitive data including OAuth tokens and API keys are encrypted at rest using AES-256 encryption — the same standard used by banks and government agencies.

🔒 TLS 1.3 in Transit

All data transmitted between your browser and our servers uses TLS 1.3 encryption, providing forward secrecy and protection against eavesdropping.

🗄️ Encrypted Database

Our PostgreSQL database uses encrypted storage volumes. Database backups are also encrypted with separate keys.

🔑 Secure Key Management

Encryption keys are managed via environment variables and never stored in code. Keys are rotated regularly and access is strictly controlled.

Infrastructure Security

Hosting ProviderVercel (SOC 2 Type II certified)
DatabaseSupabase (SOC 2 Type II, HIPAA eligible)
PaymentsStripe (PCI DSS Level 1 certified)
EmailResend (SOC 2 Type II compliant)
CDN/EdgeCloudflare (ISO 27001, SOC 2)
AnalyticsPostHog (SOC 2 Type II, consent-gated)
Error MonitoringSentry (SOC 2 Type II certified)
Spam PreventionhCaptcha (ISO 27001 certified)
Rate LimitingUpstash (SOC 2 Type II certified)

Access Controls

  • Row-Level Security (RLS): Every database table has RLS policies ensuring users can only access their own data.
  • OAuth 2.0 Authentication: We use industry-standard OAuth flows via Google and Microsoft. We never see or store your passwords.
  • RBAC for Admins: Administrative access is role-based with Super Admin and Support tiers. All admin actions are logged in an immutable audit trail.
  • API Key Scoping: API keys are hashed before storage and scoped to specific permissions.

Enterprise SSO — Available Now

LIVE

SAML 2.0 single sign-on is available for Enterprise customers. Enforce SSO across your organization with Okta, Azure AD, Google Workspace, OneLogin, or any SAML 2.0 provider. Set it up in Organization Settings → SSO.

Security Headers

Every response from StitchLink includes hardened security headers:

Content-Security-Policy: default-src 'self'; ...
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

Vulnerability Disclosure

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly through our formal program:

Report a Vulnerability

Email security@stitchlink.ai with a description of the issue, steps to reproduce, and potential impact. We respond within 48 hours.

Use secure contact form →

Responsible Disclosure Policy

Our full disclosure program includes scope, safe harbor protections, severity-based remediation targets, and researcher recognition.

View security.txt →

Incident Response & Breach Notification

StitchLink maintains a documented incident response procedure and GDPR-compliant breach notification plan:

< 72h
Authority notification per GDPR Art. 33
< 1h
Critical incident containment target
P1–P3
Severity-tiered response playbooks

Our zero-retention architecture significantly reduces breach impact — an attacker accessing our database would find no calendar event titles, descriptions, or attendee lists. Only hashed passwords-and emails are stored.

Compliance & Infrastructure

  • GDPR & CCPA Ready: Built to support data portability, right to deletion, and California consumer privacy rights.
  • Certified Infrastructure: While Project Kaz LLC is a growing startup, every vendor in our infrastructure stack (including Vercel, Supabase, and Stripe) maintains independent SOC 2 Type II certifications to ensure your data is handled in world-class, secure environments.

Note on HIPAA

StitchLink is not HIPAA compliant. Do not use StitchLink to schedule meetings involving Protected Health Information (PHI).

Need enterprise-grade security?

Enterprise plans include SSO, priority support, guided onboarding, and 99.5% uptime target.

See Enterprise Plans