Every system we build and every process we run is designed with security as the primary constraint, not an afterthought.
Client data is encrypted at rest and in transit, processed only for the purpose it was collected for, and scoped per project on a least-privilege basis — engineers only see what their work requires. Data is retained for the life of the engagement plus any period required by law, then deleted on request. We never sell client data, share it with third parties for marketing, or use it to train external models.
Stack46 signs NDAs by default on all client engagements. You don't need to ask — a mutual non-disclosure agreement is part of our standard onboarding, before any scoping conversation, code, or credentials are shared.
Data handling practices built around UK GDPR principles across every engagement — access scoping, retention limits, and deletion on request.
Independently assessed and certified under the UK Government-backed Cyber Essentials scheme, verifying baseline cyber security controls across our systems.
Registered as a data controller with the UK Information Commissioner's Office — reference ZC052022.
Covered by employers' liability insurance with AXA, meeting UK statutory minimum cover.
Cyber liability cover in place, arranged via IASME and Sutcliffe & Co Insurance Brokers.
Stack46 is a member of the Federation of Small Businesses.
Found a vulnerability? We operate a responsible disclosure programme covering stack46.com and any production system we operate directly — third-party services, social engineering, and physical security testing are out of scope. Report genuine, good-faith findings to hello@stack46.com; we commit to acknowledging reports within 24 hours and won't pursue legal action for good-faith testing within this scope. If a client's data is affected by a confirmed breach, we aim to notify them within 24 hours.
Report a Vulnerability