Operational transparency
Trust should be reviewable.
This page consolidates the controls and operating practices that are documented for StackPatrol today. Where a safeguard is optional, deployment-dependent or not currently claimed, we say so.
Last reviewed 22 August 2026
Current deployment snapshot
- Primary infrastructure
- Hetzner Cloud, Finland
- Authentication
- Email magic links, JWT sessions
- Application database
- Not exposed to the internet
- Site analytics
- No third-party analytics or ad pixels
Infrastructure and encryption
The current production application and database run on Hetzner Cloud infrastructure in Finland. StackPatrol is deployed in Docker behind a Caddy reverse proxy, and public traffic is encrypted in transit using HTTPS/TLS with automatically managed certificates. The application database is not exposed directly to the internet.
Authentication and access
Customer authentication uses email magic links through Auth.js. StackPatrol stores no customer passwords. Signed-in sessions use JWTs and one strictly necessary session cookie. Administrative access requires an eligible account plus a separate signed admin-mode cookie with an eight-hour lifetime.
The service is operated by Skaarberg Digital in Norway. Administrative and infrastructure access is limited to authorised personnel.
Data storage and retention
Retention depends on why the data exists. The periods below consolidate the current Privacy Policy and DPA rather than creating a separate policy.
| Data | Period | Scope |
|---|---|---|
| Anonymous scan reports | 90 days | Stored against a random report ID, not an account. |
| Raw infrastructure logs | At most 7 days | Raw IP addresses may appear transiently. Application scan logs store a hash. |
| Account data and scan history | While active | Associated data is deleted within 30 days after account deletion. |
| Account-linked product events | 180 days | Used to understand product workflows and service performance. |
| Contact correspondence | Up to 12 months | Measured from the last correspondence unless the relationship remains active. |
| Payment records | 5 years | Retained for accounting and tax obligations. Card numbers are not stored by StackPatrol. |
Service providers
The core service uses a small provider set. Contractual safeguards and fuller transfer details are maintained in the Privacy Policy and DPA.
| Provider | Purpose | Processing location |
|---|---|---|
| Hetzner Online GmbH | Application hosting and storage | Finland, EU |
| Resend Inc. | Transactional email | EU send region; some US account data and logs under SCCs |
| Stripe Inc. | Payments and billing | US under DPF and SCCs |
AI use
AI is not required for the baseline vendor inventory, report rendering, monitoring schedule or alert comparison. Two bounded OpenAI-assisted functions can be enabled: a fallback that classifies candidate consent controls when deterministic detection fails, and an admin-only draft suggestion for unmatched vendor records.
For consent-control classification, StackPatrol sends bounded element metadata such as labels, HTML tags, classes, IDs and ARIA labels. It does not intentionally send the scanned URL, cookies or page content. Common email, phone, URL and long-identifier patterns are redacted first, but unexpected text in third-party HTML means this filtering reduces rather than eliminates incidental personal-data risk.
Incident handling
StackPatrol's DPA commits to notify a Controller without undue delay, and in any event within 72 hours after becoming aware of a personal-data breach affecting that Controller's data. Data-rights requests are answered within 30 days. General DPA enquiries have a stated response target of five business days.
Vulnerability reporting
Report a suspected vulnerability to Andreas@stackpatrol.eu with the subject Security Report. Include the affected URL or feature, reproduction steps and the potential impact. Do not include secrets or personal data that are not needed to explain the issue.
Reports are handled directly by the operator. StackPatrol does not currently run a public bug-bounty programme.