How we protect your data and maintain compliance.
Security is foundational to everything we build at STLabs. Our platform handles sensitive IT operations data, and we treat the protection of that data as a core product requirement — not an afterthought. We apply defense-in-depth principles across our infrastructure, application layer, and operational processes.
STLabs runs on cloud infrastructure provided by leading providers with SOC 2, ISO 27001, and FedRAMP certifications. Our infrastructure practices include:
As an AI-powered platform, we apply additional safeguards to our model layer:
STLabs is pursuing SOC 2 Type II certification. Our compliance program includes formal policies for information security, acceptable use, incident response, business continuity, and vendor management. We are committed to meeting the regulatory requirements of the industries we serve.
We maintain a documented incident response plan that covers detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed security incident affecting customer data, we will notify impacted customers within 72 hours, consistent with applicable regulations.
All third-party vendors and subprocessors with access to customer data undergo security review before onboarding. We evaluate their security posture, data handling practices, and compliance certifications. Vendor reviews are repeated annually.
If you have questions about our security practices or want to report a vulnerability, please contact us at security@stlabs.com.