Security report

Security & Compliance Report

A plain-language summary of the controls WipStack has in place today, intended to support SOC 2, ISO/IEC 27001, and contractor due-diligence reviews.

This document is maintained by WipStack. It is a self-assessment, not an independent audit, penetration test, certification, or warranty.
Report owner
WipStack, a MimesisIQ LLC company
Last updated
August 20, 2026
Current status
Self-assessed beta controls

Scope & intent

What this report covers

This report describes security, privacy, and operational controls implemented in the WipStack application and the managed services it currently uses. It addresses common vendor-review topics, including logical access, confidentiality, availability, change management, incident handling, service providers, data export, and erasure.

WipStack is not currently SOC 2 or ISO/IEC 27001 certified. Framework references below are a point-in-time, self-assessed mapping of implemented controls. They do not represent an auditor’s opinion, a formal statement of applicability, or certification.

Current evidence snapshot

Release gate run on August 20, 2026

This snapshot records the verification performed for the current production release. It is not a promise that software can be free of every vulnerability.

  • The dependency audit reported zero known vulnerabilities in production dependencies at the time of review.
  • The complete lint, type-check, automated test, and optimized production build suite passed.
  • The protected-branch security workflow stores a commit-bound evidence bundle containing test, dependency-audit, source and secret scan, authorization, and evidence-manifest results for 90 days.
  • Forced row-level security and restricted database roles were verified across all 22 tenant tables, and adversarial tests showed one synthetic tenant could not read, write, move, or delete another tenant’s project, file, connected-AI work-session, client-grant, or tool-audit metadata.
  • Dynamic MCP authorization tests covered every registered tool: read-only clients were denied by every write tool, existing full-access clients passed unchanged, and every declared free-text field rejected the reviewed credential shapes before a handler could write.
  • A point-in-time scan of 33 existing project cards found no stored values matching the enforced credential patterns. Identifier-only references such as environment-variable names were not treated as credential values.
  • Clerk organization fixtures exercised administrator and member roles in an isolated development instance, and Stripe test-mode billing reconciled seat quantity from one to two and back to one without a live charge. Production team workspaces and team billing remain disabled behind separate release flags.
  • Signed-out production checks confirmed that private application, project, administrator, and scheduled-task routes reject unauthenticated requests.
  • Signed-in production checks covered the main application views, global and archived search, browser-console errors, security headers, request-size rejection, and fresh runtime log levels.
  • Repository and version-history scans found no credential patterns matching the reviewed secret formats.

Controls in place

Implemented application and operational controls

01

Access control and administration

Clerk provides managed authentication. Every protected WipStack page and API request resolves the signed-in Clerk user on the server. The current public beta remains individual-only. Clerk organization workspaces and seat billing are implemented behind separate server-side release flags and are not presented as active until their production acceptance gate is complete. Administrative routes require a separate server-side email allowlist, and sensitive administrator actions create audit records.

02

Tenant isolation and authorization

Private records are keyed to the authenticated personal or organization workspace. WipStack uses restricted application and background-job database roles and forced PostgreSQL row-level security across 22 tenant tables and the per-user AI usage table. Tenant claims come from verified Clerk sessions and are applied only within the same database transaction as each query. Project and file routes also re-check ownership at the application layer.

03

Encryption and secret handling

Traffic is served over HTTPS. Neon requires encrypted database connections and provides encryption at rest. Vercel provides encryption in transit and at rest for its platform and Blob storage. WipStack additionally encrypts connected OpenAI, Anthropic, and Slack credentials with AES-256-GCM before database storage. Saved credentials are used only in server-side requests and are never returned to the browser after saving. Project, evidence, artifact, intake, review, file-context, and MCP-session writes are checked for common secret and high-entropy credential shapes and rejected before storage with an instruction to remove the secret.

04

Files, capture, and integration boundaries

Project documents use private Vercel Blob storage and are delivered through authenticated WipStack functions. Uploads use file-type and size allowlists, tenant-bound paths, storage quotas, and bounded document extraction. Supported readable files deliberately sent to a private WipStack email address are extracted into the confirmed project context; secret-shaped extracted content is rejected, and unsupported files remain stored without being represented as readable context. MCP access is enforced centrally for every tool using the OAuth client identity verified by Clerk. New clients begin read-only; account holders can explicitly grant or remove write access, while clients connected before this control was introduced retain their prior access. Each MCP call records the verified client ID, tool, project when applicable, required access, outcome, and time without storing the prompt, token, argument content, or detected credential. MCP work-session records contain project/provider activity metadata and timestamps, not full ChatGPT or Claude transcripts. Inbound email requires a verified account sender. Stripe, Clerk, Resend, and Slack webhooks are signature-verified, and Slack requests also have a five-minute replay window.

05

Logging and change management

Application changes are versioned in Git and built through Vercel deployments. The release process runs linting, type checks, automated tests, a production build, deployment checks, and live browser or API verification in proportion to the change. Runtime failures, scheduled health results, backup outcomes, processed billing events, and selected security-relevant administrator actions are recorded for investigation.

06

Availability, recovery, and incident handling

Automated health checks run every 15 minutes against the application, database, authentication, billing, AI connection, MCP discovery, and backup configuration. WipStack creates a private application backup each day, verifies the latest backup manifest monthly, and retains backup objects for up to 35 days. Scheduled access and incident reviews create control evidence. A manifest check is not represented as a full disaster-recovery exercise.

Data handling & retention

Customer control over project data

Account holders can download a structured export from Account. Permanent account deletion cancels an active subscription, removes tenant-scoped application records, deletes stored project files and covers, removes applicable newsletter and open contact records, and deletes the Clerk user account. Deleted data may remain temporarily in managed-provider backups, security records, or legally required records until those systems’ retention periods expire.

WipStack does not sell personal information or share it for cross-context behavioral advertising. A supported readable attachment deliberately sent to the account holder’s private WipStack email address can become project context automatically after the project is confirmed. Project context is sent to an AI provider only as part of a requested AI-assisted action such as email capture or reconciliation. Daily private WipStack application backups are retained for up to 35 days; operational and provider retention can differ as described in the applicable provider terms and the Privacy Policy.

Hosting & service providers

Services that may process WipStack data

Actual provider involvement depends on the features an account chooses. A provider’s audit or certification applies to that provider’s service and does not certify WipStack.

ProviderPurposeWhen used
VercelApplication hosting, edge delivery, runtime logs, deployment pipeline, and private object storageCore service
NeonManaged PostgreSQL databaseCore service
ClerkManaged account authentication and session handlingCore service
StripeCheckout, subscriptions, invoicing, and payment processing; WipStack does not receive full card numbersWhen billing is used
ResendTransactional email, calendar invitations, newsletters, and explicitly forwarded inbound emailWhen email features are used
OpenAIRequested AI-assisted imports, reconciliation, capture, or report enhancementOnly when selected or provided for an AI feature
AnthropicRequested AI-assisted imports, reconciliation, capture, or report enhancementOnly when selected or provided for an AI feature
SlackA selected message or thread sent through an authorized Slack connectionOnly when connected and explicitly used
GitHubApplication source control and change history; customer project content is not intentionally stored in the code repositoryOperational service

Framework alignment

Self-assessed mapping, not certification

SOC 2 Trust Services Criteria

Current controls most directly support logical access and authorization (CC6), system operations and monitoring (CC7), change management (CC8), availability (A1), and confidentiality (C1). WipStack has not undergone a SOC 2 examination.

ISO/IEC 27001:2022 Annex A

Application evidence most directly maps to A.5 Organizational controls and A.8 Technological controls. People controls (A.6) and physical controls (A.7) are not asserted here beyond the published controls of managed providers. WipStack has not completed an ISO/IEC 27001 certification audit or formal statement of applicability.

Contractor due diligence

The report addresses authentication, tenant isolation, encryption, private files, service providers, incident contact, monitoring, backups, data portability, deletion, and shared responsibility.

Shared responsibility

What account holders control

  • Protect sign-in methods, review active sessions, and enable additional authentication protection when available.
  • Connect only services and API credentials the account holder is authorized to use, and revoke connections that are no longer needed.
  • Send, upload, or approve only data the account holder has the right to process, including files deliberately forwarded to the private WipStack address.
  • Review recipient-restricted report links and revoke them when access is no longer required.
  • Report suspected security issues promptly to hello@wipstack.ai.

Requesting more detail

Need a vendor-review response?

Enterprise prospects, agencies, and contractors can request available security details, a current service-provider list, or discuss a security questionnaire or data-processing agreement by emailing hello@wipstack.ai.

Privacy PolicyService StatusTerms of Service
This report reflects current practice and is updated as controls evolve. It is informational and does not constitute an independent certification, legal advice, or a contractual warranty.