Skip to content

Security architecture

Documented controls, without certification claims.

This page describes mechanisms in the launch implementation. StackShip does not claim a certification, regulatory attestation, audit report, or contractual service level today.

Available today

Identity boundaries

Organization authorization is checked at API boundaries. MCP tokens are audience-bound to the MCP resource and fail closed for a different audience.

Execution credentials

Provider credentials are encrypted and released only to the isolated execution attempt that needs them, for only as long as its plan or apply phase runs.

Bounded data paths

State, logs, and artifacts use bounded streaming paths so the Workers handling large objects do not buffer entire payloads in memory.

Availability

Evaluate StackShip without a purchase decision.

Anyone can create an account and an organization. StackShip currently has no billing, paid tiers, checkout, or published commercial SLA.