Identity boundaries
Organization authorization is checked at API boundaries. MCP tokens are audience-bound to the MCP resource and fail closed for a different audience.
Security architecture
This page describes mechanisms in the launch implementation. StackShip does not claim a certification, regulatory attestation, audit report, or contractual service level today.
Organization authorization is checked at API boundaries. MCP tokens are audience-bound to the MCP resource and fail closed for a different audience.
Provider credentials are encrypted and released only to the isolated execution attempt that needs them, for only as long as its plan or apply phase runs.
State, logs, and artifacts use bounded streaming paths so the Workers handling large objects do not buffer entire payloads in memory.
Availability
Anyone can create an account and an organization. StackShip currently has no billing, paid tiers, checkout, or published commercial SLA.