Security & Compliance

Institutional-grade security from authentication to audit logging. Built for firms that answer to LPs and regulators.

The Problem

PE firms handle sensitive financial data and investor PII. A data breach or compliance failure can end a fund manager's career.

The Solution

Stak is built with security at every layer. 2FA, encrypted storage, RBAC, audit logging, rate limiting, and GDPR readiness — all enabled by default, not as add-ons.

Key Capabilities

  • 2FA/TOTP for every account
  • 256-bit AES encryption at rest and in transit
  • Role-based access control with 8 permissions
  • Full audit logging with user, timestamp, and action
  • Rate limiting on API and login endpoints
  • Content Security Policy (CSP) and HSTS
  • GDPR and nFADP compliance tools
  • Enterprise Security Program (SOC 2 Type II — In Progress)

Data Collections

Audit LogsSecurity SettingsAccess TokensSessions

See Security Features

See how security works with real data in our interactive demo.