Security & Compliance
A public, evidence-linked overview of TheirStack security and privacy practices, customer-data scope, and infrastructure-provider attestations.
This page is the starting point for security questionnaires and vendor reviews of TheirStack. It summarizes public evidence about the controls we operate and links to the source for each statement.
Attestation status: TheirStack has not completed a SOC 2 audit and is not ISO 27001 certified. We do not claim that TheirStack is SOC 2 compliant, SOC 2 attested, or ISO 27001 certified. Certifications and audit reports held by our infrastructure providers apply to the systems and controls within those providers' scope; they are not certifications or attestations of TheirStack.
This overview is not an independent audit report or certification. Our Data Processing Addendum (DPA) contains our contractual data-processing and security commitments.
Customer-data scope
TheirStack primarily provides access to job-posting, company, and technographic datasets. Most records describe companies, jobs, and technologies rather than customers or individual people. Our GDPR overview explains the narrow categories of personal data that can appear in the datasets and the safeguards applied to that data.
We also process the information needed to operate customer accounts and deliver the service. The Privacy Policy describes account, billing, device, and usage information, while Annex A of the DPA defines Customer Data and the processing covered by that agreement.
TheirStack practices and public evidence
The links in this table are the public evidence for each statement. Contractual controls are identified as such; product behavior is linked to the relevant product documentation.
| Area | Current practice | Public evidence |
|---|---|---|
| Encryption | The DPA commits TheirStack to TLS 1.2 or higher for data in transit and encryption at rest for databases and storage systems. | DPA, Annex B |
| Access control | The DPA states that role-based access control, least privilege, access reviews, account deprovisioning, and encrypted administrative communications are used. | DPA, Annex B |
| API authentication | API requests use Bearer-token API keys. Customers can set key expiry, see a newly created key only once, and revoke a key immediately. | API authentication |
| Secret and key management | The DPA states that secure key management and regular key rotation are used. Customer API-key controls support expiry and immediate revocation. | DPA, Annex B and API authentication |
| Monitoring | The DPA states that security monitoring and alerting are continuous. Our subprocessor list identifies Cloudflare for web monitoring, WAF, denial-of-service protection, and CDN services, and Grafana Labs for monitoring and observability. | DPA, Annex B and Subprocessors |
| Backups and resilience | The DPA states that regular backups are performed and that infrastructure monitoring detects failure conditions. | DPA, Annex B |
| Secure development | The DPA states that changes require code review and that the development lifecycle includes security testing, vulnerability assessment, and automated CI/CD security scanning. | DPA, Annex B |
| Privacy and data minimization | We collect public job and company data without logging in or bypassing access controls, exclude personal contact data from the dataset, and limit personal-data processing as described in our GDPR safeguards. | Data Collection & Legal Compliance and GDPR |
| Incident commitments | The DPA requires notification without undue delay after TheirStack becomes aware of a Personal Data Breach affecting data processed for a customer, followed by known details and updates. | DPA, section 3.8 |
| Account deletion and retention | Customers can delete their account from the product. The deletion page and Privacy Policy explain deletion timing, legal-retention exceptions, and residual encrypted backups. | Account Deletion & Data Removal and Privacy Policy |
Infrastructure-provider attestations
Our Subprocessors page identifies the vendors involved in delivering the service and their purposes. The providers below publish independent compliance information for their own platforms:
| Provider | Role listed by TheirStack | Provider-published evidence | Scope boundary |
|---|---|---|---|
| Render | Infrastructure and primary hosting | Render states that its platform has a SOC 2 Type II attestation and ISO 27001 certification in its compliance documentation. | Render-controlled platform infrastructure and operations only |
| Vercel | Infrastructure and primary hosting | Vercel states that it has a SOC 2 Type II attestation and ISO 27001:2022 certification in its security and compliance documentation. | Vercel-controlled platform infrastructure and operations only |
| Cloudflare | Web monitoring, WAF, denial-of-service protection, and CDN | Cloudflare publishes its SOC 2 Type II and ISO 27001 posture in its Trust Hub. | Cloudflare-controlled network and services only |
| ClickHouse | Database | ClickHouse lists SOC 2 Type II and ISO 27001 in its Trust Center. | ClickHouse-controlled cloud services only |
Provider attestations support the infrastructure layer of our security model. They do not audit TheirStack's application code, employee access, development process, or company-wide controls. Render describes this division explicitly in its shared responsibility model: each customer remains responsible for the applications and configurations it operates on the platform.
Privacy and legal documents
- GDPR — lawful basis, data scope, minimization, retention, and individual rights
- Data Processing Addendum — contractual processing, security, incident, audit, and deletion commitments
- Subprocessors — current providers, purposes, and processing locations
- Privacy Policy — account and service information, use, disclosure, retention, and security
- Data Collection & Legal Compliance — collection methods, public-source boundaries, and opt-out
- API authentication — API-key creation, expiry, storage, and revocation
- Account Deletion & Data Removal — account deletion and residual-backup handling
For a customer-specific security questionnaire or a question not answered by these public documents, contact hi@theirstack.com.
How is this guide?
Last updated on
TheirStack Brand Kit
Download TheirStack's official logos, wordmark, icon, brand colors, and product screenshots. Use these assets when referring to TheirStack in articles, integrations, partner pages, or press coverage.
GDPR
How TheirStack complies with the GDPR — our lawful basis for processing personal data, what personal data our dataset actually contains, why we consider the balance justified, and the safeguards we apply.
