Legal
Noir Stack LLC
A Virginia Limited Liability Company
Effective Date: January 1, 2024
Last Updated: January 1, 2026
This Security Policy describes the administrative, technical, and physical safeguards implemented by Noir Stack LLC ("Company," "Noir Stack," "we," or "us") to protect systems, infrastructure, and data processed through our platforms, APIs, AI systems, and related services (collectively, the "Services").
This Policy applies to all environments operated or controlled by the Company, including multi-tenant SaaS platforms, APIs, and enterprise deployments.
The Company maintains a security program designed to protect the confidentiality, integrity, and availability of systems and data.
Security practices are aligned with industry-recognized frameworks, including:
Security controls are reviewed periodically and updated based on risk assessments, threat intelligence, and operational changes.
Security is a shared responsibility between the Company and the Customer.
The Company is responsible for:
The Customer is responsible for:
The Company implements controls designed to secure infrastructure, including:
Cloud and hosting providers are selected based on security posture and contractual safeguards.
The Company employs encryption practices consistent with industry standards:
No method of transmission or storage is guaranteed to be fully secure.
Access to systems and data is restricted using:
Access is granted based on business need and revoked when no longer required.
The Services operate in logically segregated environments designed to:
Customers are responsible for managing access within their own tenant environments.
The Company applies security controls to application and API layers, including:
APIs may be modified, rate-limited, or restricted to maintain system integrity.
The Company maintains logging and monitoring capabilities designed to:
Logs may include system events, authentication attempts, and API activity.
The Company implements processes to identify and address vulnerabilities, including:
Security updates and patches are applied based on severity and operational risk.
The Company maintains an incident response process designed to:
In the event of a confirmed breach involving personal data, notifications will be made in accordance with applicable law, including requirements under the Virginia Consumer Data Protection Act and related Virginia statutes.
Data is processed only as necessary to provide the Services.
The Company:
The Company maintains internal practices designed to reduce risk, including:
The Company may engage third-party providers for hosting, analytics, authentication, or infrastructure.
Such providers are selected based on:
The Company is not responsible for the independent security practices of third-party services outside its control.
The Company maintains practices intended to support continuity of Services, including:
No guarantee of uninterrupted availability is provided unless specified in a separate agreement.
For AI-enabled systems:
Customers are responsible for validating outputs and ensuring appropriate use.
Security practices are designed to align with:
Where the Company acts as a processor, data handling is governed by applicable agreements, including Data Processing Addenda.
While the Company implements commercially reasonable safeguards, no system can eliminate all security risk.
The Company does not warrant that:
Use of the Services is subject to the limitations described in the Terms and Conditions.
The Company may update this Security Policy periodically to reflect changes in technology, threats, or legal requirements.
Updates will be reflected by revising the "Last Updated" date.
Security inquiries, including vulnerability reports, may be directed to:
Noir Stack LLC · Commonwealth of Virginia
npm i @hexarch/guardrailsgo get hexarch.io/guardrails