Stelloid
ProblemSolutionProductWho it’s forTeamData & trustFAQ
Try the demoBook a walkthrough
Security

Security at Stelloid

This page describes a recommended minimum security posture. Stelloid publishes only confirmed controls.

← WebsitePrivacyTermsData DeletionSecuritySubprocessorsIntegrationsSupport

Our approach

Stelloid processes commercially sensitive information from commerce, advertising and analytics platforms. We use administrative, technical and organizational safeguards designed to reduce unauthorized access, disclosure, alteration and loss. Security is a shared responsibility between Stelloid, customers and connected-platform providers.

Data minimization

  • We request the minimum practical access for the enabled feature.
  • We prefer read-only access for dashboards and recommendations.
  • We seek to exclude customer names, addresses, phone numbers, email addresses and payment credentials from core analytics where they are not needed.
  • We limit retention according to the authorized purpose, customer instructions, platform requirements and law.

Access and authentication

  • Access to production information is restricted to authorized personnel with a business need.
  • Permissions are reviewed and removed when no longer required.
  • Integration credentials and tokens are not displayed to customers or shared between customer workspaces.
  • Multi-factor authentication is used for administrative systems where supported.

Encryption and infrastructure

Connections to Stelloid use HTTPS/TLS. Customer Data and integration secrets are protected using the security features of our hosting, database and secrets-management providers. This website is hosted on Vercel in the United States (Washington, D.C.), with business email on Google Workspace. Website contact-form messages are sent through Resend.

No production customer database or platform connector is in operation yet. Before any customer data store, connector or AI provider begins processing Customer Data, it will be added to the Subprocessor Register and this page will be updated with the relevant provider and region.

Application and operational security

  • We use change review, dependency management and environment separation appropriate to the development stage of the product.
  • We log relevant authentication, integration and administrative events for security and troubleshooting.
  • We maintain backup, recovery and incident-handling processes appropriate to the Services.
  • We assess material service providers before allowing them to process Customer Data and bind them to confidentiality and data-protection obligations.

Incident response

If Stelloid confirms a security incident affecting Customer Data, we will investigate, contain and remediate it and notify affected customers as required by applicable law and contract. Notices will include available information about the nature of the incident and reasonable protective steps.

Customer responsibilities

  • Use unique credentials and multi-factor authentication where available.
  • Invite only authorized users and review their access regularly.
  • Do not send passwords, one-time passwords or unnecessary personal information to Stelloid.
  • Promptly disconnect former employees and report suspicious activity.

Report a security concern

Send a detailed report to contact@stelloid.io. Do not publicly disclose a suspected vulnerability before Stelloid has had a reasonable opportunity to investigate and address it.

Stelloid does not claim ISO 27001, SOC 2, PCI DSS or another certification unless that certification is expressly stated on this page and can be independently verified.

Stelloid

AI decision intelligence for modern commerce.

Explore

ProblemSolutionProductWho it’s forTeam

Legal

PrivacyTermsData DeletionSecuritySubprocessorsIntegrationsSupport

Contact

contact@stelloid.io+91 74399 56187
© 2026 Stelloid AI. All rights reserved.