Security at Stedra
Stedra maps who controls your most critical accounts, so it's fair to ask how we control ours. This page is the plain-language version of how the product is built; if your firm needs more detail for due diligence, ask — hello@stedra.io.
The design decision that matters most
Stedra never stores your passwords or credentials for other services. The product records ownership metadata — who holds an account, who's the backup, where recovery paths point — never the logins themselves. There is no credential vault to breach, because there is no credential vault.
What the scan does — and doesn't — touch
- Discovery reads public data only: domain registration records (RDAP), DNS answers, and your public homepage. It never authenticates to anything, and it can't see inside any account.
- Everything else in your register comes from you: interview answers and fields you fill in.
Access control
- Every request is scoped to your firm and client at the data layer — role-based access with three roles (owner, consultant, client), each limited to what that role needs.
- Client portal users see only their own business, under your firm's branding.
- Stedra passwords are stored as salted scrypt hashes. Sessions are server-side and revocable; disabled users are locked out immediately.
Data handling
- Transactional email goes through a dedicated provider; every send is logged to an outbox you can audit in settings.
- Analytics are first-party, cookieless counts — no third-party trackers anywhere on the site or app.
- You can export your data (CSV/PDF) anytime; deletion requests are honored per the Privacy Policy.
During the beta
We're a young product and we'd rather earn trust than claim it: we don't yet hold formal certifications (e.g. SOC 2), and we say so. What we can offer today: the no-credentials design, the scoped access model above, export-anytime, and direct access to the team building it.
Reporting a vulnerability
If you find a security issue, email hello@stedra.io with the details. We'll acknowledge promptly, keep you informed, and won't pursue anyone acting in good faith to report a problem.