Trust

Security starts by limiting what enters the system.

Northstar Stack limits the source set, separates customer contexts, reviews providers before use, and defines access and retention around the work each engagement requires.

Data scope

Each engagement defines the business question, source inventory, permitted use, and expected output before processing begins. Northstar Stack asks for the minimum evidence needed. Sensitive personal data is outside the standard diagnostic unless the agreement expressly permits it.

Access and separation

Access is limited to the people and providers required for the declared work. Customer sources and outputs remain within that customer's engagement context. Customer data is not used as public proof or transferred into another customer's work.

The public website and its forms are hosted by the provider listed on the Subprocessors page. Engagement-specific tools are disclosed before customer data is transferred to them.

Provider review

A provider is evaluated against the data it would receive, the purpose, access controls, retention options, and contract terms. A familiar brand name is not treated as proof that every configuration is suitable.

Retention and deletion

Retention is set by the purpose of the engagement, the signed agreement, legal duties, and the limits of the selected providers. Material is deleted or de-identified when it is no longer required, subject to those obligations. Northstar Stack does not publish a fixed retention period that does not apply to every source.

Incident handling

A suspected security issue is contained, the affected sources and providers are identified, and the available evidence is preserved. Affected customers are contacted according to the signed agreement and applicable law.

Security review

Customer security requirements are mapped to the engagement's source set, access model, providers, retention terms, and contractual responsibilities before data transfer. The Trust Center connects the supporting policies and review materials.

Security principles are informed by the FTC Start with Security guide, including data minimization, sensible access, provider review, and incident planning.

Request a security review

Name the company and the control, document, or data question that must be reviewed before an engagement.