Security and data processing
A public summary for security questionnaires. It is not a certification.
Data processing
When you use Stationed for your staff or contractors, Stationed processes personal data on your instructions as a processor. You are the controller. We process it only to provide Stationed: authentication, challenges, events, workflows, alerts, and support. We do not sell it or use it for advertising.
A signed data processing agreement is available on request at hello@stationed.tech. This page is the description of processing until that agreement is signed.
Location
Production application data is hosted in the European Union. We do not collect GPS from phones.
Subprocessors
- Application and database hosting — Runs the Stationed application and PostgreSQL.
- Resend — Sends transactional email (organisation setup, invites, password reset, order confirmation, and operational alerts) when configured.
- Stripe — Takes plan and hardware payments, including billing and shipping details entered at checkout.
Controls in the product
- Passwords hashed with bcrypt. Session tokens stored hashed, in HTTP-only cookies.
- CSRF checks on cookie-authenticated writes. Organisation isolation on every resource.
- Role-based permissions. Invites so administrators do not set other people's passwords.
- Challenge tokens are high-entropy, stored hashed, single-use, and expired by the server clock.
- Devices authenticate with ECDSA P-256. Private keys stay on the board.
- Events have no edit or delete API. Administrative actions are written to an audit log.
- Webhooks can be HMAC-signed. Deliveries are retried and logged.
- Machine access uses scoped API tokens instead of a shared password.
What this is not
We are not claiming SOC 2, ISO 27001, or Cyber Essentials on this page. Events are application records, not a timestamp authority. Contact hello@stationed.tech (Weekdays 09:00–17:00 UK) for a questionnaire or a DPA.
Stationed · hello@stationed.tech