Security and data processing

A public summary for security questionnaires. It is not a certification.

Data processing

When you use Stationed for your staff or contractors, Stationed processes personal data on your instructions as a processor. You are the controller. We process it only to provide Stationed: authentication, challenges, events, workflows, alerts, and support. We do not sell it or use it for advertising.

A signed data processing agreement is available on request at hello@stationed.tech. This page is the description of processing until that agreement is signed.

Location

Production application data is hosted in the European Union. We do not collect GPS from phones.

Subprocessors

  • Application and database hostingRuns the Stationed application and PostgreSQL.
  • ResendSends transactional email (organisation setup, invites, password reset, order confirmation, and operational alerts) when configured.
  • StripeTakes plan and hardware payments, including billing and shipping details entered at checkout.

Controls in the product

  • Passwords hashed with bcrypt. Session tokens stored hashed, in HTTP-only cookies.
  • CSRF checks on cookie-authenticated writes. Organisation isolation on every resource.
  • Role-based permissions. Invites so administrators do not set other people's passwords.
  • Challenge tokens are high-entropy, stored hashed, single-use, and expired by the server clock.
  • Devices authenticate with ECDSA P-256. Private keys stay on the board.
  • Events have no edit or delete API. Administrative actions are written to an audit log.
  • Webhooks can be HMAC-signed. Deliveries are retried and logged.
  • Machine access uses scoped API tokens instead of a shared password.

What this is not

We are not claiming SOC 2, ISO 27001, or Cyber Essentials on this page. Events are application records, not a timestamp authority. Contact hello@stationed.tech (Weekdays 09:00–17:00 UK) for a questionnaire or a DPA.

Stationed · hello@stationed.tech