Security Policy
Last updated: February 2026
Our Security Commitment
At Greek-Fire Corporation, security is foundational to everything we build. ai.Stacker Pro is designed with a security-first mindset, ensuring that your data, configurations, and AI workflows are protected at every layer of our infrastructure.
We continuously invest in security practices, tooling, and training to maintain the highest standards of protection for our users. Our security program is built on the principles of defense in depth, least privilege, and continuous monitoring.
Data Encryption
We employ industry-leading encryption standards to protect your data both at rest and in transit.
Encryption at Rest
All data stored on our platform is encrypted using AES-256 encryption, the gold standard for symmetric encryption used by governments and financial institutions worldwide. This includes databases, file storage, backups, and logs.
Encryption in Transit
All data transmitted between your browser and our servers is protected using TLS 1.3, the latest version of the Transport Layer Security protocol. This ensures that your data cannot be intercepted, read, or tampered with during transmission. We enforce HTTPS across all endpoints and use HSTS headers to prevent protocol downgrade attacks.
Infrastructure Security
Our infrastructure is hosted on enterprise-grade cloud platforms with robust physical and network security controls. Key measures include:
- Isolated network environments with strict firewall rules and network segmentation
- Regular vulnerability scanning and penetration testing by independent third parties
- Automated patch management to ensure all systems are running the latest security updates
- DDoS protection and rate limiting to safeguard against volumetric attacks
- Immutable infrastructure deployments that reduce the attack surface and ensure consistency
- Real-time monitoring and alerting for suspicious activity across all system components
Access Controls
We implement strict access control measures to ensure that only authorized individuals can access your data and our systems.
Role-Based Access Control (RBAC)
Our platform implements granular role-based access control, allowing organizations to define precisely who can access what resources. Permissions are assigned based on roles, and each role follows the principle of least privilege, granting only the minimum access necessary to perform a given function.
Multi-Factor Authentication (MFA)
We strongly encourage all users to enable multi-factor authentication on their accounts. MFA adds an additional layer of security beyond your password by requiring a second form of verification. Our platform supports time-based one-time passwords (TOTP), hardware security keys, and authenticator applications.
- All internal access to production systems requires MFA and VPN connectivity
- Access reviews are conducted quarterly to revoke unnecessary permissions
- All privileged actions are logged and audited
- Session timeouts and automatic lockouts protect against unauthorized access
Data Protection
We take comprehensive measures to protect the integrity and confidentiality of your data throughout its lifecycle:
- Regular automated backups with encryption, stored in geographically separate locations
- Data isolation between tenants ensuring that your data is never accessible to other users
- Strict data retention policies with secure deletion procedures when data is no longer needed
- Input validation and output encoding to prevent injection attacks and cross-site scripting
- Regular security audits of our data handling processes and storage mechanisms
Incident Response
We maintain a comprehensive incident response plan to handle security events promptly and effectively. Our incident response process includes:
- Detection and Analysis: Continuous monitoring and automated alerting to identify potential security incidents in real time
- Containment: Immediate measures to limit the scope and impact of any confirmed incident
- Eradication and Recovery: Thorough removal of the threat and restoration of affected systems to normal operation
- Post-Incident Review: Detailed analysis of the incident to identify root causes and implement measures to prevent recurrence
- Notification: Timely communication to affected users and relevant authorities in accordance with applicable laws and regulations
Responsible Disclosure
We value the security research community and welcome responsible disclosure of any vulnerabilities discovered in our platform. If you believe you have found a security vulnerability, please report it to us promptly.
Please send vulnerability reports to security@greek-fire.com. Include a detailed description of the vulnerability, steps to reproduce it, and any supporting evidence.
We ask that you:
- Give us reasonable time to investigate and address the vulnerability before public disclosure
- Avoid accessing or modifying other users' data
- Act in good faith to avoid disruption to our services
- Do not exploit the vulnerability beyond what is necessary to demonstrate it
We commit to acknowledging your report within 48 hours and will work with you to understand and resolve the issue.
Compliance
We are committed to meeting and exceeding industry security standards and regulatory requirements. Our compliance efforts include:
- Adherence to SOC 2 Type II security principles and controls
- Compliance with GDPR requirements for data protection and privacy
- Implementation of OWASP security best practices across our application stack
- Regular third-party security assessments and audits
- Employee security awareness training conducted on a regular basis
Contact Us
If you have any questions about our security practices, want to report a security concern, or need more information, please contact our security team:
Greek-Fire Corporation — Security Team
Email: security@greek-fire.com
For urgent security matters, please include "URGENT" in your subject line to ensure prioritized handling.