Is this your company?Buyers are checking Staq here. Claim staq.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.
At Staq we take risk and compliance very seriously. Security and trust is of utmost importance to us, our partners and our customers. This page provides real-time, transparent and simple information regarding Staq's compliance and security standards. For more information you can contact the Staq team using the email address provided below.
SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Subprocessors
List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Staq SOC 2 compliant?
Staq is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Staq GDPR compliant?
According to Staq's public trust center, Staq is GDPR compliant. On SOC2C this listing is Listed.
Is Staq ISO 27001 certified?
According to Staq's public trust center, Staq is ISO 27001 certified. On SOC2C this listing is Listed.
Is Staq PCI DSS compliant?
According to Staq's public trust center, Staq is PCI DSS compliant. On SOC2C this listing is Listed.
Is Staq ISO 27017 certified?
According to Staq's public trust center, Staq is ISO 27017 certified. On SOC2C this listing is Listed.
Is Staq ISO 27018 certified?
According to Staq's public trust center, Staq is ISO 27018 certified. On SOC2C this listing is Listed.
Is Staq SOC 2 Type I or Type II?
Staq is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Staq's SOC 2 for a vendor risk assessment?
Yes. Staq's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Staq penetration tested?
Staq hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Staq secure?
Security isn't a single yes/no, but Staq is SOC 2 Type II compliant and holds GDPR, ISO 27001, PCI DSS, SOC 2 Type II, ISO 27017, ISO 27018. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Staq have a bug bounty or vulnerability disclosure program?
Staq hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@staq.io or via a /security page (Staq lists a security contact).
Who are Staq's subprocessors?
Staq's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Staq host or store data?
Staq's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Staq's trust center or security page?
Staq's trust center is at https://trust.staq.io. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Where are your servers located?
Our platform can be deployed in a location of your choosing, be that cloud (eg AWS) or on-premise. Our dev environment is currently located on cloud with AWS with data residency options across the world.
How do you manage end-user data privacy?
Our banking and business partners are the data controllers of end-user data. Staq operates as a data processor on a limited basis. Staq's platform is compliant with data privacy laws such as GDPR, enabling our partners to manage end-user data in a compliant manner. Where required by local laws, Staq signs a Data Processing Agreement (DPA) with its partners to govern the processing of end-user data.
How do you comply with outsourcing rules in financial services?
As a key outsourcing provider of regulated financial services entities, Staq is fully aware of the outsourcing rules now in place across most jurisdictions. Staq works closely with its partners to ensure full compliance with outsourcing rules. As an example, Staq's Master Service Agreement has been design with compliance in mind, seeking to address all of the common contractual requirements present in the outsource rules, which can of course be tailored to local specificities.
Is Staq a licensed financial services entity?
Staq is not a licensed financial services entity. We are a technology and business solutions company which partners with licensed financial services entities to offer Banking-as-a-Service and Embedded Finance solutions.
Do you conduct periodic security tests?
Staq engages third-party consultants to periodically audit its information security management systems.
How do you encrypt data in transit?
Our platform ensures end-to-end encryption for data in transit using industry-standard security mechanisms. We enforce TLS 1.2 or higher for all data transmitted over potentially insecure networks, ensuring strong encryption standards. Our API endpoints use certificate-based authentication and TLS encryption, with HTTP Strict Transport Security (HSTS) enabled to enhance security. Secure site-to-site tunnels are established with robust encryption mechanisms to protect sensitive data. For cloud environments, server TLS keys and certificates are managed by AWS or GCP and deployed via Application Load Balancers. On-premise deployments follow the same encryption standards using our secure infrastructure.
How do you encrypt data at rest?
Our platform ensures robust security by encrypting all data at rest across cloud and on-premise environments. Whether hosted on AWS, GCP, or using Longhorn for on-premise storage, we apply strong encryption standards to safeguard sensitive information, maintaining trust and compliance. - AWS: We use AWS Key Management Service (KMS) to encrypt data at rest in Amazon RDS, Amazon S3, and Amazon EBS. - GCP: We leverage Google Cloud’s default encryption for Cloud Storage, Cloud SQL, and Persistent Disks, with options for Customer-Managed Encryption Keys (CMEK). - On-Premise (Longhorn): We use Longhorn’s built-in encryption feature to secure persistent volumes, ensuring that all stored data remains encrypted.