Security
Last updated: July 2026
Security is foundational to how Mabstack works. Our practices are designed to protect customer data, maintain service integrity, and ensure the websites, accounts, and systems we manage for clients stay safe against evolving threats.
Encryption at Rest & In Transit
All customer data is encrypted using AES-256 at rest and TLS 1.3 in transit. Key management follows NIST standards with automatic rotation.
Access Control
Zero-trust architecture with role-based access control (RBAC), multi-factor authentication, and session auditing. Access is granted on a least-privilege basis and reviewed quarterly.
Vulnerability Management
Continuous vulnerability scanning, monthly penetration testing, and a responsible disclosure program. Critical vulnerabilities are patched within 24 hours.
Infrastructure Security
All infrastructure runs on isolated, monitored environments with intrusion detection, DDoS protection, and immutable infrastructure patterns.
Reporting a Vulnerability
If you discover a security issue, please contact our security team immediately at security@mabstack.com. We commit to acknowledging receipt within 24 hours and providing a detailed remediation timeline within 72 hours. We operate a responsible disclosure policy and will not pursue legal action against researchers acting in good faith.
Incident Response
Our incident response framework aligns with NIST SP 800-61. We maintain a dedicated on-call security team, conduct post-mortems for all incidents, and provide customers with timely notifications per our SLA commitments.
