Our commitment
StackJack.io (a product of MSP Automator Labs, LLC) provides hosted, multi-tenant MCP connectors that let AI assistants interact with the PSA, RMM, and IT documentation platforms MSPs run their businesses on. Because our connectors broker authenticated access to our customers' core operational systems, security is not a feature bolted on after the fact — it is the center of how the product is designed.
This page summarizes our security posture. For detailed documentation, questionnaires, or a copy of our current audit report, see the Requesting documentation section below.
Authentication & credential handling
- Connections are authorized using OAuth 2.0 with PKCE, available on every plan and every connector.
- Secrets and tokens are stored in Azure Key Vault, isolated per tenant, and never exposed in logs or client-side code.
- We follow least-privilege principles: each connector requests only the scopes required to operate.
Infrastructure & hosting
StackJack runs entirely on Microsoft Azure, using Azure Container Apps, Azure Functions, and Azure Key Vault. We rely on Azure's physical, network, and platform security controls, and Microsoft Entra for identity. Data is encrypted in transit (TLS 1.2+) and at rest.
Tenant isolation
Every customer operates within an isolated tenant boundary. Credentials, tokens, and configuration are scoped to the individual tenant and are never shared or accessible across tenants.
Data handling
StackJack acts as a secure broker between AI assistants and your MSP tooling. We hold the credentials required to maintain your authorized connections; we do not warehouse or repurpose the operational data that passes through those connections. Access is driven by your own authenticated requests.
Compliance
We are actively pursuing SOC 2 Type 2 attestation. Our controls are mapped to the Trust Services Criteria, and we maintain written security, access-control, and incident-response policies. Current status and available reports can be confirmed via the contact below.
Vulnerability & incident response
We maintain a documented incident-response process and monitor our environment for anomalous activity. Security issues can be reported directly to the contact listed below, and we commit to timely triage and remediation.
Insurance
MSP Automator Labs, LLC carries technology errors & omissions (professional liability) and standalone cyber liability coverage. Coverage details are available to prospective customers and partners on request as part of a due-diligence review.
Requesting documentation
Security questionnaires, due-diligence requests, and requests for our current compliance documentation should be directed to security@stackjack.io or via stackjack.io/security.