StickRate
Trust & Compliance
Security, privacy, and compliance resources for StickRate customers, prospects, and their procurement and legal teams.
Compliance posture
SOC 2 Type II
In progress
AWS infrastructure certified
GDPR
Compliant
SCCs + DPA available
CCPA/CPRA
Compliant
Service Provider terms
Data residency
US-East-1
AWS us-east-1
Documents & resources
Data Processing Agreement
GDPR/CCPA-compliant DPA covering processing purposes, sub-processors, security measures, and data subject rights.
Information Security Overview
Our security controls, encryption standards, access management, vulnerability management, and incident response.
Sub-Processor List
All third parties that process personal data on StickRate's behalf, with locations and certifications.
Privacy Policy
How we collect, use, retain, and protect personal data, and how to exercise your data subject rights.
Acceptable Use Policy
Permitted and prohibited uses of the StickRate platform, including data obligations and violation reporting.
AI governance
StickRate uses large language models (LLMs) for AI-assisted field mapping and signal extraction. Customer Data sent to LLM providers is processed under data processing agreements that prohibit training on Customer Data. LLM providers are listed in the Sub-Processor List. AI-generated outputs are always reviewable and correctable by users.