API documentation

Security overview

The security posture of the Stonewake platform, for an enterprise IT review, on one page. The product needs no data from your bank: it works on public and licensed external sources, nothing is installed on your side, and every access path is HTTPS only. This page covers the service as your teams use it in the browser; the programmatic surface has its own page under API security.

Hosting and encryption

  • The API and the product database run in the European Union; the dashboard front end is delivered through a global content delivery network; the managed sign-in service runs in the United Kingdom.
  • All traffic is TLS only, and the dashboard ships strict security headers on every response: a content security policy, frame denial, strict transport security, and content-type protections, verifiable from any browser.
  • Data is encrypted in transit and at rest. Database backups are encrypted, held apart from the production server, and kept for a defined retention window; restore procedures have been exercised.

Access and identity

  • Sign-in is by work email and password, or a one-time sign-in link sent to the work email, through a managed authentication service. Sign-in tokens expire after one hour and are renewed only for an active session; a session ends at sign-out or on administrative removal.
  • Single sign-on is prepared: SAML 2.0 federation to Microsoft Entra ID, enabled per customer once federation with your identity provider is set up. Your identity team keeps control of credentials, MFA, and conditional access.
  • Workspace access is role based (viewer, analyst, compliance, and admin), least privilege by default, and every grant is made by a named administrator. Our own operator functions sit behind a separate operator privilege that no customer account holds, administrators included.

Isolation and auditability

  • Each institution has its own isolated workspace. Tenant isolation is enforced at three independent layers, down to row-level security in the database.
  • Actions on workspace data land in an append-only audit trail attributed to the acting user; the database refuses updates and deletions of audit entries from the application.
  • Your workspace records (deals, screenings, review decisions and exports) are stored on our infrastructure and are never used to train models. Search queries and fetched public text are processed by search and AI providers under the terms in the privacy policy, sections 7 and 8.
  • Research content is AI-assisted, disclosed as such in the product, grounded in cited sources, and reviewed by your analysts. Scores apply to organizations and countries, never to natural persons: no endpoint serves a person-level score, and the build fails if one appears. Our classification under the EU AI Act is on the AI Act page.

Vulnerability management

  • Our release gate includes automated dependency audits over the backend and the dashboard dependency trees and a secret scan over the full repository history.
  • Report suspected vulnerabilities to contact@stonewake.ai with "Security" in the subject; scope, safe harbour and response times are on the security disclosure page.

Related: Enterprise onboarding, Data handling, Accessibility, the privacy policy, and the data processing agreement provided to customer banks.