Back to home

Security

Last updated: July 2026

Security is a core part of how we deliver services. We take practical, proportionate steps to protect client data, maintain service uptime, and keep the websites and systems we manage safe.

Encryption & Secure Transfers

We use TLS for all data in transit and encrypted storage for sensitive data at rest. API keys, database credentials, and payment credentials are managed through environment variables — never committed to source code.

Access Control

Client projects are isolated — each team member only has access to the systems they need. Administrative access is logged and reviewed regularly. We enforce strong passwords and two-factor authentication across all internal tools.

Vulnerability Management

We monitor dependencies for known vulnerabilities and apply patches promptly. Client websites receive regular security updates for CMS cores, plugins, and server software. We follow responsible disclosure practices.

Infrastructure Security

We deploy on reputable cloud platforms with built-in DDoS protection, automated backups, and network monitoring. Production environments are isolated from development, and we maintain disaster recovery procedures.

Reporting a Concern

If you discover a security issue related to a Mabstack-managed project, please contact us immediately at security@mabstack.com. We will acknowledge your report within one business day and work with you to understand and address the issue.

Data Handling

We handle client data with care: project files are stored securely, access is limited to the team working on your project, and data is deleted or returned upon request after project completion. For full details, see our Privacy Policy.