Security

We're a security company — we act like one.

Stinger is built by AIM Intelligence, an AI Red Team. The same scrutiny we apply to our customers' systems, we apply to our own.

Data in transit & at rest

TLS 1.2+ in transit. Encrypted at rest (provider-level AES-256). Per-tenant logical isolation in Postgres.

Authentication

RS256 JWT with JWKS. GitHub OAuth. Refresh token rotation. SAML/SCIM on Enterprise.

Hosting

Primary region: Seoul (ap-northeast-2). K8s with per-tenant isolation. EU/US regions available on Enterprise.

Vulnerability management

Dependabot in CI. Internal red team testing weekly. Third-party pentest on major releases.

Logging & monitoring

Structured logs, 90-day retention. Error tracking via Sentry. Uptime and SLO alerting.

Authorized testing only

Stinger requires written attestation that you own or are authorized to test every target.

Compliance

ISO 27001 certified (2026). SOC 2 Type 2 in progress. GDPR & CCPA compliant. DPA available on request.

Trust center

Need an ISO 27001 certificate, SOC 2 report, pentest summary, or vendor questionnaire? Email success@aim-intelligence.com.