Skip to main content

Security

Last updated: 30 Jul 2026

Our Approach to Security

Security is foundational to how we build and operate Stunt Double. We take a privacy-first approach, minimise the data we collect and retain, and align our controls and policies with recognised industry frameworks.

Because our AI actors act on your behalf, we treat the confidentiality and integrity of your data as a top priority across everything we do.

Data Protection

We protect customer data in transit and at rest using industry-standard encryption. We collect and retain only the data needed to provide our services, and we never sell or rent your personal information.

Full details of how we handle personal data are set out in our Privacy Policy.

Infrastructure & Suppliers

Stunt Double is built on established, industry-leading cloud infrastructure. Our subprocessors maintain SOC 2 Type II certification, and we assess their security posture as part of our supplier due diligence.

The subprocessors we rely on are listed in our Privacy Policy.

Access Controls

Every piece of data in Stunt Double belongs to a workspace, and tenant isolation is enforced at the data layer rather than in application code alone. Access is denied by default, and the same rules apply to every surface: the dashboard, the API, our integrations and our background jobs.

Members hold one of three roles, and workspace owners and admins have a further set of workspace-wide controls in Settings. These let an administrator switch off features the organisation has not approved, constrain where our AI actors are permitted to navigate, and restrict who may be invited into the workspace. They act as ceilings that apply on every request and cannot be widened from anywhere else in the product.

Enterprise Deployment Options

For customers whose products are only reachable inside their own network, our AI actors can run on a self-hosted worker deployed within that network, rather than on our hosted browser infrastructure. Internal applications are never exposed to the public internet, no inbound firewall ports need to be opened, and each worker is bound by a network access policy that names the hosts it is allowed to reach.

Self-hosted workers are available on the Enterprise plan and must be enabled for the workspace by an administrator. Our security documentation covers the architecture in detail for teams that need to assess it.

Compliance & Certification

Our security programme is aligned with the SOC 2 Trust Services Criteria, and we have already implemented the substantial majority of the controls required for certification. We are actively preparing for a SOC 2 Type II examination.

We comply with applicable information security and data protection legislation, and we can provide further assurance to customers on request.

Security Incident Management

In the event of a security incident affecting customer data, we will notify affected customers promptly, take appropriate steps to contain and remediate the incident, and keep customers informed of progress and any preventative measures taken.

Security Documentation

We keep a detailed Security Overview for security and compliance teams that need to assess Stunt Double. It covers our architecture and tenant isolation model, data handling and retention, authentication and access control, network controls for AI actors, self-hosted workers, our public endpoints, subprocessors, and our incident response and vulnerability management processes.

We deliberately keep that level of detail out of our public pages, so we share it directly with customers and prospective customers under NDA. Request it from security@stuntdouble.io and tell us which areas matter most to you. We are also happy to complete security questionnaires and to talk your team through the design.

Responsible Disclosure

We welcome reports from security researchers and the wider community. If you believe you have found a security vulnerability in Stunt Double, please report it to us privately at security@stuntdouble.io and give us a reasonable opportunity to investigate and remediate before any public disclosure.

Contact

For security-related enquiries, including vulnerability reports, documentation requests and questions about our compliance posture, contact us at security@stuntdouble.io. For general enquiries, you can reach us at hello@stuntdouble.io.