Trust & Security Center
Built on 100% Microsoft Azure — enterprise-grade security and compliance for your peace of mind.
AI Transparency & Data Privacy
Your Data is Never Used to Train AI Models
We are committed to absolute transparency about our AI usage. Your business data, customer information, and evaluation results are NEVER used to train, fine-tune, or improve any AI models. Your data remains 100% private and confidential to your organization.
Our AI Technology
StingerAI uses Azure OpenAI Service (a GPT-class, latest-generation model) to generate intelligent, context-aware evaluation questions based on your business type, target customer profiles, and publicly available customer reviews from Google and Yelp.
Model Details
- Provider: Microsoft Azure OpenAI Service
- Model: GPT-class (latest generation)
- Deployment: Private, dedicated instance
- Region: East US 2 (Azure)
Zero Training on Your Data
Azure OpenAI Service operates under strict data-privacy agreements. Data sent to the AI service is:
- NOT stored by OpenAI or Microsoft beyond the request
- NOT used for training or improving base models
- NOT shared with other customers or third parties
- NOT reviewed by human moderators (unless abuse is reported)
- Encrypted in transit and during processing
- Deleted immediately after generating your questions
What Data We Send to AI
When generating custom questions, we send ONLY the following non-sensitive information:
- Business Type — your industry category (e.g. “Restaurant,” “Retail Store”)
- Target Customer Profile — demographic attributes you define
- Location Info — city, state, and business name
- Public Reviews — customer feedback from Google/Yelp (already public)
Enterprise-Grade AI Security
Our AI implementation follows Microsoft's strictest security standards:
- Private Deployment — dedicated Azure AI instance, not shared
- Azure Virtual Network — AI calls isolated in a private network
- Managed Identity — secure authentication without API keys
- Content Filtering — automatic abuse & jailbreak detection
- Prompt-Injection Protection — guards against malicious inputs
- Compliance — SOC 2, HIPAA, ISO 27001 certified
How StingerAI Works
When you create a target customer persona and generate questions:
Step 1: You define your business type and customer profile in our guided wizard
Step 2: We fetch public reviews from Google/Yelp about your location (no private data)
Step 3: Azure AI analyzes patterns and generates relevant evaluation questions
Step 4: You review, select, and customize the generated questions before use
Result: Hyper-relevant questions tailored to YOUR business — no data retained by AI
Questions About Our AI Usage?
We believe in complete transparency. If you have any questions about how we use AI, what data is processed, or our privacy practices, contact our security team at security@stingercompliance.com.
Security & Infrastructure
100% Microsoft Azure
Our entire infrastructure runs on Microsoft Azure, with a 99.99% uptime SLA and global redundancy across multiple data centers.
End-to-End Encryption
All data is encrypted at rest with AES-256 and in transit with TLS 1.3 — protected at every layer of our infrastructure.
Secure Authentication
Multi-factor authentication (MFA), OAuth 2.0, and JWT token-based auth ensure only authorized users access your data.
Azure Cosmos DB
Data is stored in globally distributed Azure Cosmos DB with automatic backups, point-in-time recovery, and a 99.999% availability guarantee.
Automated Backups
Continuous automated backups with geo-redundant storage protect your data against disasters and restore it to any point in time.
Regular Updates
Microsoft Azure patches and updates infrastructure automatically, so you always benefit from the latest security improvements.
Technology Stack
Cloud Infrastructure
- Azure App Service — auto-scaling hosting for the web apps & API
- Azure Cosmos DB — globally distributed NoSQL database
- Azure Storage — secure blob storage for files and documents
- Azure CDN — global content delivery for fast performance
- Azure Key Vault — secure management of secrets and certificates
Application & Frontend
- Next.js 15 + React 19 — server-rendered client web app (TypeScript)
- React + Vite — the admin dashboard single-page app (TypeScript)
- TypeScript 5 — end-to-end type safety across the frontend
- Tailwind CSS — utility-first, accessible UI
- ASP.NET Core 10 (C#) — high-performance Web API
- Playwright — automated end-to-end UI testing on every release
Compliance & Standards
SOC 2 Type II
Microsoft Azure complies with SOC 2 Type II standards for security, availability, and confidentiality.
HIPAA Compliant
Azure infrastructure meets HIPAA requirements for handling protected health information (PHI).
GDPR Ready
Built with GDPR compliance in mind, with data-residency options and right-to-delete capabilities.
ISO 27001
Azure data centers are ISO 27001 certified for information security management.
PCI DSS
Payment processing through PCI DSS compliant gateways ensures credit-card data security.
FedRAMP
Azure meets FedRAMP standards for U.S. government cloud security requirements.
Security Protocols & Best Practices
Network Security
- TLS 1.3 encryption for all data in transit
- Azure DDoS Protection Standard
- Web Application Firewall (WAF)
- Azure Virtual Network isolation
- Network Security Groups (NSGs)
- Azure Private Link for secure connections
Data Protection
- AES-256 encryption at rest
- Geo-redundant storage (GRS)
- Automated continuous backups
- Point-in-time restore
- Data-residency controls
- Immutable blob storage for audit logs
Access Control
- Role-Based Access Control (RBAC)
- Multi-Factor Authentication (MFA)
- OAuth 2.0 and OpenID Connect
- JWT token-based authentication
- Session management & timeout controls
- Principle of least privilege
Monitoring & Logging
- Azure Monitor for real-time monitoring
- Application Insights for performance tracking
- Comprehensive audit logging
- Threat detection and alerts
- Security incident response procedures
- 24/7 automated security monitoring
Business Continuity & Disaster Recovery
99.99%
Uptime SLA
Azure's commitment to availability
< 4 Hours
Recovery Time Objective
Maximum time to restore services
15 Minutes
Recovery Point Objective
Maximum acceptable data loss
Global Infrastructure
Your data is hosted in Microsoft Azure's state-of-the-art data centers with:
- 60+ regions worldwide
- Physical security with biometric access
- 24/7 on-site security personnel
- Redundant power and cooling systems
- Fire suppression and environmental controls
- Geo-redundant replication across regions
Incident Response & Support
In the unlikely event of a security incident, we have comprehensive procedures in place:
Detection: 24/7 automated monitoring and threat detection immediately identify potential incidents
Response: Our security team is alerted and begins incident response procedures within minutes
Containment: Affected systems are isolated to prevent further unauthorized access
Communication: Affected customers are notified within 72 hours with detailed information
Resolution: Root-cause analysis and remediation prevent future occurrences
Security Resources & Contact
Security Documentation
Report Security Issues
If you discover a security vulnerability, please report it to our security team immediately:
security@stingercompliance.comWe take all security reports seriously and typically respond within 24 hours.
Powered by Microsoft Azure
Our entire infrastructure runs on Microsoft Azure's enterprise-grade cloud platform, ensuring the highest levels of security, reliability, and performance for your compliance needs.
Last updated: July 17, 2026
