Trust & Security Center

Built on 100% Microsoft Azure — enterprise-grade security and compliance for your peace of mind.

AI Transparency & Data Privacy

Your Data is Never Used to Train AI Models

We are committed to absolute transparency about our AI usage. Your business data, customer information, and evaluation results are NEVER used to train, fine-tune, or improve any AI models. Your data remains 100% private and confidential to your organization.

Our AI Technology

StingerAI uses Azure OpenAI Service (a GPT-class, latest-generation model) to generate intelligent, context-aware evaluation questions based on your business type, target customer profiles, and publicly available customer reviews from Google and Yelp.


Model Details

  • Provider: Microsoft Azure OpenAI Service
  • Model: GPT-class (latest generation)
  • Deployment: Private, dedicated instance
  • Region: East US 2 (Azure)

Zero Training on Your Data

Azure OpenAI Service operates under strict data-privacy agreements. Data sent to the AI service is:

  • NOT stored by OpenAI or Microsoft beyond the request
  • NOT used for training or improving base models
  • NOT shared with other customers or third parties
  • NOT reviewed by human moderators (unless abuse is reported)
  • Encrypted in transit and during processing
  • Deleted immediately after generating your questions

What Data We Send to AI

When generating custom questions, we send ONLY the following non-sensitive information:

  • Business Type — your industry category (e.g. “Restaurant,” “Retail Store”)
  • Target Customer Profile — demographic attributes you define
  • Location Info — city, state, and business name
  • Public Reviews — customer feedback from Google/Yelp (already public)
We NEVER send employee data, customer PII, financial information, or evaluation results to AI.

Enterprise-Grade AI Security

Our AI implementation follows Microsoft's strictest security standards:

  • Private Deployment — dedicated Azure AI instance, not shared
  • Azure Virtual Network — AI calls isolated in a private network
  • Managed Identity — secure authentication without API keys
  • Content Filtering — automatic abuse & jailbreak detection
  • Prompt-Injection Protection — guards against malicious inputs
  • Compliance — SOC 2, HIPAA, ISO 27001 certified

How StingerAI Works

When you create a target customer persona and generate questions:

  1. Step 1: You define your business type and customer profile in our guided wizard

  2. Step 2: We fetch public reviews from Google/Yelp about your location (no private data)

  3. Step 3: Azure AI analyzes patterns and generates relevant evaluation questions

  4. Step 4: You review, select, and customize the generated questions before use

  5. Result: Hyper-relevant questions tailored to YOUR business — no data retained by AI

Questions About Our AI Usage?

We believe in complete transparency. If you have any questions about how we use AI, what data is processed, or our privacy practices, contact our security team at security@stingercompliance.com.

Security & Infrastructure

100% Microsoft Azure

Our entire infrastructure runs on Microsoft Azure, with a 99.99% uptime SLA and global redundancy across multiple data centers.

End-to-End Encryption

All data is encrypted at rest with AES-256 and in transit with TLS 1.3 — protected at every layer of our infrastructure.

Secure Authentication

Multi-factor authentication (MFA), OAuth 2.0, and JWT token-based auth ensure only authorized users access your data.

Azure Cosmos DB

Data is stored in globally distributed Azure Cosmos DB with automatic backups, point-in-time recovery, and a 99.999% availability guarantee.

Automated Backups

Continuous automated backups with geo-redundant storage protect your data against disasters and restore it to any point in time.

Regular Updates

Microsoft Azure patches and updates infrastructure automatically, so you always benefit from the latest security improvements.

Technology Stack

Cloud Infrastructure

  • Azure App Service — auto-scaling hosting for the web apps & API
  • Azure Cosmos DB — globally distributed NoSQL database
  • Azure Storage — secure blob storage for files and documents
  • Azure CDN — global content delivery for fast performance
  • Azure Key Vault — secure management of secrets and certificates

Application & Frontend

  • Next.js 15 + React 19 — server-rendered client web app (TypeScript)
  • React + Vite — the admin dashboard single-page app (TypeScript)
  • TypeScript 5 — end-to-end type safety across the frontend
  • Tailwind CSS — utility-first, accessible UI
  • ASP.NET Core 10 (C#) — high-performance Web API
  • Playwright — automated end-to-end UI testing on every release

Compliance & Standards

SOC 2 Type II

Microsoft Azure complies with SOC 2 Type II standards for security, availability, and confidentiality.

HIPAA Compliant

Azure infrastructure meets HIPAA requirements for handling protected health information (PHI).

GDPR Ready

Built with GDPR compliance in mind, with data-residency options and right-to-delete capabilities.

ISO 27001

Azure data centers are ISO 27001 certified for information security management.

PCI DSS

Payment processing through PCI DSS compliant gateways ensures credit-card data security.

FedRAMP

Azure meets FedRAMP standards for U.S. government cloud security requirements.

Security Protocols & Best Practices

Network Security

  • TLS 1.3 encryption for all data in transit
  • Azure DDoS Protection Standard
  • Web Application Firewall (WAF)
  • Azure Virtual Network isolation
  • Network Security Groups (NSGs)
  • Azure Private Link for secure connections

Data Protection

  • AES-256 encryption at rest
  • Geo-redundant storage (GRS)
  • Automated continuous backups
  • Point-in-time restore
  • Data-residency controls
  • Immutable blob storage for audit logs

Access Control

  • Role-Based Access Control (RBAC)
  • Multi-Factor Authentication (MFA)
  • OAuth 2.0 and OpenID Connect
  • JWT token-based authentication
  • Session management & timeout controls
  • Principle of least privilege

Monitoring & Logging

  • Azure Monitor for real-time monitoring
  • Application Insights for performance tracking
  • Comprehensive audit logging
  • Threat detection and alerts
  • Security incident response procedures
  • 24/7 automated security monitoring

Business Continuity & Disaster Recovery

99.99%

Uptime SLA

Azure's commitment to availability

< 4 Hours

Recovery Time Objective

Maximum time to restore services

15 Minutes

Recovery Point Objective

Maximum acceptable data loss

Global Infrastructure

Your data is hosted in Microsoft Azure's state-of-the-art data centers with:

  • 60+ regions worldwide
  • Physical security with biometric access
  • 24/7 on-site security personnel
  • Redundant power and cooling systems
  • Fire suppression and environmental controls
  • Geo-redundant replication across regions

Incident Response & Support

In the unlikely event of a security incident, we have comprehensive procedures in place:

  1. Detection: 24/7 automated monitoring and threat detection immediately identify potential incidents

  2. Response: Our security team is alerted and begins incident response procedures within minutes

  3. Containment: Affected systems are isolated to prevent further unauthorized access

  4. Communication: Affected customers are notified within 72 hours with detailed information

  5. Resolution: Root-cause analysis and remediation prevent future occurrences

Security Resources & Contact

Report Security Issues

If you discover a security vulnerability, please report it to our security team immediately:

security@stingercompliance.com

We take all security reports seriously and typically respond within 24 hours.

Powered by Microsoft Azure

Our entire infrastructure runs on Microsoft Azure's enterprise-grade cloud platform, ensuring the highest levels of security, reliability, and performance for your compliance needs.

Last updated: July 17, 2026