Last updated June 8, 2026
Security
Stash stores agent transcripts, your files, pages, copied integration data, and integration credentials. Please report any issue that could expose, modify, or delete customer data without authorization.
Report a vulnerability
Email sam@joinstash.ai with a concise description, affected URLs or endpoints, reproduction steps, and any evidence needed to understand impact. Do not include third-party customer data beyond the minimum needed to demonstrate the issue.
Response expectations
We acknowledge security reports within 2 business days, prioritize confirmed vulnerabilities by customer-data impact, and coordinate remediation details directly with the reporter.
Safe harbor
Good-faith testing must avoid service disruption, social engineering, spam, data destruction, persistence, and access to data that does not belong to you. If you encounter customer data, stop testing and report the issue with only the minimum evidence required.
Questions? Email sam@joinstash.ai.