Security Terms | Stuv AI

Security Terms

Last updated: June 17, 2026

1. Access Control & User Authentication

Stuv provides secure access to the platform through a username-and-password authentication system.

We enforce Role-Based Access Control (RBAC) to ensure that users can access only the features and data permitted based on their assigned roles. All access rights are managed within the application to maintain least-privilege access.

2. Secure Software Development Practices

Stuv follows Secure SDLC practices throughout the development lifecycle.

All code changes are created, reviewed, and approved through GitHub, with the following automated controls:

  • Dependency scanning
  • Code scanning
  • Vulnerability alerts
  • Version control and audit logging

All production changes follow a controlled review and approval process.

3. Change & Configuration Management

All system and application changes are:

  • Reviewed and approved
  • Recorded with complete version history
  • Traceable via GitHub change logs

This ensures configuration integrity and accountability across the product development process.

4. Data Storage & Residency

Stuv operates on a country-specific data residency model. Customer data is stored exclusively within data centers located in the customer's country of operation.

We do not transfer or store customer information outside the customer's home jurisdiction, except as expressly permitted under this agreement.

Stuv currently supports customers in India, United Arab Emirates, Singapore, Indonesia, and other jurisdictions, and ensures compliance with applicable local data protection and residency requirements.

5. Data Privacy & Use of Third Parties

Stuv does not share customer data with third parties, except in limited cases where images are processed through trusted AI service providers for transformation purposes.

These providers:

  • Cannot use or store customer data
  • Do not conduct analytics on customer content
  • Act only as processors under strict contractual and technical safeguards

Stuv's Privacy Policy is aligned with globally accepted privacy principles.

6. Data Portability & Deletion

Upon contract termination:

  • Customers may request a complete export of their data in standard formats (CSV/JSON).
  • Stuv securely deletes all customer data from systems and backups as per our data retention policy.
  • Confirmation of deletion can be provided upon request.

7. Encryption & Key Management

Stuv uses industry-standard AES-256 encryption to protect all customer data at rest within AWS.

Key management is handled through AWS Key Management Service (KMS), ensuring:

  • Secure key storage
  • Controlled key access
  • Automated key rotation by AWS

All communication between the customer's device and the Stuv platform is encrypted using TLS/SSL.

8. Infrastructure & Network Security

Stuv's infrastructure is secured using AWS best practices, including:

  • Hardened infrastructure components
  • Restricted ports, services, and permissions
  • Controlled Security Groups and IAM policies
  • Regular OS and application patching
  • AWS-managed hypervisor patching
  • Malware and threat prevention using AWS security services

These controls ensure a secure and well-governed hosting environment.

9. Monitoring, Logging & Incident Response

We continuously monitor our cloud infrastructure through:

  • AWS CloudWatch (performance, anomalies, metrics)
  • AWS CloudTrail (access logs, administrative activity, audit logs)

Logs are protected against tampering and unauthorized access.

If Stuv detects a suspected or confirmed security incident:

  • Affected customers are notified promptly
  • Relevant logs can be provided to the customer for investigation
  • An internal incident response process ensures rapid reaction and recovery

10. Availability & Backup Measures

Stuv maintains:

  • Real-time alerts for infrastructure components
  • The ability to restore services within minutes in the event of a failure

These procedures are designed to ensure continuity and reduce downtime.

11. Audit & Customer Assurance

Stuv can provide customers, upon request:

  • Relevant security documentation
  • Internal assessments
  • System logs (in breach scenarios)