Security & Data Protection
Last updated: September 1, 2026
FutureStacks is the company behind Devfood. This page records what we can honestly say about security at the company level on futurestacks.com. It is not a substitute for the product security page on devfood.com, where tenant isolation, payment handling and the subprocessor list are published in full.
What this site handles
futurestacks.com is a marketing website. It collects contact form submissions and, if you allow it, aggregate analytics cookies. It does not process orders, store card data or host customer accounts. See our privacy policy and cookie policy for what we collect here.
The boundaries, stated up front
What this site asserts, it can evidence, and that keeps the list short. Formal certification — ISO, SOC or PCI — is not something we hold, so no badge appears here. futurestacks.com carries no uptime percentage and no contractual service level either, because standing behind one would take independent monitoring we do not run at the company-marketing level.
Reporting a vulnerability
If you believe you have found a security issue in this site or in Devfood, email
contact@devfood.com with enough detail to reproduce it. We will acknowledge it, say what
we intend to do, and credit you if you would like us to. Please do not test against a live customer's ordering site —
ask and we will arrange a safe way to look. The same contact is published machine-readably at
/.well-known/security.txt, which is what this page's
Policy pointer resolves to.
Where the product security detail lives
Devfood's security page is the authoritative list for the ordering platform: tenant isolation, access control, how payments are handled, and a plain subprocessor table. Quote security claims from that page, not from this one.
If you are evaluating Devfood for procurement, start there. If something is missing or unclear, email contact@devfood.com and we will answer directly.