Skip to content

What is StackTakt

StackTakt deploys hardened infrastructure blueprints into your own AWS account, maps every deployment to compliance framework requirements at apply time, and captures the evidence your auditor needs. AWS deploys infrastructure; StackTakt proves what it demonstrates.

Everything StackTakt creates lives in your AWS account. The platform connects through two scoped IAM roles you create and control, with no agent and no long-lived credentials. Delete the roles and access is gone.

StackTakt organizes work in three levels:

  • Organization: your company or consulting firm. Organization scope (/org) rolls up every tenant you can see: spend, compliance coverage, activity, documentation.
  • Tenant: one client or one environment. Most work happens at tenant scope. A consultancy runs one tenant per client; an in-house team might run one per environment.
  • AWS account: a tenant can hold several AWS accounts (dev, test, prod). Each account gets its own connection, and access can be granted down to a single account.

The scope switcher in the top bar moves between organization and tenant scope and keeps you on the same section. Both scopes share the same ten sections: Overview, Accounts, Assets, Blueprints, Deploy, Compliance, Docs, Identity, Activity, and Billing.

A blueprint is a versioned, parameterized infrastructure template. StackTakt renders it with OpenTofu, plans the change, and applies it in your account only after a human approves the plan. Four blueprints ship today: Secure Bucket, Compliant SFTP endpoint, Database, and Simple ETL.

Deploying a blueprint version asserts the control set shipped with that version. The mapping is snapshotted with the deployment, so the compliance view always reflects what was true at apply time.

Each blueprint ships a control mapping: which framework requirements its resources address, how, and with what caveats. The catalog covers the HIPAA Security Rule first, with SOC 2 criteria in the same catalog. StackTakt describes demonstrated capabilities with citations, for example “mapped to HIPAA Security Rule 164.312(a)(1)”. It never asserts a compliance status for you or for itself.

After a successful apply, StackTakt reads back the configuration of every resource it created (named, read-only AWS calls) and stores the result as an evidence package with an auditor-facing PDF export. Every platform action lands in an append-only audit timeline: nothing updates or deletes an audit record.

The in-app Documentation Center holds documents about your infrastructure: a system overview, a runbook, and a control narrative, derived from live deployment data, plus attestation documents your team completes and approves. This docs site is help content about using StackTakt itself. The two are different things.