Security
How Tallin protects your data.
Review how Tallin handles credentials, separates customer data, and controls access to supervised content. Deployment details and independent assurance status are below.
Supervision data flow
Know where records go and who can read them.
The source provider, storage region, retention period, and customer permissions are agreed during setup. Provider coverage depends on supported enterprise APIs and customer entitlements.
- 1
Customer-selected enterprise provider
The provider compliance API supplies supported records.
- 2
Private capture runtime
Records pass through encrypted, short-lived staging.
- 3
Selected AWS archive
KMS encryption and S3 Object Lock protect retained records.
- 4
Authorized customer review
Role-based content access requires a purpose and creates an access log.
Customer-managed deployment and retention
In customer-managed supervision, provider credentials, raw records, archives, and content-read logs remain in the customer environment. Only allowlisted coverage, health, counts, and review metadata reach Tallin. VPC-resident raw-content review is not yet available.
Hosted archive objects use Object Lock Compliance mode. The retention period is approved before capture begins; shortening the setting does not remove already-locked records. Export, deletion, region, and cross-border requirements need a deployment-specific agreement.
A customer-managed Gateway does not keep requests from reaching the selected external AI provider. Gateway routing, supervision storage, and provider processing are separate data boundaries.
Independent assurance
Security-program status.
Reviewed September 6, 2026. Implemented controls are not a substitute for an issued independent assurance report.
- SOC 2 Type I
- No issued reportA SOC 2 engagement is scheduled to begin at the end of Q3 2026. The examination and report are not complete.
- External penetration test
- PlannedPlanned after the pilot cohort. Date and scope are not yet committed. An executive summary may be shared under NDA when available.
- Vulnerability disclosure
- Open channelSend reports to security@gettallin.com. The acknowledgement target is two business days.
Data handling
Credentials, isolation, and access.
Customer permissions determine access to operational data and review records. Tallin support receives health metadata and allowlisted diagnostics by default.
Access by Tallin staff to raw hosted supervision content requires customer-approved, scoped, time-limited break-glass access. Content reads are audited.
Sub-processors
The vendors behind the service.
Confirm the providers, deployment mode, selected region, and cross-border requirements in your order form. The control plane and supervision archive have separate storage boundaries.
| Vendor | Purpose | Data accessed | Region |
|---|---|---|---|
| Amazon Web Services | Tallin-hosted supervision vault and capture runtime | Supervised AI records only when Tallin-hosted supervision is selected | Customer-selected hosted region |
| Vercel | Hosting and serverless functions | Application traffic and serverless runtime data | US primary |
| WorkOS | Enterprise SSO and directory integration | User identity, organization, and authentication metadata when enabled | US |
| Neon (Postgres) | Primary database | Customer data at rest | US |
| Resend | Transactional email | Email addresses and message content | US |
| Stripe | Billing and payments | Billing details only | US |
| Anthropic | AI API for in-product summaries and drafting | Governance metadata and prompts only when an AI feature is used | US |
| OpenAI | AI API fallback for in-product summaries and drafting | Governance metadata and prompts only when an AI feature is used | US |
Compliance documents
Review the legal baseline.
Reporting a vulnerability
Security reports go directly to the founder.
Send vulnerability reports to security@gettallin.com. Our acknowledgement target is two business days. Include the affected surface, reproduction steps, and a safe way to contact you. Do not include customer secrets or sensitive records in the initial email.