Security

How Tallin protects your data.

Review how Tallin handles credentials, separates customer data, and controls access to supervised content. Deployment details and independent assurance status are below.

Supervision data flow

Know where records go and who can read them.

The source provider, storage region, retention period, and customer permissions are agreed during setup. Provider coverage depends on supported enterprise APIs and customer entitlements.

Tallin-hosted supervision
  1. 1

    Customer-selected enterprise provider

    The provider compliance API supplies supported records.

  2. 2

    Private capture runtime

    Records pass through encrypted, short-lived staging.

  3. 3

    Selected AWS archive

    KMS encryption and S3 Object Lock protect retained records.

  4. 4

    Authorized customer review

    Role-based content access requires a purpose and creates an access log.

Customer-managed deployment and retention

In customer-managed supervision, provider credentials, raw records, archives, and content-read logs remain in the customer environment. Only allowlisted coverage, health, counts, and review metadata reach Tallin. VPC-resident raw-content review is not yet available.

Hosted archive objects use Object Lock Compliance mode. The retention period is approved before capture begins; shortening the setting does not remove already-locked records. Export, deletion, region, and cross-border requirements need a deployment-specific agreement.

A customer-managed Gateway does not keep requests from reaching the selected external AI provider. Gateway routing, supervision storage, and provider processing are separate data boundaries.

Independent assurance

Security-program status.

Reviewed September 6, 2026. Implemented controls are not a substitute for an issued independent assurance report.

SOC 2 Type I
No issued reportA SOC 2 engagement is scheduled to begin at the end of Q3 2026. The examination and report are not complete.
External penetration test
PlannedPlanned after the pilot cohort. Date and scope are not yet committed. An executive summary may be shared under NDA when available.
Vulnerability disclosure
Open channelSend reports to security@gettallin.com. The acknowledgement target is two business days.

Data handling

Credentials, isolation, and access.

Customer permissions determine access to operational data and review records. Tallin support receives health metadata and allowlisted diagnostics by default.

Access by Tallin staff to raw hosted supervision content requires customer-approved, scoped, time-limited break-glass access. Content reads are audited.

Tenant-scoped PostgreSQL row-level security. Runtime database roles are restricted and cannot bypass RLS.
TLS for application, API, and cloud-service traffic.
AES-256-GCM envelope encryption for provider credentials with workspace-scoped data keys. Saved credentials are not redisplayed.
Supervision content reads require an allowed purpose and create an access log. Review actions record the actor, decision, and timestamp.

Sub-processors

The vendors behind the service.

Confirm the providers, deployment mode, selected region, and cross-border requirements in your order form. The control plane and supervision archive have separate storage boundaries.

VendorPurposeData accessedRegion
Amazon Web ServicesTallin-hosted supervision vault and capture runtimeSupervised AI records only when Tallin-hosted supervision is selectedCustomer-selected hosted region
VercelHosting and serverless functionsApplication traffic and serverless runtime dataUS primary
WorkOSEnterprise SSO and directory integrationUser identity, organization, and authentication metadata when enabledUS
Neon (Postgres)Primary databaseCustomer data at restUS
ResendTransactional emailEmail addresses and message contentUS
StripeBilling and paymentsBilling details onlyUS
AnthropicAI API for in-product summaries and draftingGovernance metadata and prompts only when an AI feature is usedUS
OpenAIAI API fallback for in-product summaries and draftingGovernance metadata and prompts only when an AI feature is usedUS

Reporting a vulnerability

Security reports go directly to the founder.

Send vulnerability reports to security@gettallin.com. Our acknowledgement target is two business days. Include the affected surface, reproduction steps, and a safe way to contact you. Do not include customer secrets or sensitive records in the initial email.

Security | Tallin