Security and Data Handling Statement
Version 2026.09.20 | Effective September 20, 2026
Source package: Customer-Facing Legal Policies
TacSafe maintains a security program designed for a multi-tenant business SaaS environment. This statement describes current security practices at a high level and does not represent a certification or guarantee of absolute security.
| Control area | Current approach |
|---|---|
| Identity and access | Role-based access, organization scoping, least privilege, administrator controls, and MFA support/requirements for privileged access where configured. |
| Database isolation | Tenant-aware authorization and row-level access controls are used to restrict organization data access. |
| Object storage | Customer files are stored in private object storage and delivered through controlled access paths rather than public buckets. |
| Encryption | TLS is used for data in transit; infrastructure providers supply encryption at rest for managed database and object-storage services. |
| Secrets | Production credentials are stored outside source code and access is restricted. Engineering agents are not granted autonomous production authority. |
| Change management | Application changes are tested and reviewed before controlled promotion. Production promotion remains a human-authorized action. |
| Logging and monitoring | Security, authentication, system, and operational events are logged as appropriate for detection, support, and investigation. |
| Backups and recovery | Managed infrastructure backup and recovery mechanisms are used according to provider capabilities and service requirements. |
| Vendor management | Critical service providers are selected and reviewed based on service, security, data-processing, and contractual requirements. |
| Incident response | TacSafe maintains procedures to investigate, contain, remediate, document, and notify affected Customers of confirmed security incidents as required by contract and law. |
Responsible disclosure
Report suspected security vulnerabilities to Security@tacsafe.app. Do not access data belonging to others, degrade the Service, or conduct destructive testing. TacSafe may provide written authorization and test boundaries for approved security research.
