security

Security at Tandera

You are about to put your clients’ unpatched vulnerabilities in someone else’s system. That deserves specifics.

What is built is marked built. What is planned is marked planned.

Last reviewed August 2026

Where your data lives

  • One region: AWS us-east-2 US East, Ohio. Your data does not move between regions, because there is only one. If you need a different region, that is the BYOC conversation below.
  • The database has no public endpoint Postgres runs inside a private VPC. It is reachable from the API’s own functions and nothing else. There is no address on the internet to attack.
  • Evidence and uploads are encrypted in S3 Screenshots, scanner output and credential files are stored with SSE-KMS against Tandera’s own customer-managed key.

Encryption

  • In transit TLS on every connection, from your browser to the API and from the API to the database.
  • At rest Storage encryption is enabled on the database and on every bucket that holds your content.
  • Secrets get their own key Credential-vault entries, integration tokens and report passwords use envelope encryption with a per-record data key via AWS KMS. Automatic key rotation is on.
  • Deleting really deletes Removing a vault credential nulls its encrypted columns in the same statement that writes the tombstone. The ciphertext is gone, not flagged as hidden.

Who can see what

  • Your org comes from the token, never the request The organisation id used to scope every query is read from the verified session token. A client cannot ask for another tenant’s data by changing a parameter.
  • Cross-tenant reads return “not found” Never “forbidden”. A wrong answer that confirms a record exists is still a leak, so the API does not confirm it.
  • Five roles, not one Admin, manager, reviewer, hacker and client. A tester does not need the permissions of an owner, and a client needs far fewer than either.
  • Clients see only what you publish The client role reaches the portal and the findings you have chosen to share there. It does not reach the engagement behind it.

The audit trail

Every mutation is written to an append-only log in the same database transaction as the change itself. If the change committed, the audit row committed with it. Each row records:

actor · action · resource type · resource id · IP address · user agent · before state · after state · timestamp

Report rendering is sandboxed

Reports are built from scanner output and, if you use those features, from AI-assisted text. Both are untrusted input. Every piece of it is escaped before it reaches the renderer, and the renderer itself runs with no filesystem, no network and no package imports. A missed escape still cannot read a file or make a request.

Subprocessors

The third parties involved in running Tandera, and what each one can see. Two of these only apply if you turn the feature on.

ProviderWhat it doesWhat it can see
Amazon Web ServicesHosting, database, storage, encryption keys, transactional emailAll application data
ClerkAuthentication and organisation membershipNames, email addresses, session and role
StripeSubscription billing through Stripe-hosted checkoutBilling contact and payment method. Card details go to Stripe directly and never touch Tandera
AnthropicAI finding mapping and evidence assistance, only on the features that use itThe finding and evidence text submitted to those specific features
PostHogProduct and marketing analyticsUsage events and page views, not your findings
Atlassian JiraIssue sync, only if you connect itThe findings you choose to push
CloudflareDNS and CDN for the public sitePublic site traffic only

What we do not have yet

  • No SOC 2 and no ISO 27001 We are not certified. If procurement requires a certification today, tell us and we’ll give you a straight answer on the timeline.
  • BYOC is designed, not deployed Running Tandera inside your own AWS account, with your S3, your database, your KMS key, your region and your CloudTrail, is planned for Enterprise. It is a design document right now. We will keep calling it planned until it ships.

Found something?

Email security@tandera.io with steps to reproduce and we’ll acknowledge it. Our users test software for a living, so we’d rather hear it from you than not hear it. We do not run a paid bounty programme yet.

security@tandera.io
early access

Get Tandera before your next engagement.

Join the waitlist for early access. We are onboarding pentest teams in waves.

✓Priority onboarding for pentest teams.
✓A direct line to the people building it.
✓Early-access pricing, locked in.

No spam, no card. Unsubscribe anytime.

enespt-br