You are about to put your clients’ unpatched vulnerabilities in someone else’s system. That deserves specifics.
What is built is marked built. What is planned is marked planned.
Last reviewed August 2026
Every mutation is written to an append-only log in the same database transaction as the change itself. If the change committed, the audit row committed with it. Each row records:
actor · action · resource type · resource id · IP address · user agent · before state · after state · timestamp
Reports are built from scanner output and, if you use those features, from AI-assisted text. Both are untrusted input. Every piece of it is escaped before it reaches the renderer, and the renderer itself runs with no filesystem, no network and no package imports. A missed escape still cannot read a file or make a request.
The third parties involved in running Tandera, and what each one can see. Two of these only apply if you turn the feature on.
| Provider | What it does | What it can see |
|---|---|---|
| Amazon Web Services | Hosting, database, storage, encryption keys, transactional email | All application data |
| Clerk | Authentication and organisation membership | Names, email addresses, session and role |
| Stripe | Subscription billing through Stripe-hosted checkout | Billing contact and payment method. Card details go to Stripe directly and never touch Tandera |
| Anthropic | AI finding mapping and evidence assistance, only on the features that use it | The finding and evidence text submitted to those specific features |
| PostHog | Product and marketing analytics | Usage events and page views, not your findings |
| Atlassian Jira | Issue sync, only if you connect it | The findings you choose to push |
| Cloudflare | DNS and CDN for the public site | Public site traffic only |
Email security@tandera.io with steps to reproduce and we’ll acknowledge it. Our users test software for a living, so we’d rather hear it from you than not hear it. We do not run a paid bounty programme yet.
security@tandera.ioJoin the waitlist for early access. We are onboarding pentest teams in waves.
No spam, no card. Unsubscribe anytime.