# Security at Tandera

You are about to put your clients’ unpatched vulnerabilities in someone else’s system. That deserves specifics. What is built is marked built. What is planned is marked planned.

## Where your data lives

- **One region: AWS us-east-2** — US East, Ohio. Your data does not move between regions, because there is only one. If you need a different region, that is the BYOC conversation below.
- **The database has no public endpoint** — Postgres runs inside a private VPC. It is reachable from the API’s own functions and nothing else. There is no address on the internet to attack.
- **Evidence and uploads are encrypted in S3** — Screenshots, scanner output and credential files are stored with SSE-KMS against Tandera’s own customer-managed key.

## Encryption

- **In transit** — TLS on every connection, from your browser to the API and from the API to the database.
- **At rest** — Storage encryption is enabled on the database and on every bucket that holds your content.
- **Secrets get their own key** — Credential-vault entries, integration tokens and report passwords use envelope encryption with a per-record data key via AWS KMS. Automatic key rotation is on.
- **Deleting really deletes** — Removing a vault credential nulls its encrypted columns in the same statement that writes the tombstone. The ciphertext is gone, not flagged as hidden.

## Who can see what

- **Your org comes from the token, never the request** — The organisation id used to scope every query is read from the verified session token. A client cannot ask for another tenant’s data by changing a parameter.
- **Cross-tenant reads return “not found”** — Never “forbidden”. A wrong answer that confirms a record exists is still a leak, so the API does not confirm it.
- **Five roles, not one** — Admin, manager, reviewer, hacker and client. A tester does not need the permissions of an owner, and a client needs far fewer than either.
- **Clients see only what you publish** — The client role reaches the portal and the findings you have chosen to share there. It does not reach the engagement behind it.

## What we do not have yet

- **No SOC 2 and no ISO 27001** — We are not certified. If procurement requires a certification today, tell us and we’ll give you a straight answer on the timeline.
- **BYOC is designed, not deployed** — Running Tandera inside your own AWS account, with your S3, your database, your KMS key, your region and your CloudTrail, is planned for Enterprise. It is a design document right now. We will keep calling it planned until it ships.

## Found something?

Email security@tandera.io with steps to reproduce and we’ll acknowledge it. Our users test software for a living, so we’d rather hear it from you than not hear it. We do not run a paid bounty programme yet.

## More from Tandera

- [Tandera](https://tandera.io/): Pentest operations platform — scope to retest
- [About](https://tandera.io/about)
- [Attack chains](https://tandera.io/attack): Chain findings into attack narratives
- [Blog](https://tandera.io/blog)
- [Changelog](https://tandera.io/changelog)
- [Compare](https://tandera.io/compare)
- [Contact](https://tandera.io/contact)
- [Docs](https://tandera.io/docs)
- [Findings](https://tandera.io/findings): Consistent, reviewed vulnerability findings
- [Integrations](https://tandera.io/integrations): Every supported security tool, generated from the parser registry
- [Client portal](https://tandera.io/portal): Share results with clients
- [Privacy policy](https://tandera.io/privacy)
- [Recon](https://tandera.io/recon): Automated attack-surface discovery
- [Reports](https://tandera.io/reports): White-label pentest report generation
- [Solutions](https://tandera.io/solutions)
- [Terms](https://tandera.io/terms)
- [Tools](https://tandera.io/tools)

---

Canonical: https://tandera.io/security
This page as markdown: https://tandera.io/security.md
Index for agents: https://tandera.io/llms.txt

Every page here is also available as markdown: append `.md` to the path (e.g. `/recon.md`, `/index.md` for this homepage, `/blog/<slug>.md`), or request the canonical path with `Accept: text/markdown`.
