Skip to main content
Tanqory IconTanqory Logo
Log In
Get Started
  • Home
  • Pricing
  • Partners
  • Themes
  • App Store
  • Academy
  • Affiliates
  • Community
  • Developers
  • Support
  • Business Tools
  • News
  • Research
  • Blog
  • Engineering
  • Legal
  • Status
  • Build & Launch
  • Sell & Get Paid
  • Market & Engage
  • Ship & Deliver
  • Operate & Control
  • Go Global
  • Platform Overview
  • Commerce Core
  • Builder
  • Creative & Brand
  • Intelligence & Automation
  • Operations
  • Integrations
  • E-commerce & Retail
  • Wholesale & B2B
  • Restaurants
  • Events & Ticketing
  • Health & Wellness
  • Services
  • About
  • Executive
  • Leadership
  • Governance
  • Brand Identity
  • Careers
  • Legal

TRUST CENTER

Certifications roadmap, not certificates yet

Tanqory is not currently certified against any external information-security or privacy framework. The following frameworks are tracked on our roadmap, with target windows defined by our internal security and compliance program and reviewed quarterly.

Email the Trust teamView subprocessors

Frameworks on the roadmap

Each entry mirrors our internal `04-security-controls.yaml` source of truth. Status, target windows, audit firm (when engaged), and scope notes update on a quarterly cycle.

FrameworkStatusTarget windowAudit firmNotes
SOC 2 Type 1RoadmapFY2026 H2Not engaged—
SOC 2 Type 2RoadmapFY2027 (12-month observation post Type 1)——
ISO/IEC 27001RoadmapFY2027Not engagedSeveral legal docs claim 'ISO 27001-aligned'. This is acceptable language ONLY if there is an internal ISMS doc + control mapping (currently partial).
ISO/IEC 27701Roadmap——Privacy extension of 27001; depends on 27001 first.
ISO/IEC 42001 (AI management)RoadmapFY2027—AI management system. AI-Act doc claims compliance — must downgrade to 'aligned' until ISMS exists. Public Trust Center wording: 'Tanqory is not certified against ISO/IEC 42001.'
PCI-DSS (SAQ-A)Self-assessment in progress——SAQ-A (Stripe.js client-side tokenization; no cardholder data in Tanqory infra)Not yet obtained from Stripe Connect Platform program

Source: internal security controls inventory, effective 2026-05-26 (v1). Reviewed quarterly.

What this means for you

Today, Tanqory's security posture is documented in this Trust Center and in the underlying compliance dataset rather than via a third-party attestation. Internally, the engineering team maintains a SOC 2 Type II control matrix mapping each Common Criteria (CC1 through CC7+) to its implementation and evidence references; a Disaster Recovery runbook with RTO 1 hour / RPO 1 hour / MTTR 30 minutes targets; and a PCI-DSS SAQ-A self-assessment based on Stripe.js client-side tokenization (no cardholder data on Tanqory infrastructure). Live drills against the DR runbook are scheduled, not yet executed. Enterprise prospects can request the control matrix, gap assessment, and roadmap walkthrough under NDA. Once external attestations land, this page becomes the canonical place where customers, auditors, and partners verify status and download reports. Certificates and reports will be linked here when issued.

Common questions about our certifications

Why isn't Tanqory certified yet?

Tanqory's external audit program is sequenced behind our internal control baseline. We are running a structured self-assessment first so that an external auditor walks into a mature control set rather than an in-flight one. Target windows on this page reflect when we expect attestations to be in hand, not when audits start. The certification roadmap is owned by the Security and Compliance team (security@tanqory.com).

Can I get a security questionnaire response today?

Yes. Enterprise customers and procurement teams can request a completed CAIQ / SIG-Lite / vendor questionnaire from trust@tanqory.com. We respond under NDA and reference the same internal source of truth that drives this Trust Center.

Will reports be available here once issued?

Yes. SOC 2 reports and ISO certificates will be linked from this page when issued, behind an authenticated request flow where the framework requires it (for example, SOC 2 Type 2 reports under NDA).

What is the PCI-DSS scope?

Tanqory does not store, process, or transmit cardholder data within Tanqory-controlled systems for the standard merchant flow. Card data is tokenized by our PCI-validated payment service providers. Our applicable scope is SAQ-A, which we self-attest annually and reconcile against acquirer Attestations of Compliance.

What is ISO 42001 and why is it on the roadmap?

ISO/IEC 42001 is the international standard for AI management systems. Because Tanqory uses AI features in commerce workflows (content generation, segmentation suggestions, etc.), we track ISO 42001 alongside the security and privacy frameworks rather than treating AI compliance as a separate program. Tanqory is not certified against ISO/IEC 42001; external certification is on the roadmap (target window: FY2027). Owner: Data Protection Officer with the AI lead and the Compliance team.

Need a security review or DPA?

Enterprise teams can request our security questionnaire, current DPA template, and a roadmap briefing from our Trust team.

Email the Trust team

Products

  • Builder
  • Commerce Core
  • Creative & Brand
  • Operations
  • Intelligence & Automation
  • Integrations

Solutions

  • Build & Launch
  • Sell & Get Paid
  • Market & Engage
  • Ship & Deliver
  • Operate & Control
  • Go Global

Industries

  • E-commerce & Retail
  • Wholesale & B2B
  • Restaurants & Café
  • Health & Wellness
  • Events & Ticketing
  • Services & Appointments

Company

  • About Us
  • Executive
  • Leadership
  • Governance
  • Brand Identity
  • System Status

Careers

  • About Us
  • Teams
  • Locations
  • Open Positions
  • Early Talent
  • How We Hire
  • Our Values
  • Life at Tanqory

Legal

  • Legal

Support

  • Help Center
  • Community Forum
  • Events

Developers

  • Developer Resources
  • API Documentation

Learn & Partners

  • Online Academy
  • Affiliates Program
  • Service Partners
  • Technology Partners

News

  • Company News
  • Global Affairs
  • Product Updates
  • Research
  • Safety
  • Security

Research

  • Publications
  • Projects
  • Datasets & Tools

Blog

  • Start & Build
  • Tech & AI
  • Sell & Market
  • Manage & Scale
  • SEO
  • Design & Inspire

Engineering

  • About Engineering
  • Blog Posts
  • Series
  • Events
  • Open Source

Business Essentials

  • Business Name Generator
  • Logo Maker
  • QR Code Generator
  • Barcode Generator

AI Visuals & Design

  • Color Palette Generator
  • Colors & Fonts
  • Product Mockup Generator
  • Stock Photography

Business Operations

  • Invoice Generator
  • Business Card Generator
  • Email Signature Generator
  • Gift Certificate Generator
  • Pay Stub Generator
  • Purchase Order
  • Bill of Lading

Financial Calculators

  • Profit Margin Calculator
  • ROI Calculator
  • Business Loan Calculator
  • Migration Estimator

Marketing & Content

  • Slogan Generator
  • Social Caption Generator
  • Email Subject Line Generator
  • Social Ad Generator

Legal

  • Legal Overview
  • Platform Policies
  • Trust & Security

Strategic Planning

  • Business Model Canvas

Themes

  • All Themes
  • Large Catalogs
  • Small Catalogs
  • Free Themes
  • Minimalist
  • Trending
  • New Themes
© 2024–2026 Tanqory
Terms of UsePrivacy Policy
  • Home
  • Pricing
  • Partners
  • Themes
  • App Store
  • Academy