TRUST CENTER
Security, privacy, and compliance — documented
Tanqory operates a regional commerce platform built for enterprise scrutiny. This portal publishes our security posture, privacy program, certification roadmap, subprocessor registry, and global infrastructure footprint.
Lenses on Tanqory trust
Every Trust Center page is sourced directly from the same internal compliance dataset our auditors review. No marketing copy in the data tables — only the source of truth.
Certifications
Tanqory's external certification roadmap across SOC 2, ISO 27001, ISO 27701, ISO 42001, and PCI-DSS scope.
Subprocessors
The canonical list of third parties that process customer personal data on Tanqory's behalf, with purpose, location, and transfer mechanism.
Regions
The regional deployment footprint across DigitalOcean, Google Cloud, and Amazon Web Services, designed for four business regions.
Security
Overview of Tanqory's security controls, vulnerability program, incident response posture, and coordinated disclosure policy.
Privacy
Privacy program hub: privacy policy, DSAR contact, cookie policy, and international transfer mechanisms.
Technology
Tanqory's technical stack: NestJS backend, Next.js 16 + React 19 web, native iOS/Android, and an infrastructure footprint designed for multi-cloud, multi-region deployment.
AI Governance
AI providers in use, default training opt-outs, on-device vs cloud deployment, and EU AI Act / ISO 42001 design posture (Tanqory is not certified against ISO/IEC 42001).
Bug Bounty
Researcher-facing summary of the Tanqory bug bounty: scope, reward tiers, how to submit, safe harbor, and responsible disclosure.
security.txt
Machine-readable security contact and disclosure policy per RFC 9116.
Status
Live operational status and incident history for the Tanqory platform, hosted on Atlassian Statuspage.
Certification roadmap
View certificationsTanqory is not yet certified against any external framework. The following frameworks are tracked on our roadmap with target windows defined by our internal security and compliance program. Status is reviewed quarterly and reflects the current state of the underlying YAML source of truth.
- Roadmap
SOC 2 Type 1
Target: FY2026 H2
- Roadmap
SOC 2 Type 2
Target: FY2027 (12-month observation post Type 1)
- Roadmap
ISO/IEC 27001
Target: FY2027
- Roadmap
ISO/IEC 27701
- Roadmap
ISO/IEC 42001
Target: FY2027
- Self-assessment in progress
PCI-DSS (SAQ-A)
Need a security review or DPA?
Enterprise teams can request our security questionnaire, current DPA template, and a roadmap briefing from our Trust team.
Email the Trust team