Skip to main content
Tanqory IconTanqory Logo
Log In
Get Started
  • Home
  • Pricing
  • Partners
  • Themes
  • App Store
  • Academy
  • Affiliates
  • Community
  • Developers
  • Support
  • Business Tools
  • News
  • Research
  • Blog
  • Engineering
  • Legal
  • Status
  • Build & Launch
  • Sell & Get Paid
  • Market & Engage
  • Ship & Deliver
  • Operate & Control
  • Go Global
  • Platform Overview
  • Commerce Core
  • Builder
  • Creative & Brand
  • Intelligence & Automation
  • Operations
  • Integrations
  • E-commerce & Retail
  • Wholesale & B2B
  • Restaurants
  • Events & Ticketing
  • Health & Wellness
  • Services
  • About
  • Executive
  • Leadership
  • Governance
  • Brand Identity
  • Careers
  • Legal

TRUST CENTER

Layered security controls, by design

Tanqory operates a layered security program across application, infrastructure, and operational areas. Specific controls listed below are live today; controls under development are marked. Where a public commitment is made, the owning team is named.

Read Security OverviewReport a vulnerability

Four security pillars

These pillars summarise Tanqory's live security controls. Each maps to the corresponding section of the Security Overview document on the Legal Center. Each pillar is owned by a named operational team; controls under development are marked.

Encryption

TLS 1.2+ across all public endpoints, fronted by Cloudflare Universal SSL. Provider-managed AES-256 for managed databases and object storage. AES-256-GCM for application-layer secrets (TOTP, OAuth tokens, payment credentials). Owner: Engineering.

Identity & access

PS256 (RSA) JWT authentication issued by the central admin API and validated downstream by every service. Role-based access control. Multi-factor authentication via TOTP (with AES-256-GCM-encrypted secrets), SMS (Vonage), and one-time recovery codes. Session lifecycle managed with httpOnly refresh tokens and explicit invalidation. Self-hosted Infisical delivers secrets to Kubernetes via the Infisical secrets operator; production access is gated by least-privilege design. Operational status: least-privilege design in place; full enforcement audit on roadmap. Owner: Engineering. Access-review frequency: on roadmap.

Network & monitoring

Cloudflare WAF, API Shield, automatic DDoS protection, and rate limiting at the application gateway. Sentry receives application errors and performance traces across backend (NestJS), frontend (Next.js), and mobile (iOS, Android). Service status is published continuously at https://status.tanqory.com. Logs and alerting feed into on-call rotations for security-relevant events; a single queryable log store across all production services is on roadmap. Owner: Engineering on-call. Monitoring review frequency: continuous (alerting), with periodic on-call retros.

Vulnerability & disclosure

Dependency updates including security patches flow through Dependabot on a weekly Monday cadence to the development branch, with security-labelled PRs across admin-api, store-api, and other services. Administrative mutations are recorded by the activity-log and audit-timeline services in admin-api with actor, object, and timestamp. Coordinated disclosure runs under the Tanqory bug bounty policy. Quarterly review of the underlying security-controls source of truth (04-security-controls.yaml) drives this page. A published external patch SLA history is on roadmap. Owners: Security (vulnerability triage and bug bounty) + Engineering (patching). Review frequency: weekly (Dependabot) plus quarterly source-of-truth review.

Incident response, in summary

Tanqory operates a documented Incident Response plan covering detection, containment, eradication, recovery, and lessons-learned. Customer notification timelines are committed in our Data Processing Agreement and follow the applicable regulatory framework — GDPR's 72-hour breach notification window for personal-data incidents, faster for incidents that materially affect availability. The full plan, including severity tiers, on-call structure, and post-incident review cadence, is published in the Incident Response document on the Legal Center. Incident response is owned by the Security lead (security@tanqory.com) together with Engineering on-call. Breach notification to customers is owned by the Security lead with Legal review.

Read the IR plan(opens in a new window)Read the bug bounty policy(opens in a new window)

Common questions about our security program

Where do I report a vulnerability?

Email security@tanqory.com. Acknowledgement timelines, scope, rules of engagement, and reward tiers are defined in the Bug Bounty Policy on the Legal Center. We also publish a machine-readable contact at /.well-known/security.txt per RFC 9116. Bug bounty triage is owned by the Security team.

Do you offer a SOC 2 report?

Not yet. Tanqory's SOC 2 program is on the Certifications roadmap. Until a report is issued, enterprise prospects can review our internal control mapping and self-assessment evidence under NDA via trust@tanqory.com. The certification roadmap is owned by the Security and Compliance team.

How is access to production controlled?

Production access is gated by least-privilege design, with role-based access control and audit logging. Secrets are delivered via the self-hosted Infisical operator; no static long-lived credentials are embedded in deployment manifests. Operational status: least-privilege design in place; full enforcement audit (formal quarterly access reviews with retained evidence) is on the roadmap. Owner: Engineering, with Security oversight.

Do you publish a penetration-test report?

Penetration-test summaries are shared with enterprise customers under NDA. Detailed reports are not published openly — issuing detailed findings publicly is at odds with responsible disclosure for the vulnerabilities they describe. Penetration-test engagement is owned by the Security team.

What's the patching cadence?

Dependabot runs on a weekly Monday cadence across our services (admin-api, store-api, and others), opening security-labelled pull requests against the development branch where they are reviewed and merged through the standard CI pipeline. Critical and high CVEs receive prioritised review; a published external patch SLA history is on roadmap. CVE patching is owned jointly by Engineering and Security.

Is customer data used to train AI models?

No — Tanqory does not use customer-identifiable production data to train foundation models. Where Tanqory uses third-party AI subprocessors, workspace-level training opt-outs are elected wherever the upstream provider supports them. See the AI category on the Subprocessors page for the current list. AI provider review is owned by the Data Protection Officer together with the AI lead.

Need a security review?

Enterprise teams can request our completed security questionnaire, current DPA template, and a control-mapping briefing from our Trust team.

Email the Trust team

Products

  • Builder
  • Commerce Core
  • Creative & Brand
  • Operations
  • Intelligence & Automation
  • Integrations

Solutions

  • Build & Launch
  • Sell & Get Paid
  • Market & Engage
  • Ship & Deliver
  • Operate & Control
  • Go Global

Industries

  • E-commerce & Retail
  • Wholesale & B2B
  • Restaurants & Café
  • Health & Wellness
  • Events & Ticketing
  • Services & Appointments

Company

  • About Us
  • Executive
  • Leadership
  • Governance
  • Brand Identity
  • System Status

Careers

  • About Us
  • Teams
  • Locations
  • Open Positions
  • Early Talent
  • How We Hire
  • Our Values
  • Life at Tanqory

Legal

  • Legal

Support

  • Help Center
  • Community Forum
  • Events

Developers

  • Developer Resources
  • API Documentation

Learn & Partners

  • Online Academy
  • Affiliates Program
  • Service Partners
  • Technology Partners

News

  • Company News
  • Global Affairs
  • Product Updates
  • Research
  • Safety
  • Security

Research

  • Publications
  • Projects
  • Datasets & Tools

Blog

  • Start & Build
  • Tech & AI
  • Sell & Market
  • Manage & Scale
  • SEO
  • Design & Inspire

Engineering

  • About Engineering
  • Blog Posts
  • Series
  • Events
  • Open Source

Business Essentials

  • Business Name Generator
  • Logo Maker
  • QR Code Generator
  • Barcode Generator

AI Visuals & Design

  • Color Palette Generator
  • Colors & Fonts
  • Product Mockup Generator
  • Stock Photography

Business Operations

  • Invoice Generator
  • Business Card Generator
  • Email Signature Generator
  • Gift Certificate Generator
  • Pay Stub Generator
  • Purchase Order
  • Bill of Lading

Financial Calculators

  • Profit Margin Calculator
  • ROI Calculator
  • Business Loan Calculator
  • Migration Estimator

Marketing & Content

  • Slogan Generator
  • Social Caption Generator
  • Email Subject Line Generator
  • Social Ad Generator

Legal

  • Legal Overview
  • Platform Policies
  • Trust & Security

Strategic Planning

  • Business Model Canvas

Themes

  • All Themes
  • Large Catalogs
  • Small Catalogs
  • Free Themes
  • Minimalist
  • Trending
  • New Themes
© 2024–2026 Tanqory
Terms of UsePrivacy Policy
  • Home
  • Pricing
  • Partners
  • Themes
  • App Store
  • Academy