Trust Center

Last updated: June 15, 2026

Security and privacy are foundational to Tamloot

Tamloot is built for professionals who run on conversations — coaches, therapists, consultants, advisors, and the many others whose work depends on what happens in a 1-on-1. Those conversations are deeply personal, so security and privacy aren’t features we added — they shape every layer of the platform and every decision we make about your data.

Security contact: security@tamloot.cc

Compliance & certifications

Where we stand today on the standards that matter to the people who trust us with sensitive conversations.

SOC 2 Type IIn progress

An independent audit of our security controls is underway, with the Type I report expected soon.

SOC 2 Type IIPlanned

A Type II report covering the sustained operation of our controls will follow Type I.

ISO 27001In progress

We are building out our information security management system toward ISO 27001 certification.

GDPRAligned

We follow GDPR data-protection principles and provide a Data Processing Agreement (DPA) on request.

EncryptionAlways on

AES-256 at rest and TLS 1.2+ in transit protect your data everywhere it lives or moves.

Tenant isolationAlways on

PostgreSQL Row-Level Security guarantees each user can only ever access their own data.

SOC 2 and ISO 27001 are independent attestations. We will only describe ourselves as “certified” once the relevant report is issued by the auditing firm; until then these reflect work in progress.

How your data is handled

Every piece of data moves through a pipeline designed for confidentiality at every step:

  • Session recordings are captured via our desktop app, Chrome extension, mobile app, or file upload, transmitted over TLS, and stored encrypted at rest (AES-256) with server-side encryption and versioning.
  • Transcripts are generated by our speech-to-text provider and stored encrypted in our database.
  • AI-generated notes (summaries, key themes, action items) are produced via enterprise API access configured so that your data is never used to train AI models.
  • Data about the people you work with (names, contact details, session history) is stored with Row-Level Security so each user can only access their own data.

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Row-Level Security in our database ensures complete user isolation — your data is never accessible to other users.

Security controls

A selection of the technical and organizational controls that protect Tamloot, grouped by area.

Cryptographic protections

  • Encryption at rest (AES-256) on all databases and storage
  • Encryption in transit (TLS 1.2+) for all traffic
  • Server-side encryption (SSE-S3) on recording storage
  • Versioned, access-controlled object storage

Access & authentication

  • Role-based, least-privilege access to production systems
  • Server-side authorization on all admin actions (fail-closed)
  • Quarterly privileged-access reviews
  • Multi-factor authentication on administrative consoles

Tenant isolation

  • PostgreSQL Row-Level Security on all customer tables
  • Verified cross-user isolation testing
  • Locked-down privileged database functions

Change management

  • Protected main branch with pull-request-gated changes
  • Mandatory code review via CODEOWNERS
  • Release-tag controls for client distribution
  • Infrastructure as code with state locking

Vulnerability & threat management

  • Automated dependency scanning (Dependabot)
  • Static analysis on every pull request (Semgrep)
  • Secret scanning with push protection
  • Dynamic application security testing with remediation SLAs

Monitoring & logging

  • Append-only audit logging for sensitive actions
  • Centralized log retention for incident forensics
  • Webhook signature verification (HMAC-SHA256)
  • Security and availability alerting

Data handling & privacy

  • Documented data classification and retention
  • Data export and deletion on request
  • Maintained subprocessor inventory and disclosure
  • AI processing that excludes your data from model training

Availability & resilience

  • Documented backup and restore procedures
  • Disaster-recovery runbook and drills
  • Capacity and availability monitoring

Vendor management

  • Annual review of critical subprocessors
  • Data Processing Agreements with subprocessors
  • Reliance on subservice providers’ security controls

Governance & risk

  • Information security policy pack, reviewed annually
  • Risk register with named owners and review dates
  • Incident response, DR, and data-subject-request runbooks

Subprocessors

The following vendors process data on our behalf to deliver Tamloot.

We maintain Data Processing Agreements (DPAs) with our subprocessors, and can provide our own DPA to customers on request. Contact us at privacy@tamloot.cc to request one.

VendorPurposeData accessedRegion
SupabaseDatabase, authentication & storageAll application data (encrypted at rest)Tokyo (ap-northeast-1)
AWSAudio storage, compute & logsAudio files, computeFrankfurt (eu-central-1)
AnthropicAI notes, meeting prep & copilotTranscripts (not used for model training)United States
ElevenLabsSpeech-to-text transcriptionAudio recordingsUnited States
VercelAPI & web hostingData in transitUnited States
Recall.aiDesktop session recordingSession audio/videoUnited States
HookdeckWebhook routingWebhook payloads (in transit)Vendor-managed
CloudflareDNS, CDN & edgeTraffic metadataGlobal edge
GoogleAuthentication & calendarOAuth tokens, calendar eventsVendor-managed
SentryError monitoringDiagnostics (PII-minimized)Vendor-managed
PostHogProduct analyticsUsage events (content masked)United States
Lemon SqueezyPaymentsBilling metadata, emailUnited States
ResendTransactional emailEmail addresses & contentVendor-managed

Additional channels (such as Telegram or WhatsApp) only process data for users who explicitly connect them. Content you export to your own destinations (e.g. Google Docs) becomes a copy you control.

Documentation & resources

Security documentation is available to customers and prospects on request. Reach out and we’ll share what you need.

Information Security Policy
Request
Access Control Policy
Request
Data Classification & Retention Policy
Request
Encryption Policy
Request
Incident Response Policy
Request
Business Continuity & DR Policy
Request
Vendor Management Policy
Request
Data Processing Agreement (DPA)
Request
Subprocessor list
Request
SOC 2 Type I reportavailable once issued
Request

Data retention

  • Account dataRetained while your account is active and for 30 days after deletion for recovery.
  • People you work with & session dataRetained until you delete it or close your account.
  • Session recordingsRetained according to your account settings or until you delete them.
  • Usage logsRetained for up to 12 months for security and analytics.
  • Audit logsRetained on an append-only basis to support security investigations.

For complete details, see our Privacy Policy.

Incident response

We maintain a documented incident response process and breach notification procedure. In the event of a security incident affecting your data:

  • We will notify affected customers without undue delay once an incident is confirmed.
  • Our notification will describe the nature of the incident, the types of information involved, the steps we are taking, and recommendations for affected individuals.

To report a security concern or potential vulnerability, contact us at security@tamloot.cc.

Questions, a DPA, or our security documentation?

Have questions about our security posture, how we handle data, or how we protect the people you work with? Need a Data Processing Agreement or our security documentation? We’re here to help.

security@tamloot.cc