Tarseek Legal Center
Security & Trust
This page describes Tarseek’s security and trust posture. Tarseek does not claim certifications it has not achieved.
1. Hosting
Tarseek’s production architecture is designed for a major cloud provider with restricted administrative access, private networking where appropriate, and separated environments.
2. Encryption
Public APIs and dashboards use TLS in transit. Databases and object storage use encryption at rest provided by the cloud platform.
3. API keys and secrets
Customer API Keys are stored hashed or equivalently protected at rest. Provider secrets are stored in a secrets manager, not in source control.
4. Authentication and access control
Account authentication, session protection, and least-privilege production access. Organization and admin surfaces use role-based access where those surfaces exist.
5. Network security
Firewalls, private networking where appropriate, DDoS protections offered by the cloud platform, and segmented environments.
6. Logs, retention, and data isolation
Security logs may be retained as needed. Customer API content should not appear in long-lived logs by default. Customer data is logically isolated by account. See Data Practices.
7. Backups
Infrastructure backups are encrypted. Restoration is tested as part of operations.
8. Abuse prevention
Rate limits, fraud review, AUP enforcement, and key suspension. See the Acceptable Use Policy.
9. Incident response
Tarseek investigates security incidents and notifies affected customers without undue delay when legally required. Personal-data incidents affecting processor-role data are also addressed in the DPA.
10. Vulnerability management
Dependency updates, patching, and intake via the Vulnerability Disclosure Policy. No public bug bounty is offered unless Tarseek later publishes one.
11. Compliance claims
The following are not claimed unless independently achieved and then stated with a date and scope:
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS (card data is handled by a payment processor; that is not the same as Tarseek being PCI certified)
Version history
This is the current published version. Prior versions will be retained at stable URLs rather than silently overwritten.
Contact
Questions about this document: hello@tarseek.com. General inquiries: hello@tarseek.com.
