TarseekLegal Center
Developer docsSign in

Overview

  • Legal Center

Legal

  • Terms
  • API Terms
  • Usage Policy
  • Credits & Billing
  • Copyright
  • Promo Credits
  • Beta Terms

Privacy & Data

  • Privacy
  • Data Practices
  • Model Providers
  • DPA
  • Subprocessors
  • Cookies
  • Privacy Choices
  • Regional Privacy
  • Sensitive Data

Trust & Security

  • Security
  • Vulnerability Disclosure
  • AI Transparency
  • Law Enforcement

Business

  • Enterprise
  • SLA & Support

Future platform

  • Marketplace

Tarseek Legal Center

Security & Trust

Effective
September 2026
Last updated
September 2026
Version
1.0

This page describes Tarseek’s security and trust posture. Tarseek does not claim certifications it has not achieved.

1. Hosting

Tarseek’s production architecture is designed for a major cloud provider with restricted administrative access, private networking where appropriate, and separated environments.

2. Encryption

Public APIs and dashboards use TLS in transit. Databases and object storage use encryption at rest provided by the cloud platform.

3. API keys and secrets

Customer API Keys are stored hashed or equivalently protected at rest. Provider secrets are stored in a secrets manager, not in source control.

4. Authentication and access control

Account authentication, session protection, and least-privilege production access. Organization and admin surfaces use role-based access where those surfaces exist.

5. Network security

Firewalls, private networking where appropriate, DDoS protections offered by the cloud platform, and segmented environments.

6. Logs, retention, and data isolation

Security logs may be retained as needed. Customer API content should not appear in long-lived logs by default. Customer data is logically isolated by account. See Data Practices.

7. Backups

Infrastructure backups are encrypted. Restoration is tested as part of operations.

8. Abuse prevention

Rate limits, fraud review, AUP enforcement, and key suspension. See the Acceptable Use Policy.

9. Incident response

Tarseek investigates security incidents and notifies affected customers without undue delay when legally required. Personal-data incidents affecting processor-role data are also addressed in the DPA.

10. Vulnerability management

Dependency updates, patching, and intake via the Vulnerability Disclosure Policy. No public bug bounty is offered unless Tarseek later publishes one.

11. Compliance claims

The following are not claimed unless independently achieved and then stated with a date and scope:

  • SOC 2
  • ISO 27001
  • HIPAA
  • PCI DSS (card data is handled by a payment processor; that is not the same as Tarseek being PCI certified)

Related policies

  • Vulnerability Disclosure Policy
  • Privacy Policy
  • Subprocessor List
  • Data Processing Addendum

Version history

This is the current published version. Prior versions will be retained at stable URLs rather than silently overwritten.

Contact

Questions about this document: hello@tarseek.com. General inquiries: hello@tarseek.com.

PreviousSensitive DataNextVulnerability Disclosure

On this page

    Legal

    • Terms
    • Privacy
    • Usage Policy
    • Credits & Billing
    • Legal Center

    Trust

    • Data Practices
    • Security
    • Model Providers
    • Subprocessors

    Policies and legal documents for Tarseek. See the Legal Center for the complete index.