Security information

How Tangle protects its services

This page describes the security practices currently used for Tangle-operated services. It is not a certification statement or a guarantee of uninterrupted security.

Access and identity

Production administration is restricted to authorized personnel. Administrative access uses multi-factor authentication where the provider supports it, and production Linux hosts do not accept SSH password authentication. Tangle periodically reviews administrative access to its cloud, source-control, and collaboration systems.

Infrastructure and data protection

Public services use TLS in transit. Production database data and off-host backups are encrypted at rest. Backups run on scheduled jobs with retention rules, and restoration tests verify that backed-up database data can be read in an isolated environment.

Application security

Tangle uses source-control review, automated dependency monitoring, and vulnerability remediation workflows for its maintained repositories. Authentication endpoints enforce rate limits, and administrative actions are recorded in application audit logs.

Monitoring and incident response

Tangle collects application, database, operating-system, and edge-provider audit data. Security-relevant alerts and incidents are investigated according to the company incident-response process. Public service checks are published on the status page.

Report a vulnerability

To report a suspected vulnerability, email [email protected]. Do not include credentials or sensitive customer data in the initial report. We will acknowledge the report and coordinate a safe remediation path.

Related documents

See the Privacy Policy, Terms of Service, and sub-processor list for the public terms that govern use of Tangle services.