Security information
How Tangle protects its services
This page describes the security practices currently used for Tangle-operated services. It is not a certification statement or a guarantee of uninterrupted security.
Access and identity
Production administration is restricted to authorized personnel. Administrative access uses multi-factor authentication where the provider supports it, and production Linux hosts do not accept SSH password authentication. Tangle periodically reviews administrative access to its cloud, source-control, and collaboration systems.
Infrastructure and data protection
Public services use TLS in transit. Production database data and off-host backups are encrypted at rest. Backups run on scheduled jobs with retention rules, and restoration tests verify that backed-up database data can be read in an isolated environment.
Application security
Tangle uses source-control review, automated dependency monitoring, and vulnerability remediation workflows for its maintained repositories. Authentication endpoints enforce rate limits, and administrative actions are recorded in application audit logs.
Monitoring and incident response
Tangle collects application, database, operating-system, and edge-provider audit data. Security-relevant alerts and incidents are investigated according to the company incident-response process. Public service checks are published on the status page.
Report a vulnerability
To report a suspected vulnerability, email [email protected]. Do not include credentials or sensitive customer data in the initial report. We will acknowledge the report and coordinate a safe remediation path.
Related documents
See the Privacy Policy, Terms of Service, and sub-processor list for the public terms that govern use of Tangle services.