Trust Center

Security and privacy are foundational to Tamloot

Tamloot is built for professionals who run on conversations — coaches, therapists, consultants, advisors, and the many others whose work depends on what happens in a 1-on-1. Those conversations are deeply personal, so security and privacy aren’t features we added — they shape every layer of the platform and every decision we make about your data.

Last updated: June 15, 2026Security contact: security@tamloot.cc

At a glance

AES-256 encryption at rest & in transitRow-Level tenant isolationGDPR-aligned · DPA on requestYour data never trains AI models
01

Compliance & certifications

Where we stand today on the standards that matter to the people who trust us with sensitive conversations.

SOC 2 Type IIn progress

An independent audit of our security controls is underway, with the Type I report expected soon.

SOC 2 Type IIPlanned

A Type II report covering the sustained operation of our controls will follow Type I.

ISO 27001In progress

We are building out our information security management system toward ISO 27001 certification.

GDPRAligned

We follow GDPR data-protection principles and provide a Data Processing Agreement (DPA) on request.

EncryptionAlways on

AES-256 at rest and TLS 1.2+ in transit protect your data everywhere it lives or moves.

Tenant isolationAlways on

PostgreSQL Row-Level Security guarantees each user can only ever access their own data.

SOC 2 and ISO 27001 are independent attestations. We will only describe ourselves as “certified” once the relevant report is issued by the auditing firm; until then these reflect work in progress.

02

How your data is handled

Every piece of data moves through a pipeline designed for confidentiality at every step:

  1. 1
    Session recordings are captured via our desktop app, Chrome extension, mobile app, or file upload, transmitted over TLS, and stored encrypted at rest (AES-256) with server-side encryption and versioning.
  2. 2
    Transcripts are generated by our speech-to-text provider and stored encrypted in our database.
  3. 3
    AI-generated notes (summaries, key themes, action items) are produced via enterprise API access configured so that your data is never used to train AI models.
  4. 4
    Data about the people you work with (names, contact details, session history) is stored with Row-Level Security so each user can only access their own data.
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Row-Level Security in our database ensures complete user isolation — your data is never accessible to other users.
03

Security controls

A selection of the technical and organizational controls that protect Tamloot, grouped by area.

Cryptographic protections

  • Encryption at rest (AES-256) on all databases and storage
  • Encryption in transit (TLS 1.2+) for all traffic
  • Server-side encryption (SSE-S3) on recording storage
  • Versioned, access-controlled object storage

Access & authentication

  • Role-based, least-privilege access to production systems
  • Server-side authorization on all admin actions (fail-closed)
  • Quarterly privileged-access reviews
  • Multi-factor authentication on administrative consoles

Tenant isolation

  • PostgreSQL Row-Level Security on all customer tables
  • Verified cross-user isolation testing
  • Locked-down privileged database functions

Change management

  • Protected main branch with pull-request-gated changes
  • Mandatory code review via CODEOWNERS
  • Release-tag controls for client distribution
  • Infrastructure as code with state locking

Vulnerability & threat management

  • Automated dependency scanning (Dependabot)
  • Static analysis on every pull request (Semgrep)
  • Secret scanning with push protection
  • Dynamic application security testing with remediation SLAs

Monitoring & logging

  • Append-only audit logging for sensitive actions
  • Centralized log retention for incident forensics
  • Webhook signature verification (HMAC-SHA256)
  • Security and availability alerting

Data handling & privacy

  • Documented data classification and retention
  • Data export and deletion on request
  • Maintained subprocessor inventory and disclosure
  • AI processing that excludes your data from model training

Availability & resilience

  • Documented backup and restore procedures
  • Disaster-recovery runbook and drills
  • Capacity and availability monitoring

Vendor management

  • Annual review of critical subprocessors
  • Data Processing Agreements with subprocessors
  • Reliance on subservice providers’ security controls

Governance & risk

  • Information security policy pack, reviewed annually
  • Risk register with named owners and review dates
  • Incident response, DR, and data-subject-request runbooks
04

Subprocessors

The following vendors process data on our behalf to deliver Tamloot.

We maintain Data Processing Agreements (DPAs) with our subprocessors, and can provide our own DPA to customers on request. Contact us at privacy@tamloot.cc to request one.

VendorPurposeData accessedDPA
SupabaseDatabase, authentication & storageAll application data (encrypted at rest)View
AWSAudio storage, compute & logsAudio files, computeView
AnthropicAI notes, meeting prep & copilotTranscripts (not used for model training)View
ElevenLabsSpeech-to-text transcriptionAudio recordingsView
VercelAPI & web hostingData in transitView
Recall.aiDesktop session recordingSession audio/videoView
HookdeckWebhook routingWebhook payloads (in transit)View
CloudflareDNS, CDN & edgeTraffic metadataView
GoogleAuthentication & calendarOAuth tokens, calendar eventsView
SentryError monitoringDiagnostics (PII-minimized)View
PostHogProduct analyticsUsage events (content masked)View
Lemon SqueezyPaymentsBilling metadata, emailView
ResendTransactional emailEmail addresses & contentView

Additional channels (such as Telegram or WhatsApp) only process data for users who explicitly connect them. Content you export to your own destinations (e.g. Google Docs) becomes a copy you control.

05

Documentation & resources

Security documentation is available to customers and prospects on request. Reach out and we’ll share what you need.

06

Data retention

Account data
Retained while your account is active and for 30 days after deletion for recovery.
People you work with & session data
Retained until you delete it or close your account.
Session recordings
Retained according to your account settings or until you delete them.
Usage logs
Retained for up to 12 months for security and analytics.
Audit logs
Retained on an append-only basis to support security investigations.

For complete details, see our Privacy Policy.

07

Incident response

We maintain a documented incident response process and breach notification procedure. In the event of a security incident affecting your data:

  • We will notify affected customers without undue delay once an incident is confirmed.
  • Our notification will describe the nature of the incident, the types of information involved, the steps we are taking, and recommendations for affected individuals.

To report a security concern or potential vulnerability, contact us at security@tamloot.cc.

Questions, a DPA, or our security documentation?

Have questions about our security posture, how we handle data, or how we protect the people you work with? Need a Data Processing Agreement or our security documentation? We’re here to help.