Security controls
The Security page describes the customer-facing safeguards for document intake, workspace access, evidence, activation, retention, and deletion.
Start with the maintained public policies, processor record, legal terms, and reporting contacts below. Deployment-specific architecture, control evidence, assurance scope, and questionnaire responses are provided through a qualified review. The published data processing agreement remains clearly labelled as a draft.
This page answers one question: what is published about security and document handling, and where to request a qualified review. How a citation stays bound to its source is on Evidence; what a result has to carry before it is published as a number is on Benchmarks; the frozen fixtures you can rerun are on Reproducibility; the open problems and the experiments that failed are on Research.
Customer names, figures and logos appear on this site only with that customer’s written sign-off on the exact wording.
The customer-facing safeguards for document intake, workspace access, evidence, activation, retention, and deletion.
What is collected, why it is processed, where it is stored, which processing happens outside Korea, and how to ask for access, export or deletion.
Every third-party service permitted to process account, document, billing or inquiry data, with the purpose and the data class for each one.
Public availability and incident notices for the service.
The agreement itself.
security@tavonel.com for a vulnerability, privacy@tavonel.com for a data request, and the inquiry form for a security review.
The machine-readable disclosure record: reporting address, policy and preferred languages, at the well-known path.
Draft v2 (2026-09-23) — under review; not a signed agreement. It states the breach-notification and sub-processor change commitments, the verified-request deletion right, and the qualifications that apply to legal retention duties and provider backups. The clauses still open say so in place.
The Security page describes the customer-facing safeguards for document intake, workspace access, evidence, activation, retention, and deletion.
The privacy notice explains the data categories, purposes, storage and transfer locations, retention, and verified access, export, and deletion requests.
The subprocessor record names the third parties permitted to process customer data, their purpose, the data class, and the applicable location information.
A draft v2 data processing agreement is published for review and is clearly labelled as a draft, not a signed agreement.
The reporting address and disclosure policy are published at the standard security.txt location.
Deployment-specific architecture, control evidence, assurance scope, and questionnaire responses are provided through an appropriate qualified review.
Every row below is already stated on the page it links to; this is the same record in the order a security review asks for it. 9 in place · 1 on the roadmap · 8 absent.
| What a reviewer asks for | State | What is true today |
|---|---|---|
| Encryption in transit | Provided | Traffic is encrypted in transit throughout. Security |
| Encryption at rest | Provided | Stored objects are encrypted at rest by the storage provider, and service credentials remain on trusted server boundaries. Security |
| Workspace isolation | Provided | Identity and workspace membership are resolved server-side, and data access is scoped to the authenticated workspace and rechecked at protected operations. Security |
| Subprocessor record | Provided | Every third party permitted to process account, document, billing or inquiry data is named with its purpose, the data class and the region it is configured to process in. Thirty days' notice of an addition or replacement, with an objection right, is written into the draft agreement. Subprocessors |
| Personal data breach notification | Provided | Without undue delay and no later than 72 hours after becoming aware, with the nature, the categories and volume affected, the likely consequences and the measures taken. The service is operated by one person without a 24-hour rota, which is why the committed window is 72 hours rather than shorter. Data processing agreement (draft) |
| Deletion on a verified request | Provided | On a verified deletion request, or on termination, the scope and outcome are confirmed in writing, and compiled worlds can be exported as signed packages first. A request may be limited or delayed by a legal hold or retention duty, and no fixed operational completion period is committed in the draft. Privacy notice |
| Restore drill | Provided | One drill is on record: on 2026-09-10 the production database was restored from its 2026-09-08 backup into a separate temporary project, the catalog of the original and the restored copy matched on all 431 objects, and the temporary project was deleted. It covered the database. It did not cover the document bytes in object storage, a full service recovery, or a run through the customer-facing application, and the receipt is available to a customer on request. Data processing agreement (draft) |
| Responsible disclosure | Provided | The reporting address, the policy and the preferred languages are published at the standard well-known path. security.txt |
| Architecture, control evidence and questionnaire responses | Provided | Deployment-specific architecture, control evidence, assurance scope and questionnaire responses are provided through a qualified review rather than published here. Contact |
| Signed data processing agreement | Roadmap | Draft v2 (2026-09-23) is published in full for review and is labelled as a draft, not a signed agreement. The clauses still open say so in place, and the standard contractual clauses are incorporated at signature. Data processing agreement (draft) |
| Customer-managed encryption keys | Not provided | Encryption at rest is the storage provider's. There is no customer-managed key. Data processing agreement (draft) |
| Roles, single sign-on and a seat model | Not provided | Access control is a workspace membership checked server-side on every request. The account that owns a workspace is the account that reaches it, and source-level access is enforced at the grain of the workspace rather than the member. Data processing agreement (draft) |
| Contractual data residency | Not provided | The database and the serverless functions are configured for Seoul and the object bucket carries an Asia-Pacific location hint, which is best-effort. One processor (RunPod) has no pinned region. Subprocessors |
| A stated retention period | Not provided | Material stays until you delete it, until the workspace is deleted, or until a legal retention duty applies. No day count is established, and copies in provider backups age out under the provider's lifecycle. Privacy notice |
| Recovery point and recovery time objectives | Not provided | No recovery point objective, no recovery time objective and no backup retention period is committed. Objectives and a drill cadence are marked for the executed version of the agreement. Data processing agreement (draft) |
| Contractual uptime or resolution target | Not provided | Published plans include no contractual availability or resolution commitment. The published support target is an acknowledgement target rather than a resolution time, and Enterprise support terms are agreed during scoping. Pricing |
| Third-party assurance report | Not provided | No SOC 2 report, ISO 27001 certificate or independent penetration-test report exists yet. An external penetration test is planned after the first paying customer; SOC 2 timing is not set. The draft agreement's audit right is a real right to inspect controls, not a report that already exists. Data processing agreement (draft) |
| Self-hosted, private-cloud or air-gapped installation | Not provided | There is one hosted deployment. No separate installation is offered on any scope. Pricing |
Each row points at the page that makes the statement, and that page is where the wording is maintained.