Data processing and security
Talaiz is built so a customer's data stays under their control. The connector runs inside the customer's network; only brokered tool calls and their audit records cross the boundary, and credentials never leave the connector's host. This page summarizes the commitments we make in a Data Processing Agreement (DPA).
Roles
For the managed cloud, the customer is the controller and Talaiz is the processor. For the self-hosted connector and gateway, the customer operates the software on their own infrastructure and Talaiz processes nothing.
What we process
- Control-plane data: organization, user, connector and agent metadata, policy, approvals and the audit log.
- Call content: the tool arguments and results brokered through the gateway, redacted by policy before storage.
- Operational data: access logs and metrics.
Security measures
- Encryption in transit (WSS/TLS); outbound-only tunnels with hashed tokens and API keys.
- Deny-by-default authorization, per-call audit and a tamper-evident hash chain.
- Redaction of sensitive fields before results are stored.
- Role-based access (owner/admin/member) and break-glass admin tokens.
Sub-processors
We use a small set of infrastructure and billing sub-processors (hosting, and Stripe for payments). The current list is available on request, and customers are notified before a new sub-processor is added.
Retention and deletion
Audit records are retained for the configured window and pruned under a signed checkpoint. On termination, control-plane data is deleted within 30 days and backups age out on the configured schedule.
Breach notification
We notify affected customers without undue delay and within 72 hours of becoming aware of a personal-data breach, with the information they need to meet their own obligations.
Request a DPA
Enterprise customers can execute a DPA and a security review. Get started and mention it, or contact us from the address on your account.
Not legal advice. This page summarizes our standard commitments; the executed DPA governs.