We hold ourselves to the same standard.
Security is the product. Here's how we run our own program — the frameworks we follow, the safeguards we operate, and how to ask us anything.
Built on the principles we ask of you.
Talarity's own security and privacy program follows the same disciplines we help our customers run. The principles we measure your program against are the principles we operate by.
Encryption at rest and in transit, layered access controls, anti-abuse on every callable. The same multi-layer thinking we help customers operationalize.
Access is granted by role, scoped tight, and audited continuously. No standing admin, no shared accounts. Identity is the perimeter.
Customer data flows are governed by the question 'should this happen?' before 'can it?' Data minimization, purpose limitation, and clear retention shape every design decision.
Our security and privacy program is reviewed regularly, validated against the disciplines we help our customers run, and improved as the threat landscape evolves.
Defense in depth.
TLS 1.3 in transit. AES-256 at rest. Customer-managed encryption keys via Google Cloud KMS are available under Enterprise Governance program terms.
SSO/SAML/OIDC, optional MFA enforcement, SCIM provisioning, App Check on every callable.
Three-layer RBAC: route registry, dispatcher, handler. Org-group feature gating. Least-privilege by default.
60+ event types, immutable, hash-chained. Available via UI export and API.
US-Central by default. Multi-region available on request.
Point-in-time PostgreSQL backups, daily Firestore exports, documented RTO/RPO targets.
No magic, no surprises.
Customer data isn't training data. Outputs are sourced. A human owns the final word.
We continuously refine the inputs, prompts, and guardrails we provide our AI features so outputs are sourced and every claim is traceable. AI assists — it never replaces — and we keep working to reduce hallucination as the technology matures.
The AI add-on module runs entirely on your own provider key, which you connect in Settings. Inference happens under your agreement with that provider and is billed to you directly — Talarity does not resell, meter, or mark up AI usage, and your data does not pass through an AI account of ours.
Customer data is never used to train models. We don't share data with our LLM providers beyond the inference call.
AI features can be disabled or scoped at the org level. Default-off for regulated tenants on request.
Who we share data with.
A current list of sub-processors is at /legal/sub-processors. We notify customers before changes.
View listCAIQ, SIG, or VSAQ on file.
Procurement working through standard security questionnaires? We respond within five business days under NDA.
Request our responseFound a vulnerability? Tell us.
We run a coordinated vulnerability disclosure program with safe-harbor protection for good-faith research. Report anonymously — no account required — and we'll work a fix on a 90-day disclosure window, notifying affected customers through our advisory channel.
Read the program details and safe-harbor terms, or email security@talarity.com.
Have a security question?
Email security@talarity.com or use the contact form. We answer within one business day.