generated: '2026-08-29' method: searched source: https://docs.tailor.tech/reference/security name: Tailor trust and compliance posture description: >- Tailor does not operate a dedicated trust-center subdomain — trust.tailor.tech and security.tailor.tech resolve only through a wildcard record and return a Fastly default body, not a trust page. The company's compliance posture is published inside the developer documentation instead, on docs.tailor.tech/reference/security, which names SOC 2 as its compliance framework. trust_page: url: https://docs.tailor.tech/reference/security status: 200 dedicated_subdomain: false subdomain_probes: - url: https://trust.tailor.tech/ status: 200 note: Wildcard *.tailor.tech record answering with a Fastly default body ("index.html"), not a trust center. - url: https://security.tailor.tech/ status: 200 note: Wildcard *.tailor.tech record answering with a Fastly default body ("index.html"), not a security page. certifications: - name: SOC 2 authority: AICPA status: claimed evidence: >- "Tailor complies with SOC2, which is a compliance framework by the American Institute of Certified Public Accountants' (AICPA). Potential customers can reach out to us for more information." — https://docs.tailor.tech/reference/security report_access: on request (sales gate — no self-serve report portal or NDA workflow published) corroboration: >- Vanta publishes a customer story describing Tailor achieving SOC 2 in 2.5 months — https://www.vanta.com/customers/tailor (third-party, not used as the primary claim). - name: ISO 27001 status: not-claimed - name: PCI DSS status: not-claimed - name: HIPAA status: not-claimed - name: FedRAMP status: not-claimed security_controls: encryption_at_rest: AES-256 encryption_in_transit: TLS access_control: RBAC with automatic deprovisioning on termination network: segmentation, firewalls, intrusion detection endpoint: MDM-enforced disk encryption, screen lock, patching; 24/7/365 alert monitoring third_party_assessments: yes ip_allowlisting: CIDR allowlists at organization, folder or application level data_residency: regional cloud deployment (asia-northeast, us-west) data_retention: source: https://docs.tailor.tech/administration/data-retention periods: - data_type: Jobs and attempts (Executor) retention: 30 days - data_type: Executions (Function service) retention: 30 days - data_type: Resolver execution results retention: 30 days - data_type: Dataplane events retention: 3 days - data_type: Controlplane activity logs retention: 90 days note: After the retention period the data is permanently deleted and cannot be recovered. x-evidence: fetched: '2026-08-29' probes: - url: https://docs.tailor.tech/reference/security.md status: 200 - url: https://docs.tailor.tech/administration/data-retention.md status: 200 - url: https://trust.tailor.tech/ status: 200