Informational

Security at Tagile

Security is central to how we build and run Tagile. This page describes our approach in plain language. It is informational and does not replace the contractual commitments in our Terms of Service and Data Processing Agreement.

Last updated: 22 July 2026  ·  Effective from: 22 July 2026  ·  Version 1.0

Security overview

We use safeguards appropriate to the nature of the service and the data processed. Security controls are reviewed as the product and the threat environment evolve, and we prioritise protecting the confidentiality and integrity of customer data in everything we build.

Infrastructure

Tagile runs on established cloud infrastructure (Google Cloud Platform), with the aim of processing and storing primary customer data within the EU.

Encryption

Data is encrypted in transit and at rest using industry standard encryption.

Authentication

Users sign in over encrypted connections, and we apply protections against common attacks such as brute force sign in attempts.

Access management and least privilege

Access to production systems is restricted to authorised personnel and follows the principle of least privilege: people and systems only get the access they need to do their job. Administrative access takes place over secure, logged connections.

Development practices

Changes to the product go through review before release, and we aim to keep dependencies up to date and to address security relevant issues with priority.

Logging and monitoring

We log security relevant events and monitor the platform to detect anomalies. Logs are handled with care so that they do not expose more customer data than necessary.

Backups and recovery

We maintain backup routines with the aim of enabling restoration of data in the event of loss.

Incident management

We have a documented incident management process covering detection, containment, investigation, recovery and customer communication. See the Incident Response page.

Vendor management

We assess service providers before engaging them and bind subprocessors to data protection obligations. The current list is on the Subprocessors page.

Customer responsibilities

Security is shared. Customers are responsible for keeping their credentials secure, assigning licences only to authorised users, reviewing AI generated content before use, and configuring integrations responsibly.

Reporting a vulnerability

If you believe you have found a security vulnerability in Tagile, please report it to security@tagile.ai. We appreciate responsible disclosure and will respond as quickly as we reasonably can. Please do not run penetration tests against the Service without written approval.

Security FAQ

Where is our data stored?

Primary customer data is stored on established cloud infrastructure, with the aim of keeping it within the EU.

Is our data encrypted?

Yes, in transit and at rest, using industry standard encryption.

Can Tagile staff read our data?

Not as part of daily operations. Access to production systems is restricted to authorised personnel, and access for support or troubleshooting is limited and logged.

How is our data protected when sent to AI providers?

Data is sent to AI providers over their business APIs for processing only. Our aim is that customer data is not used to train providers' public models; see Responsible AI for details.

Questions about this page?

Contact us at security@tagile.ai.