MENUCLOSE
Security
A control plane your CISO can sign off on.
Tallin is the runtime control plane for AI use by humans, apps, and agents. Built for financial services and other regulated teams that need to own every AI actor, cap runaway agent spend, govern model access, prove it with honest evidence, and keep strong customer data boundaries around provider credentials.

Honest security boundary
Security starts with knowing what is and is not covered.
Tallin makes its security boundary visible. The coverage view separates direct evidence, inference, enforced controls, and uncovered activity, then shows the health and recency of the sources supporting each conclusion.
- Name the evidence sourceKeep provider, browser, identity, gateway, network, and expense signals distinct.
- Expose stale or missing telemetryShow source health and recency before a claim is trusted.
- Prove where controls applySeparate Tallin-enforced paths from activity it can only observe.
Certifications & audits
Honest trust signals, without pretending the program is older than it is.
- SOC 2 Type I
- In progressTargeting Q3 2026 with an independent audit firm. Current controls are being mapped to the trust services criteria now.
- External penetration test
- PlannedScheduled after the pilot cohort. Timing is still TBD, and the resulting executive summary will be available under NDA.
- Vulnerability disclosure
- Open channelSend reports to security@gettallin.com. PGP support is optional and will be published when a public key is available.
Data handling
Built around customer data boundaries and auditable access.
Tallin handles provider credentials, per-actor spend, model-scope policy, and audit evidence with conservative defaults for regulated operators.
Hosted is the fastest path to central control. For banks, hospitals, and regulated teams that need data to stay put, the gateway can run in your own VPC, so prompts and content stay resident inside your network and policy is enforced where the traffic lives.
Sub-processors
The vendors behind the service.
Tallin keeps this list plain so security, compliance, and procurement teams can review what each vendor is used for.
| Vendor | Purpose | Data accessed | Region |
|---|---|---|---|
| Amazon Web Services | Tallin-hosted supervision vault and capture runtime | Supervised AI records only when Tallin-hosted supervision is selected | Customer-selected hosted region |
| Vercel | Hosting and serverless functions | Application traffic and serverless runtime data | US primary |
| WorkOS | Enterprise SSO and directory integration | User identity, organization, and authentication metadata when enabled | US |
| Neon (Postgres) | Primary database | Customer data at rest | US |
| Resend | Transactional email | Email addresses and message content | US |
| Stripe | Billing and payments | Billing details only | US |
| Anthropic | AI API for in-product summaries and drafting | Governance metadata and prompts only when an AI feature is used | US |
| OpenAI | AI API fallback for in-product summaries and drafting | Governance metadata and prompts only when an AI feature is used | US |
Compliance documents
Review the legal baseline.
Reporting a vulnerability
Security reports go directly to the founder.
Send vulnerability reports to security@gettallin.com. Tallin acknowledges reports within 2 business days, honors the scope of disclosure, and will not pursue legal action against good-faith researchers acting within that scope.