Tazzie Trust Center
Live, verifiable proof of how this platform operates. We publish what is true today: implemented controls, live telemetry, and an honest status for external audits.
Live capability — straight from the runtime
Security controls
Multi-factor authentication
ImplementedTOTP-based MFA on every account (setup, confirm, disable flows in the account API).
Session management
ImplementedDevice-based sessions with revocation and rotation; users can list and revoke sessions themselves.
Encryption
ImplementedTLS 1.3 in transit; D1 at-rest encryption; secrets restricted to VS Code SecretStorage and server-side key stores.
Rate limiting
ImplementedPer-user, per-category throttling (15-minute windows) on AI endpoints.
Audit logging
ImplementedAuth events, AI usage, and tool runs recorded with immutable ids in D1 (ai_usage, agent_sessions).
Tenant isolation
ImplementedPer-user sandbox Durable Objects; per-tenant D1 row scoping on every query; fail-closed permission gates.
Permission gating
ImplementedDeny-by-default tool permissions enforced on both client and worker (parity-tested).
Change safety
ImplementedGuarded, confirmable patch application with checkpoints and rollback in the operator's editor.
External SOC 2 audit
In progressControls are implemented and evidenced in-repo. The independent auditor engagement is scheduled; the report will be published here the day it exists — never before.
Questions or a security review request? Contact us via the console →