Tazzie Trust Center

Live, verifiable proof of how this platform operates. We publish what is true today: implemented controls, live telemetry, and an honest status for external audits.

Live capability — straight from the runtime

Security controls

  • Multi-factor authentication

    Implemented

    TOTP-based MFA on every account (setup, confirm, disable flows in the account API).

  • Session management

    Implemented

    Device-based sessions with revocation and rotation; users can list and revoke sessions themselves.

  • Encryption

    Implemented

    TLS 1.3 in transit; D1 at-rest encryption; secrets restricted to VS Code SecretStorage and server-side key stores.

  • Rate limiting

    Implemented

    Per-user, per-category throttling (15-minute windows) on AI endpoints.

  • Audit logging

    Implemented

    Auth events, AI usage, and tool runs recorded with immutable ids in D1 (ai_usage, agent_sessions).

  • Tenant isolation

    Implemented

    Per-user sandbox Durable Objects; per-tenant D1 row scoping on every query; fail-closed permission gates.

  • Permission gating

    Implemented

    Deny-by-default tool permissions enforced on both client and worker (parity-tested).

  • Change safety

    Implemented

    Guarded, confirmable patch application with checkpoints and rollback in the operator's editor.

  • External SOC 2 audit

    In progress

    Controls are implemented and evidenced in-repo. The independent auditor engagement is scheduled; the report will be published here the day it exists — never before.

Questions or a security review request? Contact us via the console →