Tavrik

For security reviewers

Inside your network. Nothing inbound. Nothing stored that was not yours to keep.

Tavrik runs inside your network and makes only outbound connections, to the model providers you allow and to your own audit systems; there is no inbound path from the internet. Prompts and responses are not persisted; the audit record is categorical by construction.

The security posture Compliance posture →

What a review turns on

The audit chain

Every request, policy decision, redaction and administrative action is an append-only, hash-linked record, verifiable on demand over one event, a range, or the whole chain.

Credentials and keys

Three credential tiers, separated: tenant API keys, operator keys and browser-extension credentials. Provider keys are stored as ciphertext under a key-encryption key and decrypted in memory at the moment of a call; never shown again after upload.

Transport

Encrypted in transit, with mutual TLS where your systems support it; encrypted at rest. Data residency is a routing constraint, not a preference.

Sign-in

Operators sign in through your identity provider over OIDC or SAML. The root role cannot be reached that way.

Each of these is stated precisely, with what is and is not yet true, on the posture page. Read it in full →

Straight answers

Certification

We maintain control mappings for SOC 2, ISO 27001, HIPAA, the Australian Privacy Act and the EU AI Act. We do not yet hold a SOC 2 or ISO attestation; a SOC 2 Type I is in progress.

Reporting a vulnerability

Write to hello@tavrik.ai rather than testing it further. Reports are acknowledged within one business day.

Everything here

Every claim on this site is listed with its evidence in the repository, and the build fails if a number appears without one. Ask and we will demonstrate it live.