Security Policy
Effective Date: July 23, 2026
Last Updated: July 23, 2026
Index
- Overview
- Infrastructure Security
- Authentication
- Access Control
- Encryption
- Monitoring
- Backups
- Incident Response
- Vulnerability Management
- Responsible Disclosure
- Customer Responsibilities
- Security Updates
1. Overview
Security is an important part of how we design, build, and operate our Services.
We use administrative, technical, and organizational measures intended to protect customer information and maintain the confidentiality, integrity, and availability of our Services.
No security program can eliminate every risk. We continuously improve our practices as our products and infrastructure evolve.
2. Infrastructure Security
We use modern cloud infrastructure and security controls appropriate for the Services we provide.
These measures may include:
-
Encryption in transit using HTTPS/TLS
-
Encryption at rest where appropriate
-
Firewalls and network isolation
-
Private infrastructure components
-
Automated infrastructure provisioning
-
Security monitoring
Infrastructure providers maintain responsibility for the physical security of their facilities.
3. Authentication
We implement controls intended to protect customer accounts, including:
-
Secure password storage
-
Multi-factor authentication where supported
-
Session management
-
Access logging
-
Account recovery procedures
Users are responsible for protecting their own credentials.
4. Access Control
Access to production systems is restricted based on business need.
Access is granted using the principle of least privilege and is reviewed periodically.
Administrative actions may be logged for auditing and operational purposes.
5. Encryption
Where appropriate, we use industry-standard encryption technologies to protect customer data.
Examples include:
-
TLS for data in transit
-
Encryption for stored data where supported
-
Secure credential storage
-
Secret management systems
6. Monitoring
We monitor our infrastructure to help detect:
-
Service failures
-
Security events
-
Abuse
-
Unauthorized access attempts
-
Infrastructure health issues
Monitoring data may include logs, metrics, traces, and audit records.
7. Backups
Where appropriate, we maintain backups intended to support recovery from operational failures.
Backup frequency and retention may vary depending on the Service.
Backups are intended for disaster recovery and should not be considered a substitute for customer-managed backups where applicable.
8. Incident Response
If we become aware of a security incident affecting customer data, we will:
-
Investigate the incident
-
Contain the impact where reasonably possible
-
Restore affected services
-
Notify affected customers where required by law
-
Implement measures intended to reduce the likelihood of recurrence
9. Vulnerability Management
We regularly:
-
Apply software updates
-
Review dependencies
-
Address known security issues
-
Improve security controls
Critical vulnerabilities are prioritized for remediation.
10. Responsible Disclosure
If you believe you have discovered a security vulnerability, please report it responsibly.
Please include:
-
A description of the issue
-
Steps to reproduce
-
Proof of concept where appropriate
-
Contact information
Do not publicly disclose vulnerabilities until we have had a reasonable opportunity to investigate and address them.
Security reports may be sent to:
Email: security@tenderez.com
11. Customer Responsibilities
Customers are responsible for:
-
Protecting account credentials
-
Using strong passwords
-
Enabling multi-factor authentication where available
-
Keeping devices secure
-
Reviewing generated or uploaded content before sharing
-
Complying with applicable laws
12. Security Updates
Security practices evolve over time.
We may update this Security Policy to reflect improvements to our infrastructure, processes, or legal obligations.