Snapshot 25992
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Start your security review View & download sensitive information Ask for information Overview Tembo’s platform helps engineering teams adopt AI coding agents they can trust. We believe the best way to earn trust is by being transparent and proving we do what we say. That’s why we take a security-first approach—from isolated sandboxes and self-hosted deployments to least-privilege access and continuous monitoring. This Trust Center provides artifacts showing how we walk the walk on security, compliance, and privacy. Reach out to [email protected] with any questions. Compliance SOC 2 Type 2 SOC 2 Type 1 GDPR HIPAA ISO/IEC 27001 ISO/IEC 42001:2023 Documents COMPLIANCEISO/IEC 27001 COMPLIANCEISO/IEC 42001:2023 COMPLIANCESOC 2 Type 1 COMPLIANCESOC 2 Type 2 Risk Profile We have secure, reliable hosting that customers can depend on. We are happy to provide details about our risk mitigation practices and recovery objectives upon request. Product Security We pay great attention to enterprise features such as access control and single sign on. We are happy to provide more details about our enterprise features upon request. Reports We may provide security-related reports upon request. Self-Assessments We are working on our security compliance. We can provide completed questionnaires upon request. Data Security We follow industry best practices for data security. We are happy to provide more details about our data security practices upon request. App Security We take application security seriously and are putting together a program to monitor internal apps. AI We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI. ESG We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes. Legal Subprocessors Privacy Policy Terms of Service Data Privacy Privacy of customer data is top of mind. We follow industry best practices and follow all applicable privacy regulations. Access Control Access is tightly monitored and controlled at our company. We are happy to provide more details about our access control practices upon request. Infrastructure We take great care to work with best-in-class infrastructure providers that provide secure computing and storage. We are happy to provide more details about our infrastructure upon request. Endpoint Security We follow industry best practices for endpoint security. We are happy to provide more details about our endpoint security practices upon request. Network Security We protect our corporate network against external & internal threats. Corporate Security We implement internal measures and practices to maintain a high standard of security. Policies We are currently working with experts to put together our company policies. Please contact us for more details. Security Grades We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available. Incident Response We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request. Risk Management We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request. Asset Management We have strict asset management policies in place to ensure that all assets are accounted for and secure. BC/DR We have a business continuity plan in place to ensure that we can continue to operate in the event of a disaster. Training We provide security awareness training to all employees to ensure that they are aware of security best practices. Change Management We have a change and configuration management process in place to ensure that changes are properly reviewed and approved. Physical & Environment We have physical and environmental controls in place to ensure that our data centers are secure and reliable. Continuous Monitoring We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request. Knowledge Base (FAQ) Do all users have unique IDs for access to production systems and data? Does Tembo maintain a risk management program, perform risk assessments, and track the treatment of those risks? Are there any web-facing application protection mechanisms? What is Tembo's tenancy model and how is customer data segregated? Will my data be transferred or shared with any third parties? View more Trust Center Updates May 2026 TanStack Mini Shai-Hulud Supply Chain Attack Assessment Incidents On May 11, 2026, TanStack disclosed an npm supply-chain incident tracked by Socket as part of the Mini Shai-Hulud campaign. The attacker published 84 malicious versions across 42 packages in the @tanstack/* namespace. Affected installations could harvest CI/CD, cloud, GitHub, npm, and SSH credentials and exfiltrate them through the Session/Oxen network. Tembo uses @tanstack/react-query and @tanstack/query-core, neither of which is included in TanStack’s official affected-package list. A review of Tembo’s available lockfiles found no affected package/version combinations, and no published indicators of compromise were found in the reviewed codebases. Based on this review, we have identified no exposure to this incident. Sources: Socket analysis and TanStack postmortem. If you need help using this Trust Center, please contact us. Contact support If you think you may have discovered a vulnerability, please send us a note. Report issue