Third Party Index

Snapshot 26002

Document
Security advisories
URL
https://www.tembo.io/privacy/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
118701 bytes
SHA-256 (raw)
6caf214424f75cd6c03f7aa1fe0826ab1e86136416f224e45d3e8066d64f3461
SHA-256 (normalized text)
679107e8c5a35d0c171d8706ad85919de306171c2e944b8f05e91f0531bc7921

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Keeping your database environment and source code secure is critically important to us. This page outlines how we approach security for Tembo. Please submit potential vulnerabilities and security-related questions to [email protected]. Please note that we are still in the journey of growing our product and improving our security posture.
1. Certifications and Third-Party Assessments
Tembo has a SOC 2 Type II report. Please email [email protected] to request a copy of the report.
We commit to doing at-least-annual penetration testing by reputable third parties. Please email [email protected] to request an executive summary of the latest report.
2. Infrastructure Security
We depend on subprocessors to provide our services. Our current subprocessors, including their purposes, the data they process, and their locations, are described in our List of Subprocessors.
None of our infrastructure is in China. We do not directly use any Chinese company as a subprocessor, and to our knowledge none of our subprocessors do either.
We assign infrastructure access to team members on a least-privilege basis. We enforce multi-factor authentication for AWS. We restrict access to resources using both network-level controls and secrets.
3. AI Requests
To provide its features, Tembo makes AI requests to our server. This happens for many different reasons. For example, we send AI requests when you ask questions in chat, and we also send AI requests in the background for building up context or looking for issues to show you.
An AI request generally includes context such as your recently viewed files, your conversation history, and relevant pieces of code based on language server information. This code data is sent to our infrastructure on AWS, and then to the appropriate language model inference provider. Note that the requests always hit our infrastructure on AWS even if you have configured your own API key in the settings.
We currently do not have the ability to direct-route from Tembo to your enterprise deployment of OpenAI/Azure/Anthropic. We may be able to provide a self-hosted server deployment option.
You own all the code generated by Tembo.
4. Account Deletion
You can delete your account at any time in the Settings dashboard(click "Advanced" and then "Delete Account"). This will delete all data associated with your account. We guarantee complete removal of your data within 30 days (we immediately delete the data, but some of our databases and cloud storage have backups of no more than 30 days).
It's worth noting that if any of your data was used in model training (which would only happen if you were not on privacy mode at the time), our existing trained models will not be immediately retrained. However, any future models that are trained will not be trained on your data, since that data will have been deleted.
5. Vulnerability Disclosures
If you believe you have found a vulnerability in Tembo, please email [email protected].
We commit to acknowledging vulnerability reports within 5 business days, and addressing them as soon as we are able to. We will publish the results in the form of security advisories on our GitHub security page. Critical incidents will be communicated both on the GitHub security page and via email to all users.
Product
Cloud AgentsTembo ReviewAutomationsIntegrationsSandboxAgent Templates
Use Cases
Automated Code ReviewCode MigrationIncident TriageAll Use Cases
Developers
Developer ResourcesSDKMCPDocsChangelog
Company
CustomersBlogEventsAboutCareersContact
Trust
Trust CenterPrivacySecurityEnterpriseSelf-hosted
XLinkedInGitHubDiscord
Tembo © 2026
Terms of usePrivacy Policy