TATERTATER ← Back to Home

Security

How TATER protects your compliance data and infrastructure.

TLS 1.2+ AES-256 Encryption Azure Cloud Entra ID Auth RBAC Enforced Tenant Isolation Signed Binaries

Encryption

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption via Azure Cosmos DB and Azure Storage built-in encryption.

Authentication

Sign-in uses Microsoft Entra ID (Azure AD) with OAuth 2.0 / OpenID Connect by default, so TATER never sees or stores your directory password. OpenID Connect (OIDC) single sign-on against your own identity provider and SCIM 2.0 provisioning are available for enterprise identity. Optional local accounts store only bcrypt-hashed credentials, and TATER Vault secrets are encrypted client-side (zero-knowledge).

Multi-Tenant Isolation

Each organization's data is logically isolated using tenant-specific partition keys. Server-side authorization ensures users can only access their organization's data.

Role-Based Access

Fine-grained role hierarchy (SuperAdmin, ServiceProvider, OrgAdmin, Auditor, Viewer) controls access at the organization and feature level, plus granular permission bundles that scope individual members to specific modules and actions — all enforced server-side.

Infrastructure

TATER is hosted entirely on Microsoft Azure infrastructure:

API Security

Every API request is authenticated and authorized through a multi-step process:

Compliance Agent Security

The optional TATER Compliance Agent is designed with security as a priority:

Data Protection

Responsible Disclosure

If you discover a security vulnerability in TATER, please report it responsibly by contacting security@tatersecurity.com. We ask that you allow us reasonable time to investigate and address the issue before public disclosure. Our full vulnerability disclosure policy is published in the Trust Center.

Trust Center

This page summarizes our core practices. For the full trust statement CISOs and procurement teams review — data residency, audit log integrity (HMAC signing), signed binaries, SBOM availability, subprocessors, and attestation status — see the TATER Trust Center.