Security at Tail Sourcing
Enterprise-grade controls so your procurement data stays exactly where it should — and only with the people who should see it.
Last updated: August 25, 2026
Security pillars
Encryption
TLS 1.2+ in transit and AES-256 at rest across the platform and backups.
Access control
Role-based permissions, least-privilege internal access and full audit logs. SSO/SAML is an Enterprise plan feature where configured — it is not enabled on every workspace by default.
Infrastructure
Hardened cloud infrastructure with isolated environments, monitoring and incident response.
US-based team
A US-based team operates and supports the platform, with GDPR-aligned data handling and regular internal security reviews.
HTTPS
Our production sites — www.tailsourcing.com and esourcing.tailsourcing.com — are served over HTTPS only, using TLS 1.2 or higher.
Payment cards are entered on Stripe-hosted checkout. We do not receive or store the full card number (PAN).
Server-to-server callbacks and webhooks in production must use HTTPS endpoints.
Multi-tenant isolation
Many customer organisations share one application, and every record is scoped to a tenant_id.
Buyers in tenant A cannot read, list or search data belonging to tenant B.
The supplier portal is isolated by supplier ownership: a supplier sees only the RFx, orders and documents addressed to them.
Platform operators work from a separate console, and privileged actions are logged and audited.
This is logical isolation — a shared database with enforced tenant filters — not a dedicated physical database per customer on standard plans. Dedicated arrangements are discussed case by case on Enterprise.
Incident and breach plan
Detect. Monitoring, alerting and error tracking surface suspicious activity and anomalies.
Contain. We revoke affected credentials, rotate secrets and cut off the exposed path.
Assess. We determine which tenants, data types and records are involved.
Notify. We inform the affected tenant admin without undue delay and, where GDPR-style rules apply, within 72 hours of becoming aware — unless a law-enforcement request requires a delay. We notify supervisory authorities where legally required.
Remediate. We fix the root cause, document the timeline and share what changed.
Report a vulnerability to sales@tailsourcing.com. Please do not attach live secrets or customer data dumps in your first email. Our contact details are also published in our security.txt.
Compliance posture
The platform is designed toward the SOC 2 Security Trust Services Criteria and the OWASP Top 10, and internal reviews are run against them.
This page is a description of our controls, not an attestation. We do not claim to be SOC 2 certified, SOC 2 compliant or ISO 27001 certified.
Security questionnaires are answered under NDA — write to sales@tailsourcing.com.
There is no paid public bug bounty programme unless one is announced in our security.txt.
