Skip to main content
Tail Sourcing
Trust

Security at Tail Sourcing

Enterprise-grade controls so your procurement data stays exactly where it should — and only with the people who should see it.

Last updated: August 25, 2026

Security pillars

Encryption

TLS 1.2+ in transit and AES-256 at rest across the platform and backups.

Access control

Role-based permissions, least-privilege internal access and full audit logs. SSO/SAML is an Enterprise plan feature where configured — it is not enabled on every workspace by default.

Infrastructure

Hardened cloud infrastructure with isolated environments, monitoring and incident response.

US-based team

A US-based team operates and supports the platform, with GDPR-aligned data handling and regular internal security reviews.

HTTPS

Our production sites — www.tailsourcing.com and esourcing.tailsourcing.com — are served over HTTPS only, using TLS 1.2 or higher.

Payment cards are entered on Stripe-hosted checkout. We do not receive or store the full card number (PAN).

Server-to-server callbacks and webhooks in production must use HTTPS endpoints.

Multi-tenant isolation

Many customer organisations share one application, and every record is scoped to a tenant_id.

Buyers in tenant A cannot read, list or search data belonging to tenant B.

The supplier portal is isolated by supplier ownership: a supplier sees only the RFx, orders and documents addressed to them.

Platform operators work from a separate console, and privileged actions are logged and audited.

This is logical isolation — a shared database with enforced tenant filters — not a dedicated physical database per customer on standard plans. Dedicated arrangements are discussed case by case on Enterprise.

Incident and breach plan

Detect. Monitoring, alerting and error tracking surface suspicious activity and anomalies.

Contain. We revoke affected credentials, rotate secrets and cut off the exposed path.

Assess. We determine which tenants, data types and records are involved.

Notify. We inform the affected tenant admin without undue delay and, where GDPR-style rules apply, within 72 hours of becoming aware — unless a law-enforcement request requires a delay. We notify supervisory authorities where legally required.

Remediate. We fix the root cause, document the timeline and share what changed.

Report a vulnerability to sales@tailsourcing.com. Please do not attach live secrets or customer data dumps in your first email. Our contact details are also published in our security.txt.

Compliance posture

The platform is designed toward the SOC 2 Security Trust Services Criteria and the OWASP Top 10, and internal reviews are run against them.

This page is a description of our controls, not an attestation. We do not claim to be SOC 2 certified, SOC 2 compliant or ISO 27001 certified.

Security questionnaires are answered under NDA — write to sales@tailsourcing.com.

There is no paid public bug bounty programme unless one is announced in our security.txt.