# Security

How Tappd protects customer data. Hosted on Cloudflare, Vultr, and MongoDB Atlas with data stored in Singapore and India. TLS in transit, encryption at rest, role-based access, scoped API keys, audit log, daily encrypted backups, deletion within 30 days of account closure. Sub-processors: Cloudflare, Vultr, MongoDB Atlas, ClickHouse Cloud, Apple APNs, Google FCM, Twilio/SendGrid, Stripe. DPA available on request. Security contact: security@tappd.io.

Last updated: 12/09/2026

Canonical URL: https://tappd.io/security

This markdown summary is provided for AI agents and tools. The full legal document is available at the canonical URL above (HTML).

## Related legal documents

- [Security](https://tappd.io/security)
- [Privacy Policy](https://tappd.io/privacy)
- [Terms of Service](https://tappd.io/terms)
- [Acceptable Use Policy](https://tappd.io/acceptable-use)
- [Software Lifecycle Policy](https://tappd.io/software-lifecycle)
