Security

How we handle your data

This page is written for the reader looking for a reason to say no. Every claim below is checkable; ask us to evidence any of them.

Scope

Your data

Access

Audit

Suppliers and incidents

Questions

Vulnerability reports: see /.well-known/security.txt · Contact: hello@tacit.ltd

Evidence

Security evidence notes

Tacit does not train models on client data.

Method
Set scope in writing, use provider processing terms, and avoid client data being used for model training.
Source
Tacit security page.
Date
4 July 2026
Limitation
Supplier and jurisdiction choices are finalised per client agreement and security review.
Owner
Tacit security owner

FAQ

Security questions

Does Tacit train models on client data?

Tacit does not train models on client data. Model providers are used under agreed processing terms and workflow scope is agreed before data moves.

How is access controlled?

Access is named, scoped, logged and revocable. Agents work inside the client's agreed permissions and only reason over material the requesting user is entitled to see.

What audit trail does Tacit keep?

Tacit keeps trails for meaningful outputs: sources, prompts, model version and reviewer. The trail is designed to be available throughout the engagement.

Does Tacit claim public security certifications?

Tacit does not claim certifications it does not hold. If a control is not in place, Tacit says so and gives the date it will be.

Last updated: 4 July 2026

Start

Bring us one workflow

Pick the one that eats your Tuesdays. We'll map it, show you what the agent version looks like, and tell you honestly if it isn't worth building.