Tudovu runs its own security program on the Tudovu platform, and this page is served by it. The controls below are the ones our SOC 2 program is built on. Our SOC 2 Type 1 report is shared under NDA: sign in with your work email, accept the agreement, and we'll review your request.
tudovu.comPrivacy policySecurity overviewVulnerability disclosure policyUpdated on Oct 6, 2026
Answers come from Tudovu's published documents and approved answers, with the source named.
23 of these are watched by automated checks against the production cloud account. Last run on Oct 6, 2026.
| Name | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database and file storage, email delivery (Amazon SES), and AI model inference (Amazon Bedrock, running Anthropic's Claude models) | United States (us-east-1); Bedrock inference in any AWS commercial region |
| GitHub | The GitHub App you install on your repositories, to open pull requests with fixes | United States |
| Stripe | Billing and payments | United States |
| Slack | Notifications and the Snippy assistant, only if you connect a workspace | United States |
| Google Workspace | Our email and staff sign-in, including support email you send us | United States |
Tudovu's agents run on Anthropic's Claude models through Amazon Bedrock, inside AWS. It's the only AI service our policies allow to touch customer data.
To draft a fix, a document or an answer, an agent sends the model the context that task needs: findings and check results, AWS inventory, the repository files involved, CI output, and documents you've uploaded. Code changes wait for your team to merge them, and generated documents stay drafts until someone approves them.
Tudovu runs on AWS in us-east-1: containers on ECS Fargate in private subnets behind AWS WAF, a Multi-AZ PostgreSQL database on RDS, and an S3 bucket for evidence files. Both stores are encrypted at rest, and everything in transit uses TLS.
Found a vulnerability or a security concern? Email team@tudovu.com.