TudovuTudovu

Tudovu Trust Center

Tudovu runs its own security program on the Tudovu platform, and this page is served by it. The controls below are the ones our SOC 2 program is built on. Our SOC 2 Type 1 report is shared under NDA: sign in with your work email, accept the agreement, and we'll review your request.

tudovu.comPrivacy policySecurity overviewVulnerability disclosure policyUpdated on Oct 6, 2026

SOC 2 Type 1 · 2026Thoropass Assurance, as of July 31, 2026
Ask Tudovu a security question

Answers come from Tudovu's published documents and approved answers, with the source named.

Controls (45)

23 of these are watched by automated checks against the production cloud account. Last run on Oct 6, 2026.

Access control
9 controls · 8 monitored
  • Access Control Policy and Procedures
  • Access Provisioning
  • Access Termination
and 6 more
Business continuity and incident response
4 controls · 1 monitored
  • Contingency Plan
  • Contingency Plan Testing
  • Incident Response Plan
and 1 more
Data security
5 controls · 4 monitored
  • Encryption of Data at Rest and in Transit
  • System Backup
  • System Backup Test
and 2 more
Infrastructure security
7 controls · 6 monitored
  • Boundary Protection
  • Network Segmentation
  • Logging and Monitoring
and 4 more
Organizational security
9 controls
  • Information Security Policy and Procedures
  • Policy Creation
  • Information Security Program Leadership Role
and 6 more
Product security
4 controls · 3 monitored
  • Change Management and Software Development Life Cycle
  • Configuration Management
  • Vulnerability Management
and 1 more
Risk and vendor management
7 controls · 1 monitored
  • Risk Assessment
  • Risk Assessment Policy and Procedures
  • Risk Management Committee
and 4 more

Subprocessors

NamePurposeLocation
Amazon Web ServicesHosting, database and file storage, email delivery (Amazon SES), and AI model inference (Amazon Bedrock, running Anthropic's Claude models)United States (us-east-1); Bedrock inference in any AWS commercial region
GitHubThe GitHub App you install on your repositories, to open pull requests with fixesUnited States
StripeBilling and paymentsUnited States
SlackNotifications and the Snippy assistant, only if you connect a workspaceUnited States
Google WorkspaceOur email and staff sign-in, including support email you send usUnited States

How we handle your data with AI

Tudovu's agents run on Anthropic's Claude models through Amazon Bedrock, inside AWS. It's the only AI service our policies allow to touch customer data.

To draft a fix, a document or an answer, an agent sends the model the context that task needs: findings and check results, AWS inventory, the repository files involved, CI output, and documents you've uploaded. Code changes wait for your team to merge them, and generated documents stay drafts until someone approves them.

  • Nobody trains a model on your data. We don't train or fine-tune models, and Amazon Bedrock doesn't use prompts or responses to train models or share them with the model provider.
  • Inference runs through Bedrock's global routing, so a request can be processed in any AWS commercial region, including ones outside the US. It stays inside AWS either way.
  • What the product keeps (your documents, findings and drafts) stays in our AWS account in us-east-1, encrypted at rest. Unless your contract says otherwise, it's deleted 90 days after you close your account. The full retention schedule is in our policy handbook, under the NDA.

Where your data goes

Tudovu runs on AWS in us-east-1: containers on ECS Fargate in private subnets behind AWS WAF, a Multi-AZ PostgreSQL database on RDS, and an S3 bucket for evidence files. Both stores are encrypted at rest, and everything in transit uses TLS.

  • Your AWS account is read through a role you create with a CloudFormation stack (AWS's SecurityAudit and ReadOnlyAccess policies, one-hour sessions, an external ID). We don't hold access keys for it.
  • Fixes reach your repositories as pull requests from the GitHub App you install. Your own pipeline deploys what your team merges, under a role only that workflow can assume.
  • The context an agent needs for a task goes to Claude on Amazon Bedrock, and stays in AWS.
  • Email goes out through Amazon SES and payments through Stripe. Slack only sees what you send it, and only if you connect a workspace.

Report a security issue

Found a vulnerability or a security concern? Email team@tudovu.com.

Documents

  • Tudovu Company Policy Handbook · ConfidentialThe information security policies our SOC 2 program runs on, from access control to incident response and data retention.
  • SOC 2 Type 1 Report · ConfidentialOur SOC 2 Type 1 report from Thoropass Assurance, covering security, availability and confidentiality as of July 31, 2026.

Built with Tudovu