Security
Built to handle confidential M&A data.
Effective June 22, 2026
Our founder has sat in the deal team, advisory, and legal seats for M&A. Protecting deal data isn’t a feature here — it’s the foundation.
Compliance
SOC 2 readiness is in progress. We are operating against the Trust Services Criteria for availability, confidentiality, privacy, processing integrity, and security. We are targeting our SOC 2 Type I report by Q3 2026, with our Type II report to follow.
A current readiness status letter is available on request under mutual NDA.
Encryption
All traffic to and from the platform is encrypted in transit using TLS 1.2 or higher. Customer data at rest is encrypted using AES-256 via our infrastructure providers.
Customer credentials are never stored on Taia infrastructure; authentication uses short-lived tokens issued by our auth provider. Secrets and API keys are stored in managed secret stores, never in source code or logs.
Access controls
Authentication is enforced with mandatory multi-factor authentication for all accounts with production access. Production access is restricted to a documented set of personnel with role-based privileges and a clear business need.
Staff access to customer deal data through the platform’s authenticated interface is limited, logged, and reviewed. Access is reviewed quarterly and revoked within one business day of offboarding.
Data handling
Customer data is hosted on infrastructure located in the United States. Each client’s data is contained in its own isolated workspace.
Customers do not have direct database access; all data flows through Taia’s authenticated platform. Infrastructure providers carry SOC 2 Type II or ISO 27001 attestations.
Data retention
Your benchmarks and deal data remain within your workspace. Taia does not sell, share, or surface them in any other client’s work, and does not use your benchmarks to train AI models.
Where Taia uses third-party large language model providers, those providers operate under enterprise terms that prohibit training on customer inputs, and Taia configures these workloads for zero data retention where available.
Customer data is retained for the duration of your subscription. On contract termination or written deletion request, hard deletion completes within 7 days, reflecting our database provider’s rolling backup retention window.
Sub-processors
A current list of sub-processors, the data they receive, and links to their data processing terms is provided to customers under mutual non-disclosure as part of vendor due diligence. Email privacy@taiatech.com to request a copy.
Taia will notify customers of sub-processor changes — additions or removals — at least 30 days in advance, providing the right to object per the DPA.
Vulnerability management & incident response
Dependencies are monitored for known vulnerabilities through automated tooling. Incident response procedures are in place and being formalized as part of Taia’s SOC 2 readiness. Security incidents affecting customer data will be communicated to the affected customer within 24 hours of confirmation.
Responsible disclosure of suspected vulnerabilities is welcome at security@taiatech.com.