Security at Tulina
Tulina holds the keys to the tools you connect, so the first question anyone sensible asks is where those keys live and who can reach them. This page answers that, along with the rest of a normal vendor review, without you having to send the questionnaire first.
Last updated 2 September 2026
Hosting
European Union
The platform, its database, its object storage, its secrets and its credential vault are hosted in the Union, and all of it currently runs on Scaleway in France. Your working data never leaves the Union to be processed by us.
Credentials
AES-256-GCM
Every token and API key you connect is encrypted at rest. The master key lives outside the database in a secret manager and never touches disk, so a database dump is ciphertext and nothing else.
The agent
Never sees a secret
Credentials are decrypted at the moment of the call and never logged. They do not pass through the language model's context, so no prompt, transcript or model provider ever holds one.
01
Where we stand on certification
Tulina holds no SOC 2 report and no ISO 27001 certificate today, and neither does the company operating the backend. We say so here rather than let a page shaped like a compliance badge imply otherwise, because a buyer finds out during diligence either way and the second version costs the deal twice.
What exists instead is on this page: European hosting, an encrypted vault, a written policy set held by the operator and shareable under NDA, and an article 28 agreement already published rather than negotiated per deal. If your purchasing policy requires a certificate, that is a real answer and we would rather give it early. If it requires evidence, ask us for the document set.
We carry no cyber liability insurance. It comes up in procurement, so it is here too.
02
How the platform is run
Isolation
Data is partitioned by user and by organisation, and every call runs on the credentials of the person making it. The machine serving the platform has its own firewall, no private network to anything else, and is not colocated with the systems holding credentials.
Access control
Sign-in is OAuth with PKCE against a self-hosted Logto, with no shared password anywhere. Access follows the roles an organisation's administrators set, and least privilege is the default: sensitive sources are closed until opened, and a connector is unavailable to an organisation until it is explicitly turned on. A team can only ever subtract from what its organisation allows.
What we never do with your data
We do not train models on it, sell it, or profile anyone for our own purposes. That is a contractual commitment under article 28, not a policy we could quietly change.
What we can see
We do not read the contents of your connected tools. Error monitoring receives the name of a failing operation and an opaque user identifier. IP addresses, cookies, headers and call arguments are all excluded by configuration, so a stack trace never carries your data.
Audit trail
Every tool call is logged: who ran it, which tool, how long it took, and whether it succeeded. No secret content is ever written to that log. An organisation can review its own workspace through it, and it is what anomaly detection and incident response are built on.
Detection and availability
Network-level intrusion prevention bans malicious addresses automatically, and availability and server resources are monitored continuously. The database is managed and highly available, with daily backups kept for seven days.
Secure development
Changes reach production through review and automated checks. Secrets live in a managed secret store rather than in the code or on a developer machine.
You can read the code
The technical foundation the platform is built on is open source and auditable rather than asserted: oto-core, france-opendata, o-browser and otomata-calllog are all public. A reviewer who does not want to take our word for the claims above can go and check several of them.
Incident response
We notify you without undue delay once we become aware of a breach affecting your personal data, with what we know at the time and updates as we learn more. That commitment is contractual and sits in the DPA.
Vulnerability reports
Write to security@tulina.ai before disclosing anything elsewhere. Our terms grant a good-faith researcher permission to test, within limits set out on that page.
03
Documents
Four are published and binding. The rest are the operator's internal policy set, which we can share under an NDA as part of a review.
Data processing agreement
The article 28 terms, incorporated into every contract. A signed copy on request.
Privacy policy
What we collect as controller, on what basis, and for how long.
Terms of use
Including the liability position and the responsible-disclosure permission.
Legal notice
The publishing entity, its registration and its host.
Available under NDA
- Security summary (operator)
- Operator article 28 agreement
- Information security policy
- Access control policy
- Backup and continuity policy
- Secure development policy
- Subprocessor management policy
- Data retention policy
- Security incident response procedure
- Breach notification procedure (art. 33-34)
Ask at security@tulina.ai and say which of them your review needs. We would rather send four relevant documents than a folder of twelve.
04
Who processes your data
Three groups, and the difference between them matters more than the names. We contract directly with the first. The second are engaged by the company operating the backend, so they sit one step further down the chain. The third are touched only if you choose to touch them.
Engaged for every customer
Our own subprocessors, under an article 28 agreement.
Operates the backend behind the platform: the encrypted credential vault, the database and the sign-in service. A separate legal entity from JF VENTURES, which makes it a subprocessor rather than us.
Hosts the tulina.ai website and measures its audience, cookielessly. The platform itself does not run on it and it holds no customer working data.
Receives contact form submissions so we can act on them.
Backup delivery of contact form submissions by email when Slack is unavailable.
Engaged by the backend operator
Otomata runs the platform, and these are its own suppliers. They are a step removed from us and named anyway, because “who else can reach this” is the question a chain of subprocessors is meant to answer rather than obscure.
Dedicated servers, managed PostgreSQL, object storage and the secret manager. Nearly the whole platform sits here.
Error tracking. Receives the failing operation and an opaque user id, never call arguments or personal data.
DNS, CDN and web application firewall in front of the platform domains.
Product analytics for the platform.
Engaged only by your own use
Tulina connects to around a hundred tools, and none of them is connected until you connect it. Which of the following ever receives anything therefore depends on what you install and run, not on being a customer.
With your own key, we are not in the loop. Most connectors run on credentials you supply. Your data travels to that provider under your existing contract with them, on your instruction. We pass it on and we are not the controller of what happens there.
With our key, the vendor sits on our account. A few enrichment and messaging connectors can run on a shared Tulina key instead, so you can try them without signing up separately. That is the only case where one of these vendors becomes a subprocessor of ours, and it starts the moment you use that connector and stops when you stop.
A workspace starts with nothing installed, and a connector stays unavailable to an organisation until an administrator turns it on, so an organisation that never enables enrichment never reaches any of this. Payment and billing providers are on our privacy page instead, since we are the controller for billing rather than your processor.
Hosted multi-channel messaging, when you connect LinkedIn, WhatsApp or Telegram.
Waterfall enrichment of B2B contacts, when you run an enrichment that uses it.
Professional email lookup and verification.
B2B contact enrichment, phone and email.
Web search, and the hosted scraper the web reader falls back to when a page will not open with a plain fetch.
A disposable hosted browser, the web reader's last resort on a page that defends itself. Never a silent default: it runs only when a call opts into it.
The catalogue changes as connectors are added. For the current list, and which of them can run on a shared key, see connectors. We tell customers before adding or replacing a subprocessor that processes their data, and you can object.
Running a security review?
Send us the questionnaire. We answer them ourselves rather than routing you through a portal, and we will tell you plainly where the answer is no.