Skip to content
Trust centre

Security at Tulina

Tulina holds the keys to the tools you connect, so the first question anyone sensible asks is where those keys live and who can reach them. This page answers that, along with the rest of a normal vendor review, without you having to send the questionnaire first.

Last updated 2 September 2026

Hosting

European Union

The platform, its database, its object storage, its secrets and its credential vault are hosted in the Union, and all of it currently runs on Scaleway in France. Your working data never leaves the Union to be processed by us.

Credentials

AES-256-GCM

Every token and API key you connect is encrypted at rest. The master key lives outside the database in a secret manager and never touches disk, so a database dump is ciphertext and nothing else.

The agent

Never sees a secret

Credentials are decrypted at the moment of the call and never logged. They do not pass through the language model's context, so no prompt, transcript or model provider ever holds one.

01

Where we stand on certification

Tulina holds no SOC 2 report and no ISO 27001 certificate today, and neither does the company operating the backend. We say so here rather than let a page shaped like a compliance badge imply otherwise, because a buyer finds out during diligence either way and the second version costs the deal twice.

What exists instead is on this page: European hosting, an encrypted vault, a written policy set held by the operator and shareable under NDA, and an article 28 agreement already published rather than negotiated per deal. If your purchasing policy requires a certificate, that is a real answer and we would rather give it early. If it requires evidence, ask us for the document set.

We carry no cyber liability insurance. It comes up in procurement, so it is here too.

02

How the platform is run

Isolation

Data is partitioned by user and by organisation, and every call runs on the credentials of the person making it. The machine serving the platform has its own firewall, no private network to anything else, and is not colocated with the systems holding credentials.

Access control

Sign-in is OAuth with PKCE against a self-hosted Logto, with no shared password anywhere. Access follows the roles an organisation's administrators set, and least privilege is the default: sensitive sources are closed until opened, and a connector is unavailable to an organisation until it is explicitly turned on. A team can only ever subtract from what its organisation allows.

What we never do with your data

We do not train models on it, sell it, or profile anyone for our own purposes. That is a contractual commitment under article 28, not a policy we could quietly change.

What we can see

We do not read the contents of your connected tools. Error monitoring receives the name of a failing operation and an opaque user identifier. IP addresses, cookies, headers and call arguments are all excluded by configuration, so a stack trace never carries your data.

Audit trail

Every tool call is logged: who ran it, which tool, how long it took, and whether it succeeded. No secret content is ever written to that log. An organisation can review its own workspace through it, and it is what anomaly detection and incident response are built on.

Detection and availability

Network-level intrusion prevention bans malicious addresses automatically, and availability and server resources are monitored continuously. The database is managed and highly available, with daily backups kept for seven days.

Secure development

Changes reach production through review and automated checks. Secrets live in a managed secret store rather than in the code or on a developer machine.

You can read the code

The technical foundation the platform is built on is open source and auditable rather than asserted: oto-core, france-opendata, o-browser and otomata-calllog are all public. A reviewer who does not want to take our word for the claims above can go and check several of them.

Incident response

We notify you without undue delay once we become aware of a breach affecting your personal data, with what we know at the time and updates as we learn more. That commitment is contractual and sits in the DPA.

Vulnerability reports

Write to security@tulina.ai before disclosing anything elsewhere. Our terms grant a good-faith researcher permission to test, within limits set out on that page.

03

Documents

Four are published and binding. The rest are the operator's internal policy set, which we can share under an NDA as part of a review.

Available under NDA

  • Security summary (operator)
  • Operator article 28 agreement
  • Information security policy
  • Access control policy
  • Backup and continuity policy
  • Secure development policy
  • Subprocessor management policy
  • Data retention policy
  • Security incident response procedure
  • Breach notification procedure (art. 33-34)

Ask at security@tulina.ai and say which of them your review needs. We would rather send four relevant documents than a folder of twelve.

04

Who processes your data

Three groups, and the difference between them matters more than the names. We contract directly with the first. The second are engaged by the company operating the backend, so they sit one step further down the chain. The third are touched only if you choose to touch them.

Engaged for every customer

Our own subprocessors, under an article 28 agreement.

Marseille, France

Operates the backend behind the platform: the encrypted credential vault, the database and the sign-in service. A separate legal entity from JF VENTURES, which makes it a subprocessor rather than us.

United States

Hosts the tulina.ai website and measures its audience, cookielessly. The platform itself does not run on it and it holds no customer working data.

United States

Receives contact form submissions so we can act on them.

United States

Backup delivery of contact form submissions by email when Slack is unavailable.

Engaged by the backend operator

Otomata runs the platform, and these are its own suppliers. They are a step removed from us and named anyway, because “who else can reach this” is the question a chain of subprocessors is meant to answer rather than obscure.

Paris, France

Dedicated servers, managed PostgreSQL, object storage and the secret manager. Nearly the whole platform sits here.

EU region

Error tracking. Receives the failing operation and an opaque user id, never call arguments or personal data.

United States

DNS, CDN and web application firewall in front of the platform domains.

EU hosting

Product analytics for the platform.

Engaged only by your own use

Tulina connects to around a hundred tools, and none of them is connected until you connect it. Which of the following ever receives anything therefore depends on what you install and run, not on being a customer.

With your own key, we are not in the loop. Most connectors run on credentials you supply. Your data travels to that provider under your existing contract with them, on your instruction. We pass it on and we are not the controller of what happens there.

With our key, the vendor sits on our account. A few enrichment and messaging connectors can run on a shared Tulina key instead, so you can try them without signing up separately. That is the only case where one of these vendors becomes a subprocessor of ours, and it starts the moment you use that connector and stops when you stop.

A workspace starts with nothing installed, and a connector stays unavailable to an organisation until an administrator turns it on, so an organisation that never enables enrichment never reaches any of this. Payment and billing providers are on our privacy page instead, since we are the controller for billing rather than your processor.

France

Hosted multi-channel messaging, when you connect LinkedIn, WhatsApp or Telegram.

United States

Waterfall enrichment of B2B contacts, when you run an enrichment that uses it.

United States

Professional email lookup and verification.

France

B2B contact enrichment, phone and email.

United States

Web search, and the hosted scraper the web reader falls back to when a page will not open with a plain fetch.

United States

A disposable hosted browser, the web reader's last resort on a page that defends itself. Never a silent default: it runs only when a call opts into it.

The catalogue changes as connectors are added. For the current list, and which of them can run on a shared key, see connectors. We tell customers before adding or replacing a subprocessor that processes their data, and you can object.

Running a security review?

Send us the questionnaire. We answer them ourselves rather than routing you through a portal, and we will tell you plainly where the answer is no.

security@tulina.ai

Experience Tulina for 14 days.

By continuing, you agree to our Terms of Use and Privacy policy.