Our commitments
tapestry®'s business depends on retailers, suppliers and partners trusting us with high-value shelf data. We've structured the company, the product, and the contracts to make that trust earned and verifiable - not assumed.
- Your data is yours. You own it. We process it on your behalf.
- We will never share without your explicit, configured consent.
- Every share is logged. You can see it, audit it, and revoke it.
- Aggregation and anonymity are configurable, not assumed.
- If we get it wrong, we tell you - and we have a 72-hour notification SLA.
Security controls
Encryption
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Keys are managed in a customer-isolated AWS KMS hierarchy with annual rotation.
Access
Role-based access control with least-privilege defaults. SSO via SAML or OIDC. Multi-factor authentication enforced for every administrator account. Hardware key support for engineering staff.
Infrastructure
Hosted on AWS in primary and disaster-recovery regions appropriate to your jurisdiction (AU, US, EU). Multi-AZ database replication. Daily point-in-time backups with 30-day retention; 1-year cold archive.
Application
Continuous static analysis, dependency scanning, and quarterly third-party penetration testing. Vulnerability disclosure program. Bug bounty open to certified security researchers.
People
Background checks for every employee with production access. Annual security training. Production access requires explicit, ticketed, audited approval.
| Certification | Status | Last audited |
|---|---|---|
| SOC 2 Type II | Active | March 2026 |
| ISO 27001:2022 | Certified | November 2025 |
| PCI DSS scope | N/A · no cards | - |
| GDPR / Australian Privacy Principles | Compliant | Ongoing |
Data governance
The marketplace at the centre of tapestry® only works if data sharing is governed - granularly, transparently, auditably. Three controls are non-negotiable:
- Aggregation thresholds. Default minimum cell sizes prevent inadvertent disclosure. You can tighten further per share.
- Anonymity layers. Store-level data can be shared as aggregated, anonymised, or identified - configurable per supplier, per category.
- Audit trails. Every share, every access, every payment is logged. Exports are available on demand.
Data processing
Under our standard agreement, tapestry® is a processor for the data you bring to the platform, and a controller only for the optional marketplace flows you explicitly opt into.
Standard DPA terms
- Processing limited to the purposes you direct
- Sub-processors disclosed and updated 30 days in advance
- Cross-border transfers governed by SCCs (EU) or equivalent
- Breach notification within 72 hours of confirmed incident
- Data deletion within 30 days of contract end (with audit certificate)
Request the latest DPA at legal@tapestry.ai.
Status & incidents
The live status page tracks API, ingest, dashboard, marketplace and HANK services across all regions. Past 90 days are public; full 12-month history is available to customers in-app.
Sub-processors
tapestry® uses a small, audited set of sub-processors. Customers are notified by email 30 days before any addition. Current list:
| Vendor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Primary cloud infrastructure | AU / US / EU |
| Snowflake | Data warehouse for analytics | AU / US / EU |
| Datadog | Observability & APM | US |
| Linear | Engineering issue tracking | US |
| Notion | Internal documentation | US |
Contact security
For vulnerabilities, incidents, or any security-sensitive question: security@tapestry.ai. PGP key available on request.
For privacy and DPA matters: privacy@tapestry.ai.