Tamworks
← Tamworks

Security & data handling

Last updated August 2026

We build systems that touch financial and operational data, so security is an engineering requirement, not a marketing page. This describes how we actually work. If your diligence needs more detail, email hello@tamworks.io — we're happy to complete security questionnaires and walk through architecture.

This website

All traffic is served over TLS (HTTPS). We collect only what you choose to send — an inquiry, an email address for the blog — and use vetted infrastructure providers to run it: Vercel (hosting) and Resend (email delivery). No advertising cookies, no trackers, no data sales.

Client engagements

Data minimization. We take the least data necessary to do the work, and we prefer working inside your environment — your cloud account, your data warehouse, your access controls — over copying data out of it.

Least-privilege access. Access is scoped to the engagement, granted per person, and removed when the work ends. Credentials live in secret managers, never in code or email.

Encryption. Data is encrypted in transit (TLS) and at rest using the managed encryption of the underlying cloud platforms we deploy on (AWS, Google Cloud).

Confidentiality. We sign NDAs and data-processing agreements as part of normal engagement paperwork. At the end of an engagement, client data and access are returned or destroyed — offboarding is part of the plan, not an afterthought.

Products

Software we operate ourselves (such as YakLedger) is built with tenant isolation, authenticated APIs, encrypted transport, provider-managed encryption at rest, and audit logging of user actions.

AI & your data

Where our systems use AI models, we architect deterministic-first: models see the minimum context needed for a decision, and their inputs and outputs are logged for auditability. We do not use client data to train models, and we configure model providers accordingly.

Certifications — an honest note

Tamworks is a small firm and does not yet hold formal certifications such as SOC 2. We build to those control standards, our infrastructure providers hold their own certifications, and we're transparent about the gap — ask us anything in diligence and you'll get a straight answer.

Reporting a vulnerability

If you believe you've found a security issue in this site or one of our products, email hello@tamworks.io with the details. We read every report, respond quickly, and appreciate responsible disclosure.

Tamworks LLC · 18952 MacArthur Blvd, Suite 100, Irvine, CA 92612 · hello@tamworks.io