Security & trust

Security is the product, not a feature

Tungdam handles identity documents, financial data and compliance records. We treat that responsibility with controls built in at every layer.

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Sensitive fields are additionally isolated.

Access control

Role-based access, granular permissions and SSO keep every record visible only to the people who should see it.

Audit trails

Every verification, document action and approval is time-stamped and immutable, always audit-ready.

Resilient infrastructure

Hosted on hardened cloud infrastructure with automated backups, monitoring and disaster recovery.

Secrets & keys

API keys are scoped and rotatable. Secrets are stored in a managed vault, never in plain configuration.

Data residency

Choose where documents and records are stored to meet your regulatory and internal policy requirements.

Our practices

How we keep your data safe

Security is an ongoing discipline. These are some of the practices we hold ourselves to across engineering and operations.

  • Principle of least privilege across all internal systems
  • Regular third-party penetration testing and vulnerability scanning
  • Secure software development lifecycle with peer-reviewed code
  • Continuous monitoring and alerting on infrastructure
  • Documented incident response and breach notification process
  • Vendor risk reviews for every subprocessor we rely on
Encryption in transit TLS 1.2+
Encryption at rest AES-256
Single sign-on SAML / OIDC
Audit logging Immutable
Backups Automated

Talk to us about your security requirements

Have a security questionnaire, data residency need or private deployment requirement? Our team is happy to walk through the details.