Tap
Security & trust

Built to industry security best practices.

Tap coordinates how your team helps each other — it doesn't host your work. That principle shapes everything below: we hold as little of your data as possible, protect what we do hold, and keep your proprietary files out of our systems entirely.

Last reviewed: June 2026

How we approach compliance

Tap is built to industry security best practices, using the SOC 2 Trust Services Criteria as the framework for our controls — covering access management, change management, system operations, and data protection.

We are not currently SOC 2 certified. If your procurement process requires a formal attestation, we can prioritize an independent audit for enterprise engagements — reach out and we'll scope it with you.

This page describes controls that are live in the product today. We review it regularly and update it as the product evolves.

The controls protecting your data

Encryption everywhere

All traffic to and from Tap runs over TLS. Your application data is stored in managed PostgreSQL (Neon) and encrypted at rest.

Authentication & access control

Sign-in and sessions are managed by Clerk. Role-based permissions (owner, director, member) are enforced on the server for every action — never only hidden in the interface.

Strict workspace isolation

Every query is scoped to your workspace. The server derives your workspace from your authenticated session and never trusts a workspace identifier supplied by the browser.

Append-only activity log

Data-changing actions are recorded to an append-only activity log — with the actor, source, and any denied attempts — giving an accountable history of what happened in the workspace.

Data minimization by design

We store the least we can to run the product: names, work email addresses, and optional chat handles. Nothing more.

Monitoring & backups

Application errors are tracked with Sentry, configured to exclude personal data. The database is backed up automatically with point-in-time recovery.

Secure development & dependencies

Every change ships through automated checks on a protected branch. Dependencies are pinned, continuously monitored for advisories, and the build fails on a high-severity vulnerability.

The safest data is the data we never hold.

Most of our security story is structural. Tap coordinates the work; it doesn't store it.

No file uploads, ever

Tap links to your work in Figma, Adobe, and wherever else it lives. Proprietary files never enter our systems — there is nothing to leak.

No payment card data

Billing is handled by Stripe. Card details go straight to Stripe; Tap never sees or stores them.

Minimal personal data

Names, work email, and optional Slack/Teams handles — that is the full extent of the personal data we hold.

Our subprocessors

We rely on a small set of reputable infrastructure providers. Each runs its own security program and independent audits.

ProviderPurposeRegion
ClerkAuthentication & user identityUSA
StripePayments & billingUSA / Global
NeonManaged PostgreSQL databaseUSA
RenderApplication hostingOhio (US East)
ResendTransactional emailUSA
SentryError monitoring (PII excluded)USA
InngestBackground job processingUSA
PostHogProduct analyticsUSA

Need our security documentation?

Security reviewers and procurement teams can request our detailed security overview, completed questionnaires, and a DPA.