Security
Last updated · September 26, 2026
If you’ve found a weakness in anything we run, thank you. Tell us privately and we’ll work with you to fix it.
Reporting a vulnerability
Email security@tanaloom.com with:
- a description of the issue and its impact;
- steps to reproduce it, with any proof-of-concept;
- the URLs or components affected;
- how you’d like to be credited, if at all.
Our security.txt file has the same details in machine-readable form.
Scope
- tanaloom.com and its subdomains
- Products we operate, including Salvio (salvio.in)
Systems we build for clients belong to those clients; we’ll pass reports on to them promptly.
Our commitments
- We’ll acknowledge your report within three business days.
- We’ll keep you informed as we investigate and fix it.
- We won’t pursue legal action against good-faith research that follows this policy.
- With your permission, we’ll credit you once the issue is resolved.
Please don’t
- access, change or delete data that isn’t yours (use test accounts);
- run denial-of-service, spam or load tests;
- use social engineering or physical attacks against our people or offices;
- disclose the issue publicly before we’ve had a reasonable chance to fix it.
How we protect data
Encryption in transit and at rest, least-privilege access, dependency and security scanning on every change, strict security headers, and IP addresses stored only as salted hashes. Client engagements add controls agreed per project.