Security

Last updated: August 24, 2026

01

Security Philosophy

Security is foundational to T. Every feature is designed with a security-first mindset, from the way we encrypt your media to how we handle authentication.

We believe your content is yours alone. Our zero-knowledge architecture ensures we cannot access your encrypted files, even if compelled to.

02

Encryption

All media files are encrypted client-side using AES-256 before upload. Files remain encrypted at rest in our storage infrastructure.

Data in transit is protected using TLS 1.3 with forward secrecy. All API communication requires authenticated, encrypted connections.

Encryption keys are managed through a dedicated key management service with regular rotation and strict access controls.

03

Access Control

We employ role-based access control (RBAC) across all internal systems. Employees access production data only with explicit, time-limited authorization.

Multi-factor authentication is required for all internal access to infrastructure and customer data.

All access is logged and audited. Anomalous access patterns trigger automated alerts and investigation.

04

Infrastructure Security

Our infrastructure runs on isolated, hardened instances with regular security patching and vulnerability scanning.

Network segmentation separates public-facing services from internal systems. Database access is restricted to authenticated application instances only.

We conduct regular penetration testing and engage independent security firms for annual audits.

05

Compliance

T is SOC 2 Type II certified, demonstrating our commitment to security, availability, and confidentiality controls.

We comply with GDPR, CCPA, and other applicable data protection regulations. Data processing agreements are available for enterprise customers.

06

Incident Response

We maintain a 24/7 incident response capability. Security incidents are triaged, contained, and remediated following our documented response procedures.

In the event of a data breach affecting your information, we will notify affected users within 72 hours as required by applicable law.

Security researchers can report vulnerabilities to security@tordor.com. We operate a responsible disclosure program.

07

Contact

For security questions or to report a vulnerability, contact security@tordor.com. We use PGP encryption for sensitive communications.

Questions about this policy? Reach out to legal@tordor.com