Skip to main content

Trust and compliance

Which compliance posture Tale Cloud ships with, who audits what, which controls are yours, and how to report incidents.

3 min read

Trust and compliance on Cloud is the page an auditor wants. It names the frameworks the platform is certified against, splits responsibilities between Tale and your org cleanly, lists the data-protection controls available to you, and tells you who to call when something goes wrong.

The content here is descriptive — what is shipped today, what evidence Tale can hand over on request. The legal documents themselves (DPA, terms, privacy) live under Legal; this page is the operator's quick reference.

A worked control — audit logs end to end

The org's compliance officer needs to demonstrate that "every change to access control is logged with the actor, the target, and the timestamp". Tale's Audit logs record every member invite, role change, removal, and 2FA reset with the actor's user ID, the affected member's ID, and an ISO timestamp. Logs are immutable — restoring a snapshot does not modify them — and retained per the org's configured floor. The officer exports a date range as CSV, hands it to the auditor, and the worked example clears the control.

Certifications and frameworks

Tale Cloud is currently audited or attested against the following frameworks; the certification reports are available under NDA via support:

  • SOC 2 Type II (annual)
  • ISO/IEC 27001
  • GDPR-aligned controls (EDPB guidance applied)
  • FADP-aligned controls for the Switzerland region (revDSG)

Pending or planned: HIPAA BAA (US enterprise customers), additional regional attestations as the region list grows.

Shared-responsibility split

ControlTaleYouEvidence
Infrastructure availabilityStatus page, SOC 2 SLA report
Data encryption at restArchitecture description
Encryption in transitTLS termination by Tale's edge
Member identity and rolesMembers and roles
API key issuance and rotationAPI keys
Content filtering and DLPProvides hooksConfigures rulesGuardrails
Audit-log retentionProvides storageSets retentionRetention
Data-subject requestsProvides workflowInitiates and approvesDSRs
Provider credentialsProviders

Data protection controls

Inside the product, three control surfaces matter for compliance:

  • Audit logs — immutable record of who did what; retention configurable.
  • Legal hold — exempts a record set from retention until lifted; covered in Legal hold.
  • Data subject requests — the request → claim → erasure → audit workflow; covered in DSRs.

Reporting incidents

Tale's security incident contact is security@tale.dev. Suspected vulnerability disclosure follows the responsible-disclosure policy on the same email. Customer-facing security advisories are published on the status page and emailed to the org's Owner.

Where this fits

Trust and compliance is the audit-time page; Data residency is the architecture-time page; Subprocessors is the list-of-vendors page. An auditor usually wants all three at once — bookmark them together. If you operate self-hosted, the controls are the same; what changes is who runs the infrastructure beneath them — see Self-hosted overview.

© 2026 Tale by Ruler GmbH — ISO 27001 & SOC 2 certified.

Tale is MIT licensed — free to use, modify, and distribute.