Skip to content

Security

Last updated · September 26, 2026

If you’ve found a weakness in anything we run, thank you. Tell us privately and we’ll work with you to fix it.

Reporting a vulnerability

Email security@tanaloom.com with:

  • a description of the issue and its impact;
  • steps to reproduce it, with any proof-of-concept;
  • the URLs or components affected;
  • how you’d like to be credited, if at all.

Our security.txt file has the same details in machine-readable form.

Scope

  • tanaloom.com and its subdomains
  • Products we operate, including Salvio (salvio.in)

Systems we build for clients belong to those clients; we’ll pass reports on to them promptly.

Our commitments

  • We’ll acknowledge your report within three business days.
  • We’ll keep you informed as we investigate and fix it.
  • We won’t pursue legal action against good-faith research that follows this policy.
  • With your permission, we’ll credit you once the issue is resolved.

Please don’t

  • access, change or delete data that isn’t yours (use test accounts);
  • run denial-of-service, spam or load tests;
  • use social engineering or physical attacks against our people or offices;
  • disclose the issue publicly before we’ve had a reasonable chance to fix it.

How we protect data

Encryption in transit and at rest, least-privilege access, dependency and security scanning on every change, strict security headers, and IP addresses stored only as salted hashes. Client engagements add controls agreed per project.