Where is Tailor hosted?
Tailor runs on Microsoft Azure infrastructure in Australia East for the Tailor-controlled production environment, with security, access-control, and audit evidence available during procurement review.
Tailor runs on Australian infrastructure: your documents are stored and processed in Australia. Here’s how we protect them.
Compute, storage, and databases run in Microsoft Azure's Sydney region, so your documents are stored and processed on Australian soil.
A fully managed database with automatic backups and point-in-time restore, hosted in Australia.
Traffic is served over encrypted connections from Azure's Australian infrastructure, with Azure's platform-level protection against denial-of-service attacks. A dedicated web application firewall at the edge is part of the design we are building toward.
Documents, metadata, and user data are encrypted while stored (at rest) using AES-256, a widely trusted encryption standard. Encryption keys are managed in Azure Key Vault.
Every connection to Tailor is encrypted on the way in and out using TLS 1.2 or higher, and browsers are instructed to only ever connect securely (HSTS). Unencrypted connections are not accepted.
Cryptographic keys, secrets, and certificates are stored in Azure Key Vault, Microsoft's managed key store, with access logged.
SOC 2 Type II is an independent audit of a company's security practices. We do not hold this certification yet: we are building toward it, with controls designed against its criteria for security, availability, and confidentiality.
Designed to meet the Australian Privacy Principles (APPs), the national rules for how organisations handle personal information. A Data Processing Agreement is available on request.
Our controls follow the Essential Eight, the Australian Signals Directorate's baseline security guidance: application control, prompt patching, multi-factor authentication, and restricted administrator privileges.
Single sign-on (SSO) through Microsoft Entra ID, so your team signs in with the work accounts they already use. Built on the standard protocols (SAML and OIDC) your IT team expects.
Fine-grained roles control who can see and change each document: owner, reviewer, admin, and viewer.
Multi-factor authentication (MFA) asks for a second proof of identity beyond a password. Tailor supports MFA through Microsoft Entra ID, including your organisation's own sign-in policies.
We are building an independent penetration-testing program, where an external security firm attempts to break in and reports what it finds. Summary results will be available to security teams on request.
Azure Monitor and Application Insights track platform health, sign-in activity, and security events, with automated alerts when something unusual happens.
A document describing our architecture and security posture in detail is available for IT security teams during procurement evaluation. Request it via hello@tailor.au.
Request our security whitepaper or schedule a call with our team to discuss your specific compliance requirements.
FAQ
Tailor runs on Microsoft Azure infrastructure in Australia East for the Tailor-controlled production environment, with security, access-control, and audit evidence available during procurement review.
Yes. Teams can review the security posture, data-residency assumptions, access controls, audit-trail model, and evidence-pack requirements before starting a controlled AI document review pilot.
Yes. Tailor is designed for human-approved AI-assisted review. AI can group comments and surface conflicts, but accountable reviewers approve, reject, merge, or escalate final decisions.