Where is Tailor hosted?
Tailor runs on Microsoft Azure infrastructure in Australia East for the Tailor-controlled production environment, with security, access-control, and audit evidence available during procurement review.
Tailor runs on Australian infrastructure: your documents are stored and processed in Australia. Here’s how we protect them.
Compute, storage, and databases run in Microsoft Azure's Sydney region, so your documents are stored and processed on Australian soil.
A fully managed database with automatic backups and point-in-time restore, hosted in Australia.
Traffic is served over encrypted connections from Azure's Australian infrastructure, with Azure's platform-level protection against denial-of-service attacks. A dedicated web application firewall at the edge is part of the design we are building toward.
Documents, metadata, and user data are encrypted while stored (at rest) using AES-256, a widely trusted encryption standard. Encryption keys are managed in Azure Key Vault.
Every connection to Tailor is encrypted on the way in and out using TLS 1.2 or higher, and browsers are instructed to only ever connect securely (HSTS). Unencrypted connections are not accepted.
Cryptographic keys, secrets, and certificates are stored in Azure Key Vault, Microsoft's managed key store, with access logged.
SOC 2 Type II is an independent audit of a company's security practices. We do not hold this certification yet: we are building toward it, with controls designed against its criteria for security, availability, and confidentiality.
Designed to meet the Australian Privacy Principles (APPs), the national rules for how organisations handle personal information. A Data Processing Agreement is available on request.
Our controls follow the Essential Eight, the Australian Signals Directorate's baseline security guidance: application control, prompt patching, multi-factor authentication, and restricted administrator privileges.
Single sign-on (SSO) through Microsoft Entra ID, so your team signs in with the work accounts they already use. Built on the standard protocols (SAML and OIDC) your IT team expects.
Fine-grained roles control who can see and change each document: owner, reviewer, admin, and viewer.
Multi-factor authentication (MFA) asks for a second proof of identity beyond a password. Tailor supports MFA through Microsoft Entra ID, including your organisation's own sign-in policies.
We are building an independent penetration-testing program, where an external security firm attempts to break in and reports what it finds. Summary results will be available to security teams on request.
Azure Monitor and Application Insights track platform health, sign-in activity, and security events, with automated alerts when something unusual happens.
A document describing our architecture and security posture in detail is available for IT security teams during procurement evaluation. Request it via hello@tailor.au.
Documents, chat, document search, image reading and transcription are processed by AI models in Azure Australia East. What you store stays in Australia. Three features send data overseas, and only while you use them:
| Feature | What leaves Australia | Goes to |
|---|---|---|
| Live voice calls with Tailor in the browser | Call audio and the agent's briefing | Azure OpenAI, East US 2 |
| Phone calls with Tailor | Call audio and the agent's briefing | OpenAI |
| Talk to Tailor on a shared link, and text-to-speech | Audio, the text spoken and the agent's briefing | ElevenLabs |
Call transcripts Tailor keeps are stored in Australia. If you connect your own Azure OpenAI endpoint, inference runs in the region you chose.
Government cells run a stricter setting. The engine refuses live voice, phone and any chat, image, document-search or transcription call not addressed to the cell’s own AI gateway, and stops rather than rerouting if that gateway is down. ElevenLabs voice needs a key to work; government cells are not given one.
Request our security whitepaper or schedule a call with our team to discuss your specific compliance requirements.
FAQ
Tailor runs on Microsoft Azure infrastructure in Australia East for the Tailor-controlled production environment, with security, access-control, and audit evidence available during procurement review.
Yes. Teams can review the security posture, data-residency assumptions, access controls, audit-trail model, and evidence-pack requirements before starting a controlled AI document review pilot.
Yes. Tailor is designed for human-approved AI-assisted review. AI can group comments and surface conflicts, but accountable reviewers approve, reject, merge, or escalate final decisions.