Security
Your creative work is sensitive. Here's how we protect it.
Encrypted in transit and at rest
Traffic is encrypted over TLS, and stored data and files are encrypted at rest by our hosting provider. Uploaded assets live in buckets scoped per workspace and are served through short-lived signed links.
Row-level access control
Every database query is filtered by workspace membership. Members can only read or modify data inside workspaces they belong to — enforced by the database, not just the app.
Modern authentication
Sign in with email/password or Google OAuth. Sessions are issued as signed tokens over HTTPS and refreshed automatically; passwords are hashed server-side and never stored in plaintext.
Health monitoring & incident response
Queue, error, and spend metrics are tracked automatically, and critical conditions raise internal alerts for triage. We will notify affected customers in line with applicable breach-notification laws.
AI features and third-party processing
Some AI features require the necessary creative content to be securely processed by approved third-party AI service providers. When you run AI Resizer or Studio AI generation, the content needed for that request is transmitted to those providers and processed under their own service and data-processing terms, which may include retention for safety and abuse monitoring. We do not use customer creative content to train Tadvio AI models.
See our Privacy Policy for details on what is shared and how long we keep it.
Reporting a vulnerability
We welcome responsible disclosure. Email support@tadvio.com with a description and reproduction steps. Please do not publicly disclose issues before we've had a chance to remediate.
