Tabula · Legal
Security
Last updated [EFFECTIVE_DATE]
This page describes our security practices and our vulnerability disclosure policy for security researchers.
Our Security Commitment
We take the security of Tabula and your data seriously. We apply industry-standard safeguards including encryption in transit (TLS/HTTPS), encryption at rest, row-level security on our database, scoped access controls, and least-privilege service credentials.
No system is perfectly secure, and we cannot guarantee absolute security, but we work continuously to protect our users.
Reporting a Vulnerability
If you discover a security vulnerability, please report it responsibly to [SECURITY_EMAIL]. Please do not disclose the issue publicly until we have had a reasonable opportunity to address it.
When you report in good faith, we commit to:
- Acknowledge your report within 48 hours;
- Provide regular updates on our progress toward a fix;
- Not pursue legal action against researchers who act in good faith and comply with this policy.
Scope
In scope
- tabula.com and its subdomains (*.tabula.com)
- The Tabula desktop application
Out of scope
- Social engineering of our staff or users
- Physical attacks
- Denial-of-service (DoS/DDoS) attacks
- Reports from automated scanners without a demonstrated, exploitable impact
Safe Harbor
Activities conducted in a manner consistent with this policy will be considered authorized conduct, and we will not initiate legal action against you. If legal action is initiated by a third party against you for activities that complied with this policy, we will make this authorization known.