Download for Mac

Tabula · Legal

Security

Last updated July 28, 2026

This page describes our security practices and our vulnerability disclosure policy for security researchers.

01

Our Security Commitment

We take the security of Tabula and your data seriously. We apply industry-standard safeguards including encryption in transit (TLS/HTTPS), encryption at rest, row-level security on our database, scoped access controls, and least-privilege service credentials.

No system is perfectly secure, and we cannot guarantee absolute security, but we work continuously to protect our users.

02

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly to tabulaap@gmail.com. Please do not disclose the issue publicly until we have had a reasonable opportunity to address it.

When you report in good faith, we commit to:

  • Acknowledge your report within 48 hours;
  • Provide regular updates on our progress toward a fix;
  • Not pursue legal action against researchers who act in good faith and comply with this policy.
03

Scope

In scope

  • tabulaapp.com and its subdomains (*.tabulaapp.com)
  • The Tabula desktop application

Out of scope

  • Social engineering of our staff or users
  • Physical attacks
  • Denial-of-service (DoS/DDoS) attacks
  • Reports from automated scanners without a demonstrated, exploitable impact
04

Safe Harbor

Activities conducted in a manner consistent with this policy will be considered authorized conduct, and we will not initiate legal action against you. If legal action is initiated by a third party against you for activities that complied with this policy, we will make this authorization known.

The web, arranged around you.

PrivacyTermsCookiesRefundsAcceptable UseSecurityAccessibilityGDPRData ProcessingDMCALicenses
tabulaap@gmail.com© 2026 Tabula