Security, without the vague claims.
What Tahanic protects today, how those protections are enforced, and the gaps we have not earned the right to hide.
Everything presented as active on this page describes controls currently in place.Accounts & sign-in
Authentication is handled by Clerk. Tahanic never receives or stores your password. Every private API request carries a session token that the server verifies before doing anything else.
Technical details
- Session tokens are verified server-side with RS256 signature verification against the provider's public keys
- Issuer and authorized-party claims are validated
- Expiry and standard claims are checked on every request
Roles & authorization
Four roles — Owner, Manager, Staff, Read-only. Interface controls improve usability; server authorization is what actually enforces access. The browser never gets to decide which business or role a user belongs to: membership, role and scope are derived on the server from the verified session, through a shared authorization guard.
Rate limiting
Abuse-prone and externally exposed operations are rate limited using Cloudflare Durable Objects, which count and decide atomically. Limits apply per IP and, where relevant, per user or business. When a limit is hit the request is refused with HTTP 429 and a Retry-After header — requests are never silently dropped.
Infrastructure & data
Application data is stored in Cloudflare D1 and reached only through server-side Worker code — it is not exposed directly to the browser. Authorization and refresh tokens, where used, remain server-side.
Browser & transport security
Scripts are restricted: no unsafe-inline, no unsafe-eval. The few required inline scripts are authorized by hash, and CSP violations are reported.
HSTS, nosniff, frame protection, referrer policy, permissions policy and same-origin policies are set on responses.
The embeddable review widget has narrowly scoped cross-origin exceptions, because it is intentionally embedded on external business websites. Everything else stays same-origin.
Plaintext traffic is upgraded at the edge, and insecure API requests are refused outright.
style-src still permits inline styles, because the current sign-in provider requires runtime-injected styling. Script execution remains fully restricted.
Cookies & tracking
Signing in requires necessary authentication cookies. Tahanic sets no advertising cookies and operates no third-party analytics or tracking scripts. The full data-processing explanation lives in the Privacy Policy.
Customer feedback & retention
After the 365-day retention period, written feedback and contact information are automatically redacted; the rating and date are retained for statistics. This retention rule applies to private customer feedback — other data categories are covered in the Privacy Policy.
Google authorization
Connecting a Google account uses OAuth 2.0 with PKCE (S256). The authorization state is created on the server, bound to the authenticated user and business, accepted only once, and re-verified on completion. Access can be withdrawn at any time.
Google Business Profile review retrieval and direct reply publishing require Google Business Profile API access and are not currently available.
What is not in place today.
These are current gaps, not hidden roadmap promises.
Found something we should know about?
If you find a vulnerability, or something on this page does not match the product's actual behavior, tell us — with enough information to reproduce the issue.