Tahanic Tahanic ← Home
Security

Security, without the vague claims.

What Tahanic protects today, how those protections are enforced, and the gaps we have not earned the right to hide.

Everything presented as active on this page describes controls currently in place.
AuthenticationClerkSession-based sign-in; Tahanic does not store passwords.
AuthorizationServer enforcedRoles and business scope are resolved and enforced on the server.
InfrastructureCloudflareApplication infrastructure and data services run on Cloudflare.
Application dataCloudflare D1Reached through server-side code, not exposed directly to the browser.
TransportHTTPS enforcedPlaintext traffic is upgraded at the edge; insecure API requests are refused.
Rate limitingActiveSensitive and abuse-prone operations are rate limited.
Advertising trackingNone operated by TahanicNo Tahanic advertising cookies or third-party tracking scripts.

Accounts & sign-in

Authentication is handled by Clerk. Tahanic never receives or stores your password. Every private API request carries a session token that the server verifies before doing anything else.

Technical details
  • Session tokens are verified server-side with RS256 signature verification against the provider's public keys
  • Issuer and authorized-party claims are validated
  • Expiry and standard claims are checked on every request

Roles & authorization

Four roles — Owner, Manager, Staff, Read-only. Interface controls improve usability; server authorization is what actually enforces access. The browser never gets to decide which business or role a user belongs to: membership, role and scope are derived on the server from the verified session, through a shared authorization guard.

Authenticated user→ Server verifies session→ Server resolves membership + role + scope→ Allowed or rejected

Rate limiting

Abuse-prone and externally exposed operations are rate limited using Cloudflare Durable Objects, which count and decide atomically. Limits apply per IP and, where relevant, per user or business. When a limit is hit the request is refused with HTTP 429 and a Retry-After header — requests are never silently dropped.

Infrastructure & data

Browser→ Cloudflare Worker→ Cloudflare D1

Application data is stored in Cloudflare D1 and reached only through server-side Worker code — it is not exposed directly to the browser. Authorization and refresh tokens, where used, remain server-side.

Browser & transport security

Content Security Policy

Scripts are restricted: no unsafe-inline, no unsafe-eval. The few required inline scripts are authorized by hash, and CSP violations are reported.

Security headers

HSTS, nosniff, frame protection, referrer policy, permissions policy and same-origin policies are set on responses.

Cross-origin boundaries

The embeddable review widget has narrowly scoped cross-origin exceptions, because it is intentionally embedded on external business websites. Everything else stays same-origin.

HTTPS

Plaintext traffic is upgraded at the edge, and insecure API requests are refused outright.

Known limitation

style-src still permits inline styles, because the current sign-in provider requires runtime-injected styling. Script execution remains fully restricted.

Cookies & tracking

Signing in requires necessary authentication cookies. Tahanic sets no advertising cookies and operates no third-party analytics or tracking scripts. The full data-processing explanation lives in the Privacy Policy.

Customer feedback & retention

Private feedback submitted→ Visible only to the business→ Business can delete→ Auto-redacted after 365 days

After the 365-day retention period, written feedback and contact information are automatically redacted; the rating and date are retained for statistics. This retention rule applies to private customer feedback — other data categories are covered in the Privacy Policy.

Google authorization

Connecting a Google account uses OAuth 2.0 with PKCE (S256). The authorization state is created on the server, bound to the authenticated user and business, accepted only once, and re-verified on completion. Access can be withdrawn at any time.

Google Business Profile review retrieval and direct reply publishing require Google Business Profile API access and are not currently available.

What is not in place today.

These are current gaps, not hidden roadmap promises.

Two-factor authenticationNot available today

Sign-in is currently single-factor through the existing authentication setup.

Self-serve whole-account exportNot available today

Reports export to CSV, but a full self-serve export of an entire account does not exist yet; it is handled on request through support.

Published uptime / public status pageNot available today

No public status page exists, and no uptime percentage is quoted anywhere — including here.

Security certification / external assessmentNone currently

No SOC 2 report, no ISO 27001 certification, no third-party penetration test, and no external security audit is claimed. Cloudflare and Clerk are service providers; their certifications do not certify Tahanic.

Found something we should know about?

If you find a vulnerability, or something on this page does not match the product's actual behavior, tell us — with enough information to reproduce the issue.

admin@tahanic.com