Skip to content

Documents

Documents and how to get them

Last updated: 2026-08-12

Most vendors make you ask before you learn what there is to ask for. This page is the index: what exists, what it takes to get it, and what does not exist at all. If an answer is already written down, we would rather you cite it than send a questionnaire for it.

Published here, no request needed

Everything in this trust center is public and needs no request, no account, and no form. The two most often cited in a review are the security questions, subprocessor register.

Sent on request

No NDA. Ask the person you are already talking to, or use the address at the foot of this page, and say who at your organization needs it.

Sent on request
DocumentWhat it covers
Data processing agreementThe Article 28 processor terms, with the subprocessor register as its annex. Signed per customer.
System descriptionArchitecture, the data processed, residency, and the security controls that protect it. The document a due-diligence team usually opens with.
Capabilities overviewPlain-language account of what the platform does, for an audience that is not evaluating security.

Sent under NDA

A narrow exception, and worth explaining rather than hiding. These documents describe attack paths and the controls placed against them. The models and agents page says plainly that we do not publish a map of where an attack should aim; handing that map to anyone who asks would contradict it. Under an NDA, with a named recipient, we will go through any of them with your security team.

Sent under NDA
DocumentWhat it covers
Architecture and data flowC4 system and container views, network topology, the data inventory and its classification, and where the trust boundaries fall.
Threat modelSTRIDE analysis: attack vectors against the platform and the controls placed against each one.
Risk registerSecurity, privacy, and operational risks, with owners and treatment.
Data protection impact assessmentThe GDPR Article 35 assessment for the platform, useful when you are running your own.

What does not exist yet

Named here so you find out now rather than three emails into a procurement cycle.

  • A SOC 2 Type II report. Planned, not held, so there is nothing to send.
  • An ISO 27001 certificate. The management system is in place and certification is in progress; the certificate is not held.
  • A third-party penetration test report. None has been commissioned, so no summary exists either.

Each of these is also an open row on the Overview

How to ask

Through whoever you are already speaking to at Taiga, or security@tai.ga

Tell us who needs it and what decision it supports. There is no portal to register for and no form to fill in; a document request is a conversation with a person, and for anything under NDA it has to be.

Tiers set 2026-08-12. The engineering documents carry their own verification stamp in the platform repository and are re-checked against the code before they are sent.