<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Taiga trust center updates</title>
  <subtitle>Changes to Taiga's security posture, subprocessor register, and trust documents.</subtitle>
  <link href="https://tai.ga/trust-updates.xml" rel="self" />
  <link href="https://tai.ga/en/trust/updates/" />
  <id>https://tai.ga/en/trust/updates/</id>
  <updated>2026-08-12T00:00:00Z</updated>
  <author><name>Taiga AI Oy</name><email>hello@tai.ga</email></author>
  <entry>
    <title>The agent register is now published by stage, not by agent</title>
    <link href="https://tai.ga/en/trust/updates/#agent-register-by-stage" />
    <id>https://tai.ga/en/trust/updates/#agent-register-by-stage</id>
    <updated>2026-08-12T00:00:00Z</updated>
    <category term="general" />
    <summary>The models and agents page used to list every agent by name with the model it runs. It no longer does. The list mirrored a file in the platform repository that changes roughly weekly, so keeping it true depended on someone editing a different repository remembering this page existed, and a trust page that silently falls behind its source is worth less than one that never claimed the detail. What replaces it is durable and answers the same question better: each stage of a run, whether it reads free-form content you supplied, and the guardrail profile that classification selects. Nothing about how the agents work has changed, and nothing that was true is now unsaid.</summary>
  </entry>
  <entry>
    <title>The trust center is now public</title>
    <link href="https://tai.ga/en/trust/updates/#trust-center-published" />
    <id>https://tai.ga/en/trust/updates/#trust-center-published</id>
    <updated>2026-08-05T00:00:00Z</updated>
    <category term="general" />
    <summary>Security questions, the subprocessor register, and the vulnerability disclosure policy are published and ungated. Previously the only route to this detail was requesting the system description. That document still exists and still answers more, but you should not need it to answer a questionnaire.</summary>
  </entry>
  <entry>
    <title>Correction: Bedrock Guardrails are not enforcing</title>
    <link href="https://tai.ga/en/trust/updates/#guardrails-off" />
    <id>https://tai.ga/en/trust/updates/#guardrails-off</id>
    <updated>2026-08-05T00:00:00Z</updated>
    <category term="security" />
    <summary>This site previously stated that Amazon Bedrock Guardrails ran on agent traffic with PII blocking and prompt-injection detection. That was wrong. The guardrails are built and versioned but switched off in every environment, production included, while support cases with AWS are open. The claim has been corrected wherever it appeared. Carrying that surface meanwhile: retrieval is scoped to your tenant, agents run least-privilege and are invoked only by the API, and agent output is validated at the API layer. Re-enabling them will be posted here.</summary>
  </entry>
  <entry>
    <title>Vulnerability disclosure policy published, with safe harbor</title>
    <link href="https://tai.ga/en/trust/updates/#vdp-published" />
    <id>https://tai.ga/en/trust/updates/#vdp-published</id>
    <updated>2026-08-05T00:00:00Z</updated>
    <category term="security" />
    <summary>Good-faith security research that follows the policy is authorized, and we will not bring or support a civil claim over it. The policy sets out what is in and out of scope, notably that customer tenants and applications deployed into a customer's own cloud account are not ours to authorize, and what we commit to in return: acknowledgement within 3 business days, an assessment within 10, updates every 14. security.txt now points at it.</summary>
  </entry>
  <entry>
    <title>Subprocessor register published, and Microsoft added</title>
    <link href="https://tai.ga/en/trust/updates/#subprocessor-register-published" />
    <id>https://tai.ga/en/trust/updates/#subprocessor-register-published</id>
    <updated>2026-08-05T00:00:00Z</updated>
    <category term="subprocessor" />
    <summary>The current subprocessor list is now public rather than only an annex to the data processing agreement. Microsoft appears on it for the first time, covering the optional Microsoft Entra ID single sign-on a customer can enable: sign-in claims transit the federation broker and are not stored in Taiga's own Entra tenant. If your organization does not use Entra single sign-on, nothing changed for you. Objections follow the notice terms in your agreement.</summary>
  </entry>
  <entry>
    <title>Terms, platform terms, and the acceptable use policy published</title>
    <link href="https://tai.ga/en/trust/updates/#legal-documents-published" />
    <id>https://tai.ga/en/trust/updates/#legal-documents-published</id>
    <updated>2026-08-05T00:00:00Z</updated>
    <category term="general" />
    <summary>The website terms of use, platform terms, platform privacy statement, and acceptable use policy are now published. The platform documents are subordinate to your signed agreement and apply only where it is silent; they do not amend anything you have signed.</summary>
  </entry>
</feed>
