Verification, written up for auditors
Taifoon is a verification layer. It produces tamper-evident, independently checkable records of what automated systems did, so that audits become recomputation rather than interviews.
This page answers the standard security questionnaire before it is sent. Every section carries a status tag; nothing appears as held that is not held.
Architecture and isolation
REALA six-plane architecture separates observation, decision, approval, execution, logging, and anchoring. Workloads run in kernel-isolated tiers, each documented with a “proves / does not prove” table; per-cell attestation is published for enclaved workloads. The diagram below is the architecture as run.
Data residency and processing
BUILDINGEU-region cells for EU clients. A data processing agreement template, records of processing, and a sub-processor list with change notification are in preparation; the region policy is in force from phase 0 of the first enterprise delivery.
Audit trail
REALLogs are write-once. Log roots are anchored to a public ledger (Base, an Ethereum Layer 2), which is what makes the records independently verifiable without trusting Taifoon. The verification procedure is written so a client auditor can run it alone: fetch the record, recompute the root, compare against the ledger. The anchor cadence figure will appear here the day the status page serves it; it is not typeset by hand.
Access control
REALA vault policy model with no standing keys in runtimes. Admin access reviews run on a stated cadence beginning with the first enterprise tenant, and the break-glass procedure is itself logged like everything else.
Certifications
PROPOSEDISO 27001 and SOC 2 Type II are roadmap entries with gate dates; the chosen auditor is named once engaged. We publish the roadmap rather than the claim. Nothing in this section implies possession.
Penetration testing
PROPOSEDExternal testing per major release and at least annually; a summary is published, the full report is available under NDA. The first test is scheduled inside phase 3 of the first enterprise delivery.
Vulnerability handling
REALReports go to security@taifoon.io. Acknowledgement within two business days; fix targets by severity; public credit for reporters who want it.
Incident response
BUILDINGA severity ladder with notification windows aligned to NIS2 reporting duties, a named-role on-call, and post-incident reports published to affected clients. The procedure is written; it earns its REAL tag with the first drill, which is itself logged.
Business continuity
BUILDINGRecovery objectives per plane and a degradation ladder: observation continues when actuation is paused, and the log never pauses. An annual restore test is part of the procedure.
Regulatory mapping
BUILDINGNIS2: our own scope, and separately the evidence packs we generate for clients’ obligations. EU AI Act: the approval ladder is documented as the human-oversight mechanism for high-consequence actions, with model and system documentation per workload. GDPR: we are processor for tenant data and controller for our own telemetry. This mapping is documentation, not legal advice; counsel review is pending.
Insurance and liability
WAITINGCoverage held; limits on request through the contact path below.
The register
REALEvery public claim this company makes is tagged, and claims that failed verification are retracted in place rather than quietly dropped. The register is public: the claims register →
Enterprise conversations start with this page. Write to hello@taifoon.io with the sections you need expanded; the reply is a document against this structure, not a sales call. Security reports go to security@taifoon.io and follow section 07.
