Tasirio is designed for the buyer whose job is to say no. It reads the least it can, writes nothing back, isolates every customer at the database, and proves its own integrity.
Your data is encrypted in transit and at rest — with a second, application-level layer over the most sensitive values, so a stolen database alone yields nothing readable.
No Tasirio connector writes, changes, or deletes anything in the system it reads. Every connector is read-only in code — the call path can only issue reads, and the build fails if that stops being true. Where a vendor offers no read-only scope for something we must read, we ask for the write-named one and tell you exactly what it is before you grant it, rather than quietly skipping the check. Access is granted on your terms and can be revoked at any time. One deliberate exception, and it is yours to switch on: if you connect a ticketing system (Jira, ServiceNow, Zendesk, Syncro), Tasirio writes the tickets it opens there on your behalf — setting their status and adding comments. Ticket objects only, never the systems being governed, and nothing at all until you enter those credentials.
We read the locks and the keys — identities, groups, permissions, sharing, and labels — rather than the contents of your documents and messages. Three narrow exceptions exist because the check cannot be done without them, and all three are disclosed: Medius supplier bank-account numbers, stored masked; Softbase Evolution cardholder column names and row counts, never a cardholder value; and, for Notion pages you have Published to the web, the page body text — pattern-matched in memory so we can tell you a publicly published page holds regulated data, with only the resulting labels stored, never the text.
Your governed data — every finding, permission and document record we hold about your estate — is isolated with row-level security enforced by the database itself, not by application code, so cross-tenant access fails closed — FORCE ROW LEVEL SECURITY means even the table's own owner cannot read across tenants without the tenant context, and the application connects as a non-owner role that has no way to set it for someone else. Platform records such as your connector settings sit in a separate schema where every query is tenant-filtered and the application runs as a role that cannot bypass isolation.
The audit trail is hash-chained and HMAC-keyed. Any attempt to rewrite history breaks the chain and is detectable on verification.
Secrets live in a managed vault; the application connects as a non-privileged role that cannot bypass isolation. Connector credentials are certificate-first where supported.
Tasirio runs in its own dedicated cloud environment, separate from any other product or workload, with its own identity, secrets, and data store.
Everything Tasirio holds about your estate sits in Microsoft Azure, East US 2, in the United States. That is the only region we operate, it is not something you can choose, and there is no EU, UK or Canadian hosting option today. Our Data Processing Addendum and sub-processor list say the same thing in contract language, including the one qualification that is real: alert email and text messages are processed in the EU by our messaging provider, so an alert leaves the US. You choose who receives alerts, and you can turn them off.
We say this next part because a buyer with a residency requirement deserves the actual state rather than a roadmap. On 22 August 2026 we stood up a complete second region in Azure Canada Central and proved, end to end, that a governed row written for a Canadian tenant landed in the Canadian database and was verifiably absent from the US one — and that a tenant assigned to a region we have not built is refused rather than quietly served from the US. Nine assertions, all passing. Then we deleted the region the same night and re-queried to confirm it was gone.
What that test does not say. It covered the database only. The credential vault, evidence storage and the ingest endpoint were provisioned but never written through, so their residency is unproven. The product ships with one region in its list, the region control is staff-operated rather than self-serve, and no customer runs outside the United States. The product is English-only. In short: the mechanism is proven, the offering does not exist yet. If regional hosting is a requirement for you, tell us — that is a scoping conversation, not a checkbox.
Data handling
You can't leak what you never collected. Tasirio deliberately governs the permission graph — the thing that determines AI reach — while leaving your documents, email and messages where they are. Two connectors read a named record field because the check cannot exist without it, and we say which: Medius supplier bank-account numbers (stored masked) and Softbase Evolution cardholder column names and row counts — never a cardholder value.
Compliance posture
Two things earn a security team's trust: how we run our own shop, and how well we help you evidence your AI footprint to your auditors. We're explicit about both — and we never conflate them. So here is our own status, stated plainly rather than implied.
Our security posture — the unflattering version
We publish a self-attestation mapped to SOC 2 controls. That is not a SOC 2 report and we will not let it be presented as one. No third-party penetration test has ever been performed — if your security review asks, that is the answer, and you should have it from us rather than from the questionnaire. The controls above are real and you can test them; the certificates are not, and we are not going to imply a timeline we have not bought. Read the rest of what we are not, in writing, on our partner disclosures, and the legal detail in our DPA, sub-processor list and privacy policy.
Frameworks we help you meet
Standard and framework names are the property of their respective organizations and are referenced descriptively to indicate what Tasirio helps you assess. Tasirio is not affiliated with, endorsed by, approved by, or certified by any of them, and a Tasirio mapping is not a formal conformity assessment or certification.
What we don't claim
Any tool can produce a green dashboard by not looking. These are the rules that stop us doing it — they cost us favourable-looking numbers on purpose.
A control is reported clean only if the read demonstrably ran, the surface was attested by the connector, and a test has already proved that check can fire on a bad estate. Anything else is reported not assessed — a different sentence, and usually the honest one.
Some vendors put read-only data behind a scope whose name says "write". We tell you what it is, what it unlocks and what we still will not collect before you grant it. Decline it and those checks report NOT RUN rather than passing. Quietly not looking is not the same as looking and finding nothing.
Where an estate is too large to read exhaustively, the result says "we read 40 of 900" instead of presenting a sample as a verdict.
"This regulated data exists" and "this job function can reach it" are different claims, and we never let the first be sold as the second. Where the permission model we would need lives in a system we were not given, the finding says so.
No connector ingests a vendor's access logs, so we cannot tell you a file was opened — and we refuse to infer it from a login timestamp. It is a capability we do not have, and saying so is more useful than the claim would have been.
Effective access is computed from the permission model. We never test it by acting as one of your users, and Tasirio never writes, changes or remediates anything in the systems it governs. The one exception is yours to choose: if you connect a ticketing system (Jira, ServiceNow, Zendesk, Syncro), Tasirio opens and updates tickets there so you can manage remediation in the tool you already use.
Deploy in minutes. Connect to your existing environment.
Nothing to install for cloud systems, and no changes to your infrastructure.
Tasirio never modifies or changes the environment it governs. It writes in exactly two places, both outside those systems: your credential into a key vault (ours, or your own under bring-your-own-key), and — only if you connect one — tickets in your ticketing system.
Configuration and permission metadata — who can reach what. Two connectors read a named record field because the check cannot exist without it; both are named here. Your data stays where it is.
Microsoft 365, Google Workspace, AWS, Salesforce, ServiceNow, Okta, and more — see the full coverage list.
Connect your first platform and start seeing insights in minutes.
Every customer environment is logically isolated with enterprise-grade security.
Scan on demand, or on a schedule you set — with a diff against the last run and an alert if a scheduled scan fails to produce one.
Enterprise scale. Enterprise security. Enterprise support.
That's the Tasirio difference.
Tasirio turns AI sprawl into clarity, ownership, and proof so you can move fast—without taking risks.
Discover every AI system and map its access to sensitive data, users, and critical systems.
Every risk, exposure, and finding has a clear owner and a path to resolution.
Generate audit-ready evidence and reports that map to your policies and regulations.
See what moved since the last scan, and keep your evidence aligned with evolving laws, frameworks, and policies.
Reduce risk. Improve accountability. Gain confidence.
Build AI you can trust.