Last updated August 13, 2026
Security at Tipoff
Security is foundational to how Tipoff is built and operated. This page describes the practices we maintain today. It is provided for general information, may evolve as the product does, and does not modify any agreement between 2primes and its customers.
Infrastructure. Tipoff runs on Google Cloud Platform in U.S. regions. We rely on GCP’s physical and infrastructure security controls; GCP maintains its own certifications (including SOC 2 and ISO 27001) covering that infrastructure.
Encryption. Data is encrypted in transit (TLS) and at rest (AES-256 via GCP’s default encryption). Connector credentials and OAuth tokens are encrypted before storage.
Access control. Workspace access is role-based, and organizations control who can access their workspace. Internal access to customer data is limited to personnel who need it to operate, secure, and support the Service.
Customer content. We use customer content only to provide, secure, maintain, and support the Service, and we do not use it to train AI models. AI model providers that help deliver the Service process content under agreements that do not permit them to use it for training.
Payments. Payments are processed by Stripe. Tipoff does not store full payment card numbers.
Development and assessment. Code review and automated dependency and vulnerability scanning are part of our development process. We reassess our security posture periodically as the product evolves.
Incident response. If we confirm an incident affecting customer content, we notify affected customers without undue delay, consistent with our agreements.
Compliance. The certifications noted above are GCP’s and cover the infrastructure Tipoff runs on. Tipoff’s own SOC 2 certification is on our roadmap, and we are glad to complete security reviews and questionnaires and to walk through our practices as part of any evaluation.
Contact. Security questions, reviews, or vulnerability reports: security@tipoff.io.