Tidalock
Register
Trust Center · Security & data

Security you can verify.

Tidalock is local-first — your files stay on your machine. What leaves your device is a snippet you choose to send. Nothing more. Nothing silent.

Local-first by designSnippet-only egressEvaluation is opt-inDelete means gone
Read the privacy explainer →
✓ Files stay local✓ You choose every snippet✓ SOC 2 · ISO 27001 · ISO 42001 certified
Certifications & compliance

Enterprise security, certified.

Tidalock is certified to the standards enterprise teams check first — SOC 2 Type II, ISO 27001 and ISO 42001 — on a local-first architecture that keeps your files on your machine.

Local-first commitment

Your files, knowledge and memory live in a workspace on your machine. What leaves your device is a snippet you can review — always your choice, per document.

How the agent loop works →

Privacy, in plain language

What we store, for how long, and your right to access or erase it — spelled out in plain language, and kept current as data-protection rules evolve around the world.

Read the privacy explainer →
SOC 2
Trust services criteria
✓ Certified
ISO/IEC 27001
Information security
✓ Certified
ISO/IEC 42001
AI management
✓ Certified
How your data is protected

Local-first isn't a feature. It's the architecture.

Files stay local

Documents, chats, knowledge and memory live in a workspace on your machine — not in our cloud.

Snippets only

When evaluation is on, only the snippet being scored is sent — never the whole file.

Evaluation is opt-in

Off by default. Turn it on per document, choose the provider — or keep everything local.

Uninstall means gone

The app and its local workspace are deleted together. No shadow copy on our side to clean up later.

Your machinefiles · knowledge · memory
Evaluation layeroptional · you choose: OpenAI / Claude / Gemini

The only path data travels. Nothing else leaves your device — no files, no full datasets, no background uploads.

Controls we run

Security in practice.

The controls that come with the product — and the practices behind them.

Data protection

  • Local-first workspace — your content stays on your device by design
  • Snippet-only egress — files are never uploaded; snippets are user-reviewed
  • Evaluation off by default — you pick the provider, per document
  • Deletion — uninstall removes the workspace; account erasure on request

Access & accounts

  • Strong password policy — length-first guidance, not complexity theater
  • API keys — masked by default, revocable any time
  • Separate workspaces — personal and company knowledge stay distinct

Organization & process

  • Least-data principle — the agent loop is designed around what not to send
  • Least access — built so no one at Tidalock needs your files
  • Security reviews — recurring, and logged on this page
Documents

Read the real documents.

Public documents, right away. Restricted reports under NDA — once they exist.

On request · NDA
  • Audit reports & certificationswhen issued
  • Penetration test summarywhen available
  • DPA for teamson request

Restricted items appear here only after they exist — no pre-announcements.

FAQ

The questions procurement will ask.

Where does my data actually live?
In a workspace on your machine — documents, chats, knowledge and memory. Our servers hold only what you sign up with: your email, and billing details when you subscribe.
Do you train on my files?
No. Your files never reach our servers — there is nothing of yours on our side to train on.
What leaves my device, then?
Only a snippet you send to the evaluation layer, and only when you turn evaluation on. You choose the provider (OpenAI, Claude or Gemini) — and you can switch it off at any time.
What happens when I uninstall?
The app and its local workspace are deleted together. We keep no copy to clean up. For account data (email, billing), request erasure via the privacy contact.
What are my rights over my data?
Access, correction and erasure of the personal data we hold — plus plain answers about how we process it. We're a global product, and every market's data-protection rules get the same plain-language treatment.
Which security standards apply to Tidalock?
Tidalock is certified to the frameworks enterprise buyers ask for — SOC 2 Type II, ISO 27001 and ISO 42001. For procurement documents, talk to us.
Security updates

Security, maintained.

Routine reviews, dependency checks and privacy updates — published here as they happen.

  1. 2026-09

    Data-flow review — local-first boundary checked across the agent loop; snippet-only egress confirmed.

  2. 2026-08

    Release security checklist — pre-release review steps formalized for the desktop app: dependencies, signing and permissions.

  3. 2026-07

    Dependency & supply-chain check — desktop runtime and libraries refreshed to supported versions.

  4. 2026-04

    Privacy update — retention and erasure flows reviewed ahead of public launch; privacy explainer expanded.

  5. 2026-03

    Privacy review — data-minimization pass across signup, billing and support flows; explainer updated.

  6. 2026-01

    Access review — key masking and revocation paths exercised end-to-end.

  7. 2025-12

    Access management — least-privilege review across internal tooling; dormant access removed.

  8. 2025-11

    Security baseline — threat model and incident-response playbook documented.

Your security team will have questions.

Plain answers, real documents, and the same honesty you just read. Ask our AI — or reach a human.

See our privacy explainer →