TAI Labs

Security & Trust

How we store, protect and process your team's data · Last updated: 15 August 2026

This page is written for the person asked to review us before a purchase. Everything below is current practice, not aspiration. If you need something that isn't here — a completed security questionnaire, a signed DPA, or a specific contractual term — email hello@tailabs.ai and we'll turn it around rather than route you through a sales cycle.

At a glance

Legal entitySnapDrum Ltd (trading as The AI Internship), 124 City Road, London EC1V 2NX, United Kingdom
Governing regimeUK GDPR and the Data Protection Act 2018
Encryption in transitTLS on every connection to the platform and between us and our sub-processors
Database access controlRow-level security, enforced in the database rather than in application code
AuthenticationSupabase Auth — email, magic link and Google OAuth. Admin access additionally requires 2FA
International transfersUK GDPR Art 46 Standard Contractual Clauses, including the UK Addendum
DPAAvailable on request before signature — hello@tailabs.ai
Data deletionSelf-serve from dashboard settings, or on verified request

Certifications, stated honestly

We are not currently SOC 2 or ISO 27001 certified, and we would rather say so here than let you discover it late in a procurement cycle. We operate under UK GDPR and the Data Protection Act 2018, we will complete your security questionnaire, and we will sign a DPA before you send us any data.

If a formal attestation is a hard requirement for your organisation, tell us at the start of the conversation — it changes what we can commit to and when, and that is a better discussion to have on day one than at contract stage.

How the platform is built

  • Row-level security. Access rules live in the database, not in application code, so a bug in a page cannot expose another customer's rows.
  • Separated privileges. The browser only ever holds a public, restricted key. Elevated service-role access exists only in server-side functions and is never shipped to a client.
  • No secrets in the codebase. Credentials live in the deployment platform's encrypted secret storage — never in the repository, never in a committed environment file.
  • Payments are out of scope by design. Card details go directly to Stripe and never touch our infrastructure. We store a customer reference and the last four digits.
  • Admin access requires 2FA in addition to authentication.
  • AI outputs are suggestions, not decisions. We do not perform automated decision-making that produces legal or similarly significant effects.

What managers can and cannot see

On team plans, an employer sponsors access but does not get a window into the employee. This boundary is built into the product, not left to policy.

Managers see

  • Completion of activities that were assigned to the employee
  • Assessment outcomes and readiness evidence for work-related skills
  • Certifications earned on the platform
  • Aggregated team-level usage and adoption patterns

Managers never see

  • Private career materials — personal CVs, external job applications, salary research
  • Raw conversations with AI features, or private coaching content
  • Personal career plans and goals the employee has not chosen to share
  • Anything from a group small enough to identify one person — aggregation thresholds apply

Sub-processors

Every third party that may process customer data, and what it does. Where data leaves the UK/EU we rely on UK GDPR Art 46 Standard Contractual Clauses, including the UK Addendum.

ProviderPurposeRegion
SupabaseDatabase and authentication hostingEU
NetlifyWebsite and application hostingUS / global edge
CloudflareEdge workers and page rendering for enrichment featuresGlobal edge
Stripe, Inc.Payment processing. Card numbers never reach our serversUS
AnthropicAI model processing for platform featuresUS
GoogleAI model processing, and Google OAuth sign-inUS
ResendTransactional email (receipts, verification, notifications)US
Maven Learning, Inc.Only where you purchase a Maven-hosted programme. Maven is an independent controller of the data you give itUS
PostHogProduct analyticsEU

Analytics and advertising partners used on our marketing pages are listed in the privacy policy.

Retention and deletion

Account and learning dataFor the life of the account. Deleted on verified account-deletion request.
Payment and accounting records7 years, as required for tax and audit.
Marketing dataUntil you unsubscribe or object.
Anonymous usage logs for free-tool limitsRolling 30-day window, plus aggregate statistics.

An individual can delete their account and its data from dashboard settings. An administrator can request deletion for a departing employee, and seats can be reassigned without carrying the previous holder's private data across.

Your rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk). Full detail is in the privacy policy.

Reporting a vulnerability

If you believe you have found a security issue, email security@tailabs.ai with enough detail to reproduce it. We will acknowledge within two working days and keep you updated until it is resolved. Please give us a reasonable window to fix an issue before disclosing it publicly — we will not pursue anyone who reports in good faith and does not access or alter data belonging to other people.

Talk to a human

Security questionnaires, DPAs, and architecture questions: hello@tailabs.ai. For a rollout conversation that includes your security team, book a call.