Security / control statement 2026-08-30

Facility evidence stays out of analytics.

Inventory, SDS content, contacts and filing records are treated as sensitive operational data. Authenticated workspace text is masked from product analytics and no customer document content is intentionally captured.

Region
US-East
Object access
Private
Upload screening
Malware scan
Audit records
Actor-stamped

Operating controls

What the system enforces today.

01

US-hosted stack

Application, PostgreSQL, Redis and private object storage run on TierSure's isolated US-East stack.

02

Private evidence storage

Objects are private, access-controlled, hashed on upload and malware-scanned before processing. TierSure does not currently claim application-managed encryption at rest.

03

Independent recovery

Database and private-object archives are copied daily over TLS to off-host storage. Database backups are restored into isolation before retention.

04

Tenant and audit controls

Row-level tenant policies, server-side membership revalidation, role checks, immutable artifact hashes and actor-stamped audit events protect each filing workspace.

Availability boundary

TierSure currently runs in one US-East region and does not claim multi-region high availability. Report a suspected security issue to [email protected]. Service commitments are defined by the terms accepted at checkout and any applicable order form.