tidbit

Trust & Security

Last updated July 30, 2026

A plain-language summary of how Tidbit is run, secured, and communicated about, separate from the legally binding Terms, Privacy Policy, and DPA, which govern if anything here reads differently.

1. Where things stand today

Tidbit is in invite-only beta. As stated in our Terms of Service, the Service is provided during beta without a formal service-level agreement, uptime commitment, or support SLA: we are not going to publish an uptime number we can’t yet stand behind at scale. What we do commit to: we run the product on our own traffic every day, and every customer-visible incident gets a plain-language writeup (see "How we handle incidents" below).

A live, real-time status page is on our roadmap but not yet built. Until then, this page and direct email are the source of truth for what’s happening.

2. How we handle incidents

If an incident affects your traffic (elevated errors, degraded latency, or an outage), we notify affected customers directly by email as soon as we have confirmed cause and impact. Our working target is within one business hour of confirming a customer-impacting incident, not from the first alert firing internally.

After the incident is resolved, we send a short writeup: what happened, who was affected, and what we changed to make it less likely to recur. We do not hide incidents behind vague language.

To report a security issue or suspected incident, email security@usetidbit.ai. For anything else, use the contact form.

3. How we handle your data

Account data and stored credentials are encrypted at the application layer under a per-tenant key, on top of the storage-layer encryption our cloud provider already applies. Every session requires two-factor authentication: there is no account state without a second factor, and there is no way to turn 2FA off entirely.

Request content (the prompts and completions that pass through the gateway) is treated as pass-through by default: it is forwarded to power your request and is not retained beyond what’s needed for reliability. Three things change that, and each is something you turn on for your own traffic: opting in to the Traffic Sampling program, turning on debug capture for your own account, and marking an individual API request for debug capture with the `x-tidbit-debug` header. All three are off by default; see the Privacy Policy for what each stores and for how long.

Our bot-protection on public forms (signup, waitlist, contact) is a self-hosted proof-of-work challenge that runs in our own process: it sends nothing to a third party and collects no behavioral fingerprinting data. The product itself (the gateway and the desktop app) contains no third-party analytics. Our production website uses Google Analytics to measure how the site is used; see the Cookie Policy for the cookies it sets and how to control them. We run no advertising or cross-site tracking anywhere.

The full detail lives in our Privacy Policy, Data Processing Addendum, and published subprocessor list. This page is a plain-language summary, and those documents govern if anything here reads differently.

4. Certifications

We do not currently hold a SOC 2 report or ISO 27001 certification. If that changes, we will publish the report (or a summary of it) here rather than just adding a badge. Tidbit holds no formal certification today; disregard any claim otherwise.

5. Questions

Security or trust questions that aren’t answered here: email security@usetidbit.ai, or reach out via the contact form.