# Tenki Security & Compliance (https://tenki.cloud/company/security)

> For the complete documentation index, see [llms.txt](https://tenki.cloud/llms.txt)

Tenki's security and compliance posture: SOC 2 Type II (via parent company Luxor Technology), SOC 2-attested and ISO 27001-certified data centers, ephemeral single-tenant VM isolation, a 99% uptime SLA, and documented incident-response and responsible-disclosure practices.

## Enterprise-grade security on every run

Trusted by hundreds of teams. Companies deploy faster with Tenki.

## Compliance

**Tenki is aligned with SOC 2 Type II and ISO 27001 security practices.**

- **SOC 2 Type II via Luxor Technology** — Tenki operates under the SOC 2 Type II program of its parent company. Reports from [Luxor Technology](https://luxor.tech/) are available under NDA upon request.
- **SOC 2 Attested Data Center** — All Tenki compute runs in SOC 2-attested data-center facilities with physical access controls, environmental monitoring, and audit logging.
- **ISO 27001 Certified Data Center** — All Tenki compute runs in ISO 27001-certified data-center facilities covering information-security management controls.
- **Ephemeral VM Isolation** — Ensures isolation, strong security and clean execution environments.
- **99% SLA** — Uptime SLA, contractually guaranteed and backed by credits.

## Security Program

**How we secure your builds, end-to-end.** A SOC 2-aligned program covering audit attestation, a published threat model, and modern encryption for data at rest and in transit.

- **SOC 2 Type II** — Tenki operates under the SOC 2 Type II program of its parent company, [Luxor Technology](https://luxor.tech/), audited by an independent licensed CPA firm against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality. Reports are refreshed annually and made available to qualified prospects and customers under a mutual NDA. To request the latest report, email hello@tenki.cloud from a corporate domain and we will respond within two business days with the NDA and report bundle.
- **Threat model** — Our threat model centers on protecting customer source code, build artifacts, and CI secrets from unauthorized access during workflow execution. Every job is provisioned to a single-tenant ephemeral virtual machine with a fresh kernel, fresh disk, and isolated network namespace, so jobs cannot inspect or interfere with other jobs. The runner is destroyed at the end of every workflow and job-time secrets never leave the VM boundary. We continuously evaluate risks across our supply chain, hypervisor, control plane, and customer integrations.
- **Encryption in transit** — All traffic between your GitHub organization, the Tenki control plane, and our runners is encrypted using TLS 1.2 or higher with modern cipher suites and forward secrecy. Public endpoints enforce HSTS and reject downgraded connections, and internal service-to-service calls run over mutually authenticated TLS inside a private network.
- **Encryption at rest** — Customer data is encrypted at rest with AES-256 across object storage, databases, backups, and ephemeral runner volumes. Encryption keys are managed by our cloud provider's hardware-backed key management service, rotated on a defined schedule, and access is restricted to a least-privileged subset of production engineers under audit logging. Customer-supplied secrets injected into workflows are encrypted at rest, decrypted only inside the runner VM at job start, and zeroized when the VM terminates.

## Operations & Disclosure

**Incident response, testing, and responsible disclosure.** Documented operational practices for detecting, containing, and communicating security events — and a clear path for researchers to report them.

- **Incident response** — Tenki maintains a documented incident-response plan with defined severity tiers, escalation paths, and a 24/7 on-call engineering rotation. Every incident is followed by a post-incident review capturing root cause, customer impact, and remediation actions, and the plan is exercised on a recurring basis to validate detection and response timing.
- **Notification SLA** — If a confirmed security incident materially affects your data or workflows, Tenki will notify impacted customers within 72 hours of confirmation through the security and billing contact emails on file. Initial notifications include what we know, what we do not yet know, and immediate steps. A written post-mortem with remediation status follows once the investigation has closed.
- **Penetration testing** — Independent security firms perform third-party penetration tests of our application surface and infrastructure at least annually, supplemented by continuous internal vulnerability scanning, dependency review, and peer code review on every change. Findings are tracked to closure under defined service levels; critical and high-severity issues are remediated as a priority before the engagement is closed and a clean retest is issued. A summary letter from our most recent test is available to enterprise customers under NDA on request.
- **Vulnerability disclosure** — If you believe you have discovered a vulnerability in Tenki, email hello@tenki.cloud with reproduction steps and any supporting artifacts. We acknowledge valid reports within two business days and, once an issue is confirmed, provide an expected remediation timeline — usually within ten business days, depending on severity and complexity. We credit researchers at their request once a fix has shipped. Please do not publicly disclose unfixed issues, perform testing that disrupts other customers, or attempt to access data that does not belong to you.

## Connection Security

**Least-privilege GitHub access.** Tenki requests only the GitHub permissions each app needs — nothing more. Tenki ships as two separate GitHub Apps (Tenki Runner and Tenki Code Reviewer) that are installed independently, and each requests only the scopes it needs. Install one and you never grant the other's permissions. [View the full permission table for each app](https://tenki.cloud/docs/github/gh-app-access-level.md)

The page also includes customer testimonials about Tenki's speed and reliability.

## FAQ

Have a question we haven't answered? Reach out to hello@tenki.cloud.

### Is Tenki SOC 2 compliant?

Tenki operates under the SOC 2 Type II program of its parent company Luxor Technology. Reports are available under NDA upon request.

### Where do Tenki runners execute customer workloads?

All Tenki compute runs in SOC 2-attested and ISO 27001-certified data centers. Every CI job runs in a fresh, single-tenant VM that is provisioned at job start and destroyed when the job completes — Linux jobs in ephemeral VMs and macOS jobs in isolated VMs on Apple Silicon hardware — so no customer code, dependencies, or secrets persist between runs.

### How are jobs isolated between customers?

Each job runs in its own fresh, single-tenant VM that is destroyed when the job finishes — on Linux, a hardware-isolated VM with its own kernel and filesystem. There is no shared filesystem, no shared keychain, and no shared user account between jobs. macOS jobs run on Apple Silicon hardware that is multi-tenant at the hardware level, but each job is still isolated in its own VM with no persistent state carried between runs.

### Is Tenki GDPR-compliant?

Tenki processes customer data in alignment with the EU General Data Protection Regulation (GDPR). A Data Processing Agreement (DPA) is available on request at hello@tenki.cloud. Full GDPR certification is on our compliance roadmap.

### What is Tenki's uptime SLA?

Tenki offers a contractual 99% uptime SLA backed by service credits. SLA terms and credit calculations are defined in the Tenki Master Services Agreement, which we share with prospective enterprise customers during procurement.

### How does Tenki handle GitHub Actions secrets?

Tenki Runners use GitHub Actions' native secret system unchanged. Secrets are injected into the runner VM by GitHub at job start, used by the workflow steps, and destroyed with the VM when the job ends. Tenki never persists workflow secrets and never sees them outside the lifetime of a single job.

### Does Tenki support responsible disclosure?

Yes. Report suspected vulnerabilities to hello@tenki.cloud with reproduction steps and any supporting artifacts. We acknowledge valid reports within two business days and, once an issue is confirmed, provide an expected remediation timeline — usually within ten business days, depending on severity and complexity. We credit researchers at their request once a fix has shipped. Please don't publicly disclose unfixed issues or test in ways that disrupt other customers.

### Can I request a Tenki SOC 2 report or DPA?

Yes. SOC 2 Type II reports (via Luxor Technology), Data Processing Agreements, and security questionnaires are all available under NDA. Contact hello@tenki.cloud and we will route the request to the Tenki security and legal team.