Tirdad
Security & Compliance

Enterprise-grade security

Built for organizations that require complete auditability, strict data isolation, and compliance-ready architecture. Procurement-safe by design.

Security at every layer

From data encryption to audit trails, every aspect of Tirdad is designed for enterprise and government requirements.

Complete Auditability
Every charge, credit adjustment, and subscription change is logged with immutable audit trails. Line-item billing transparency for compliance and dispute resolution.
  • Immutable event log
  • Point-in-time state reconstruction
  • Detailed change attribution
  • Exportable audit reports
Tenant Isolation
Strict data isolation between tenants at every layer—database, API, and processing. No cross-tenant data access by design.
  • Logical tenant separation
  • Tenant-scoped API keys
  • Isolated processing queues
  • Per-tenant encryption keys
Role-Based Access Control
Granular RBAC with predefined roles and custom permission sets. Control who can view, modify, or administer billing operations.
  • Predefined admin roles
  • Custom permission sets
  • API key scoping
  • Action-level permissions
Event Traceability
Full request tracing from event ingestion through invoice generation. Correlate any billing outcome to its source events.
  • Distributed tracing
  • Request correlation IDs
  • Event lineage tracking
  • Debug mode for development
Data Encryption
Encryption at rest and in transit for all data. Customer payment credentials never touch our servers—handled by PSP partners.
  • TLS 1.3 for transit
  • AES-256 at rest
  • PSP-managed card data
  • Key rotation support
API Security
Secure API authentication with scoped keys, rate limiting, and IP allowlisting for enterprise deployments.
  • Scoped API keys
  • Rate limiting
  • IP allowlisting
  • Webhook signature verification
Compliance

Meeting regulatory requirements

We take compliance seriously. Tirdad is designed to help you meet your regulatory obligations.

SOC 2 Type II

Certified (via Flexprice)

Security, availability, and confidentiality controls

GDPR

Certified (via Flexprice)

EU data protection and privacy regulation

PCI DSS

Via PSP Partners

Payment card data handled by certified PSP partners

Data Residency

Available

Deploy in your preferred geographic region

Deployment

Flexible deployment models

Choose the deployment model that fits your security and compliance requirements.

Cloud (Multi-Tenant)

Fully managed SaaS deployment with tenant isolation. Fastest time to value with automatic updates.

Automatic updates
Managed infrastructure
99.99% SLA

Dedicated Cloud

Single-tenant cloud deployment in your preferred region. Enhanced isolation for regulated industries.

Single-tenant
Region selection
Custom SLA

On-Premise / VPC

Deploy within your own infrastructure or VPC. Full control for maximum data sovereignty.

Your infrastructure
Full data control
Custom integrations
Security Resources

Security Documentation

Download our security materials and compliance documentation.

Security Whitepaper

Comprehensive overview of Tirdad's security architecture, encryption standards, and compliance framework.

SOC 2 Type II Report

Request access to our SOC 2 Type II audit report (via Flexprice) under NDA.

Penetration Test Summary

Annual third-party penetration testing results summary available upon request.

Ready to discuss your security requirements?

Our team can provide security documentation, compliance questionnaire assistance, and custom deployment discussions.