Our Commitment

At Tarifix, we understand that your product catalog, supplier relationships, and tariff exposure data are competitively sensitive. We've built our platform with security and privacy as foundational requirements, not afterthoughts.

✓ SOC 2 Type II CertifiedIn Progress

We are currently undergoing SOC 2 Type II audit and expect certification by Q2 2026. This demonstrates our commitment to security, availability, and confidentiality controls.

Data Security

Encryption

At Rest: All customer data is encrypted using AES-256 encryption. Database volumes, backups, and file storage are all encrypted with keys managed through AWS KMS.

In Transit: All data transmitted between your systems and Tarifix uses TLS 1.3. We enforce HTTPS across all endpoints and reject unencrypted connections.

Infrastructure

Tarifix runs on AWS infrastructure in the US-East region. We leverage AWS's security controls including:

Access Controls

We implement least-privilege access across our systems:

Data Privacy

We Never Share Your Data

Your product catalog, supplier information, and tariff exposure data belong to you. We:

Data Retention

You control your data:

Third-Party Services

We use a minimal set of third-party services, all of which are bound by data processing agreements:

Compliance

U.S. Data Residency

All customer data is stored in AWS US-East region and never leaves the United States. We do not transfer data to international jurisdictions.

GDPR & Privacy

While Tarifix primarily serves U.S.-based companies, we respect privacy rights for all users. You can:

Tariff Classification Standards

Our HTS classification engine is trained on publicly available CBP rulings and the official Harmonized Tariff Schedule. We update our tariff database daily from USITC sources.

Incident Response

In the unlikely event of a security incident:

Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a security issue:

Questions?

For security questions or to request our security documentation (for vendor assessments), contact security@tarifix.com.

For privacy questions or to exercise data rights, contact privacy@tarifix.com.