Legal
Security
Draft · last updated September 30, 2026
Draft for counsel review. This page contains placeholder language prepared before TAMVEL’s legal entity has been formed. It has not been reviewed or approved by legal counsel, does not constitute legal advice, and will be replaced before commercial launch. Bracketed items are placeholders.
Our position today
TAMVEL is an early-stage company. We do not currently hold security certifications or attestations (such as SOC 2 or ISO/IEC 27001), and we will not claim any until they are independently issued.
Design principles
- Hardware-backed keys for value operations, never exported.
- Bounded exposure: offline value is capped by policy-set limits.
- Replay protection through monotonic counters and party binding on every signed record.
- Tamper resistance: integrity and attestation checks, failing closed.
- Auditability through structured, signed logs.
- Reconciliation of all offline activity against authoritative systems.
- Least privilege between the intelligence layer and the value module.
This website
- Served over HTTPS with HSTS, a restrictive Content Security Policy and standard security headers.
- Forms are protected by Cloudflare Turnstile, server-side validation and rate limiting.
- No secrets are shipped to the browser; analytics runs without cookies.
Reporting a vulnerability
Please follow our Responsible Disclosure policy. Our machine-readable contact is at /.well-known/security.txt.