This page describes Tanvelo’s security approach and design principles. It is not a certification, independent audit report, or guarantee. Contact us for current, product-specific security information.
1. Our approach
Cleaning operations can include customer contact details, property access instructions, employee information, photos, approvals, invoices, and other sensitive records. Tanvelo treats the protection of this information as an operational requirement.
Our approach is based on limiting access, keeping important activity traceable, collecting only what is needed, and reviewing security throughout the product lifecycle.
2. Access and workspace boundaries
Workspace separation
Tanvelo is designed so each organization works within its own tenant boundary at the application and data layers.
Role-aware access
Owners, managers, cleaners, and financial users should receive access appropriate to their responsibilities.
Purposeful sharing
Customer-facing links are intended to be scoped to the specific approval, payment, or record being shared.
Traceable decisions
Important status changes, approvals, and operational decisions are designed to leave an auditable history.
3. Operational safeguards
Tanvelo’s security program is intended to include:
- Authentication and authorization controls appropriate to the service.
- Administrative controls for access to production systems and customer information.
- Monitoring and logging intended to support investigation and recovery.
- Change, dependency, and vulnerability management practices.
- Backup, recovery, incident-response, and breach-notification procedures.
- Contractual safeguards for service providers that process information for Tanvelo.
We provide details about hosting, encryption, retention, material service providers, backups, and independent assurance only when those details have been verified and apply to the service being evaluated.
4. Security is shared
Customers also help protect their workspace. Organizations should assign appropriate roles, promptly remove access for people who no longer need it, protect credentials, review shared links, and avoid entering information that is unnecessary for the cleaning workflow.
No online service can guarantee absolute security. Product-specific security commitments, data-processing terms, and incident-notification obligations should be documented in the applicable customer agreement.
5. Report a security concern
If you believe you have found a security issue or suspect unauthorized access, use our contact form and choose “Security concern.” Do not include passwords, access codes, customer photos, or other sensitive information in the initial message.