SECURITY AT TEND
A private home record needs careful foundations.
Tend uses layered account, network, storage, and authorization controls. We are also candid about what is still being tested before a broad public launch.
Protect your Tend account
- Use a strong password that you do not reuse on another service.
- Never share a password, email verification code, recovery code, or private calendar link.
- Sign out on shared devices and protect your phone or computer with its screen lock.
- Report unexpected sign-in, account, or calendar activity promptly.
How the service is protected
| Area | Current safeguards |
|---|---|
| Sign-in | Email verification and managed authentication through Amazon Cognito. Tend’s application database does not store your password. |
| Connections | HTTPS encrypts data in transit between supported clients and Tend services. |
| Cloud storage | Workspace records and uploaded files use encrypted AWS storage. File buckets block public access. |
| Authorization | Private API requests require a valid signed account token, and stored records are scoped to the authenticated account. |
| Availability and abuse | CloudFront includes AWS Shield Standard network protection. API throttles and deliberately small development capacity limit unexpected scaling while Tend is in early access. |
| Mobile sessions | Supported mobile apps keep session credentials in protected device credential storage. |
Early-access limits
No system is perfectly secure. Tend is still completing cross-account isolation, backup restoration, alerting, recovery, and physical-device release testing. Use test or replaceable files during early access and keep original copies of important home records. These precautions will change as testing is completed.
Tend does not currently advertise a formal bug-bounty program or promise compensation for reports.
Report a security concern
Email info@tendyourhouse.com with the subject Security Report. Describe the affected page or feature, what you observed, and safe steps to reproduce it. Do not include passwords, active tokens, private calendar links, or another person’s home information in ordinary email.
Please avoid privacy violations, social engineering, denial-of-service traffic, automated account creation, destructive testing, or accessing, changing, downloading, or retaining data that is not yours. Stop testing if you encounter another person’s information and report it immediately.
Privacy and data deletion
The Privacy Notice explains collection, use, retention, and deletion. Account holders can export their structured workspace and permanently delete the account and associated cloud data.